ISO 27001 vs HITRUST CSF: structure, and which you need
Neither framework publishes a price. ISO 27001 certification bodies quote per engagement, and so do HITRUST-authorised external assessors, so every cost comparison you have read between these two was built from assumptions. What genuinely separates them is structural, and it is a real difference: one asks you to justify your controls against your risk, the other tells you the controls. That shapes the work far more than any price would.
Updated July 2026
Why this page carries no cost comparison
An ISO 27001 audit fee is audit days multiplied by a day rate, and neither input is published. The days are determined by the certification body under ISO/IEC 27006-1:2024, whose audit-time provisions sit in the normative Annex C; ISO sells that standard and we have not read the tables, so we do not reproduce them. The day rate is commercial and no accredited body publishes one.
HITRUST assessments are performed by HITRUST-authorised external assessors, who also quote per engagement against your scope. So a side-by-side cost table for these two frameworks is a table of somebody's assumptions dressed as data. We would rather give you the structure, which is real, and the questions that get you your own numbers. See how ISO 27001 audit fees are set.
What each framework actually is
ISO/IEC 27001:2022
An international standard published by ISO. It requires you to establish an information security management system: define the scope, assess risk, decide treatment, select controls from Annex A on that basis, document the selection and the reasoning in a Statement of Applicability, run an internal audit programme, and hold management reviews.
- 93 Annex A controls across 4 themes
- Risk-based selection; justified exclusion is normal
- Certified by a body accredited for ISMS certification
- Two-stage initial audit, then a three-year cycle
- Governed by ISO, an international standards body
The certificate is a claim about how you run security, not about which products you bought.
HITRUST CSF
A framework operated by the HITRUST Alliance, a private organisation. Its design goal is consolidation: it draws requirements from a range of US regulatory and standards sources into a single prescriptive control catalogue, so one assessment speaks to several regulatory expectations at once.
- Prescriptive control catalogue rather than risk-based selection
- Tiered assessment options of increasing rigour
- Assessed by HITRUST-authorised external assessors
- Concentrated in the US healthcare market
- Governed by a private alliance, not a standards body
The output speaks to a specific regulatory landscape, which is exactly why it travels less well outside it.
The structural comparison
| Attribute | ISO 27001 | HITRUST CSF |
|---|---|---|
| Who governs it | ISO, an international standards body, with accreditation overseen by national accreditation bodies. | The HITRUST Alliance, a private organisation that operates the framework and authorises the assessors. |
| Control model | Risk-based selection from Annex A. You justify what applies; excluding a control with justification is normal. | Prescriptive catalogue. The framework specifies the requirements rather than asking you to derive them. |
| What is assessed | The management system first: scope, risk assessment, risk treatment, internal audit, management review. Controls follow from it. | Conformance against the specified requirements for the tier and scope you are assessed at. |
| Who assesses | A certification body accredited for ISMS certification. Accreditation is published on the accreditation body's own register. | A HITRUST-authorised external assessor. |
| Recognition | International. The portable instrument for European, UK and APAC procurement. | Concentrated in US healthcare. Little recognition outside that context. |
| Design intent | A management system that adapts to any organisation's risk profile and sector. | Consolidation of a specific regulatory landscape into one assessable catalogue. |
| Published price | None. No accredited body publishes a rate card, and the audit-time tables are sold by ISO. | None. Authorised assessors quote per engagement. |
The difference that actually shapes the work
Risk-based versus prescriptive is not a detail of wording, it is the whole character of each programme. Under ISO 27001, the intellectual work is upstream: you have to know what you are protecting, understand your risks, decide what treatment is proportionate, and then defend those decisions to an auditor. The Statement of Applicability is where that argument lives. Two similar companies can hold ISO 27001 certificates covering meaningfully different control sets, and both are correct, because each justified its selection against its own risk.
Under a prescriptive catalogue, that argument is largely settled for you. The requirements are specified, and the work moves downstream into demonstrating conformance against them. That is less flexible by design, and the lack of flexibility is the point: a buyer reading the output knows exactly what was assessed without having to evaluate your reasoning. Which of those you prefer is mostly a question of whether you would rather spend the effort making the argument or evidencing the checklist.
This is also why the two are not in conflict when run together. An ISMS gives you scope discipline, a risk process, an asset and supplier register, an internal audit function and an evidence habit. All of that is infrastructure a prescriptive assessment then draws on. The sequencing that follows from the structure, rather than from any cost claim, is that the management system is the thing worth having first.
Which one do you need
HITRUST, if
- A US healthcare buyer names HITRUST in the document that decides the deal
- Your obligations are concentrated in the US healthcare regulatory landscape
- You want one assessment that speaks to several US regulatory expectations at once
ISO 27001, if
- Your buyer asks for an accredited information security certification generally
- You sell outside the US, where HITRUST carries little recognition
- You need one certificate that travels across regions and sectors
- You want the governance backbone before any prescriptive assessment
The deciding question is narrower than it looks: what does the requirement actually say? If a buyer names HITRUST, ISO 27001 does not answer it however much the control coverage overlaps, because procurement is not evaluating your security posture at that moment, it is checking a named requirement. If the requirement is written generally, ISO 27001 answers it and travels further. Where it is ambiguous, ask the buyer before you commit to a programme. That conversation is cheaper than either framework.