Planning

How long does a CSF program or HITRUST assessment take?

A realistic end-to-end range for a first CSF 2.0 program: 4–9 months. A HITRUST r2 journey (readiness → remediation → validated assessment): 9–18 months. Timelines below assume a mid-market organization with basic IT hygiene already in place.

  1. Weeks 1–4
  2. Weeks 5–12
  3. Months 4–9
  4. Months 6–12
  5. Ongoing

What causes delays

  • Discovery debt. No asset inventory means months of archaeology before control work.
  • OT treated as an afterthought. OT assessment runs on a safety-constrained track — start it in parallel, not after.
  • Tool-first buying. Buying monitoring tools before defining what they'll monitor. Define the program, then tool it.
  • Scope creep. Adding business units mid-program without re-baselining the timeline.

Fastest realistic path

Small operator, decent starting posture: free CISA scanning (week 1) + 4-week gap assessment + 60 days of quick wins ≈ 3–4 months to a defensible CPG baseline. Large or OT-heavy: plan for 9–12+ months.

Timeline questions

Do I need a consultant, or can I do this in-house?

Start in-house with CISA's free services and the CPG checklist. Hire a consultant for the gaps you can't close — specialized assessments, OT scope, or program build-out at speed.

What slows CPG programs down most?

Asset inventory. Organizations that can't see their exposed systems spend months on discovery before any control work starts. Run CISA's free scanning on day one.

Is there a deadline?

For federal agencies: yes — BOD timelines and zero-trust milestones are mandatory. For everyone else: no federal deadline, but customers, insurers, and contracts increasingly set their own.

Start the clock

Tell us your deadline — we'll match you with firms who can hit it.

Get a free quote