Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

MyCSF explained

MyCSF: The Complete Guide to the HITRUST Assessment Platform

MyCSF is the HITRUST platform every assessment runs through — the SaaS system in which an organisation scopes its assessment, tailors the requirement statements, collects and scores evidence, works with its External Assessor, submits for HITRUST’s quality assurance, and shares results with customers. HITRUST describes it as “the all-in-one platform for managing HITRUST assessments — from collaboration and evidence collection to secure results sharing and certification”, and the feature that changes the economics is inheritance: MyCSF lets an organisation “inherit up to 85% of applicable controls” from HITRUST-certified service providers, so that a control the cloud provider operates and has had validated need not be evidenced again. This guide sets out what the platform does at each stage of the assessment lifecycle, how scoping and tailoring produce the requirement set, how evidence and scoring work inside it, how inheritance is set up and what it saves, how results are shared, and the five ways organisations lose time on the platform.

MyCSF: the HITRUST assessment lifecycle in one platform
Create the assessment object → scope and tailor (e1, i1 or r2) → self-assess and collect evidence → inherit from certified providers (up to 85%) → External Assessor validation → HITRUST quality assurance → certification and results sharing.

What MyCSF is

MyCSF is HITRUST’s proprietary software-as-a-service platform, and it is not optional: the assessment object that becomes a certification is created, populated and submitted in it. HITRUST lists the roles it serves — organisations pursuing or maintaining certification, third-party assessors and service providers — and the functions it automates: “workflows for tailoring, remediation, validation, and reporting”. Access is by subscription, priced per organisation and quoted rather than published; the subscription is one of the three invoices in a HITRUST budget. Our guide to HITRUST certification cost sets it against the other two.

The lifecycle inside the platform

Stage What happens in MyCSF Who acts
1. Assessment object The organisation creates an assessment of the chosen type — e1, i1 or r2 — and defines the scope: systems, facilities, business units Organisation
2. Scoping and tailoring For e1 and i1 the requirement set is fixed; for r2 a questionnaire on organisational, system and regulatory factors generates the tailored set of requirement statements Organisation, with assessor input on r2
3. Self-assessment Each requirement statement is scored by the organisation across the maturity levels — policy, procedure, implemented, measured, managed — with evidence attached Organisation
4. Inheritance Controls operated by a HITRUST-certified provider are linked to that provider’s validated results rather than evidenced afresh Organisation and provider
5. Validation The External Assessor tests the organisation’s scores and evidence in the platform and records its own External Assessor
6. Quality assurance The validated assessment is submitted to HITRUST, whose assurance team reviews it before certification HITRUST
7. Certification and sharing The certification report and letter issue; results are shared securely with customers through the platform HITRUST, organisation
8. Maintenance Interim assessment (r2) or rapid recertification (i1) run as new objects against the existing scope Organisation, assessor

Scoping and tailoring

Scoping is the decision that sizes everything downstream. The scope defines which systems, facilities and organisational units are assessed; for an r2, the tailoring questionnaire then asks about factors such as the number of records, the systems’ exposure and the regulatory regimes that apply, and generates the requirement statements. Each factor answered expansively adds requirements; each answered narrowly must be defensible to the assessor. Our guide to HITRUST assessments covers choosing the level; the practical rule is to scope in MyCSF with the assessor before evidence gathering, because the tailored set is what the whole engagement costs.

Evidence and scoring

The platform holds the requirement statements, the organisation’s maturity scores and the evidence behind each. Scoring follows HITRUST’s model — each level scored on coverage and strength, combined into a requirement score, aggregated by domain against the certification threshold — and the platform calculates the result as scores are entered, which is the only reliable way to know before the assessor arrives whether a domain will pass. Our guide to HITRUST scoring covers the model; the platform is where it is applied. Evidence is attached per requirement and per level, so a policy document is linked at the Policy level, a runbook at Procedure, a screenshot or export at Implemented, a metric at Measured, and a remediation record at Managed.

Inheritance: the 85%

HITRUST’s page states the number twice: MyCSF “enables inheritance of validated controls, reducing effort by up to 85% for certified providers” and lets organisations “inherit up to 85% of applicable controls”. The mechanism is a link in the platform between the organisation’s requirement statement and the certified provider’s validated result for the corresponding control — the provider must be HITRUST-certified and must accept the inheritance request. For a SaaS company on a certified cloud, infrastructure, physical and much of the operational control set can be inherited; what remains is the application, the people and the organisation’s own processes. Setting inheritance up is the single largest cost lever in a HITRUST programme, and it is a platform task, not a document.

Results sharing

The platform is also where results go out. Certified organisations share their certification report with customers through the platform’s secure distribution rather than emailing PDFs, and customers can rely on a report that HITRUST’s quality assurance stands behind. For third-party risk programmes that consume many vendors’ results, that distribution is the reason HITRUST positions the platform as a TPRM tool as well as an assessment one.

Five ways organisations lose time on the platform

  1. Scoping alone. An r2 tailored without the assessor generates requirements that get renegotiated at validation.
  2. Evidence at the wrong level. A policy attached at Implemented scores nothing there.
  3. Inheritance requested late. Providers take time to accept; requests sent after self-assessment delay validation.
  4. One owner for everything. The platform supports many users; a single administrator uploading for the whole organisation is the bottleneck.
  5. Self-scores that flatter. The assessor rescoring downward is the most common cause of a failed domain discovered late.

Running MyCSF well

  • Subscribe early and build the scope with the assessor in the platform.
  • Map evidence to levels before uploading; the toolkit’s policy, procedure and register separation exists for this reason.
  • Send inheritance requests on day one.
  • Score conservatively and use the running domain calculation to direct remediation.
  • Keep the object alive between assessments — the interim and the rapid recertification reuse it. Our guide to the HITRUST interim assessment covers year two.

Frequently asked questions

What is MyCSF?
HITRUST’s SaaS platform for the whole assessment and certification lifecycle: creating and scoping the assessment, tailoring the requirement set, self-assessment and evidence, inheritance from certified providers, External Assessor validation, HITRUST quality assurance, certification and secure results sharing.

Is it required?
Yes. Validated assessments submitted to HITRUST for certification are created and submitted in MyCSF; access is by subscription.

What does inheritance do?
It links a requirement to a HITRUST-certified provider’s validated result so the control need not be evidenced again; HITRUST states organisations can inherit up to 85% of applicable controls.

Who uses it?
The organisation being assessed, its External Assessor, HITRUST’s assurance team, and certified service providers granting inheritance; customers receive results through it.

How much does it cost?
HITRUST quotes subscriptions per organisation; it is one of the three invoices in a HITRUST budget alongside the assessor and the internal effort.

Where this leaves you

Treat MyCSF as the programme, not the paperwork: scope in it with the assessor, attach evidence at the maturity level it proves, request inheritance on day one, score conservatively and watch the domain thresholds, and keep the object alive for the interim or rapid recertification. The 85% is HITRUST’s number; claiming it is a platform task.

References

More on HITRUST

The MyCSF and Assessment Approach Guide, the Scoping Guide and Authoritative Sources Mapping, the PRISMA Maturity Scoring Guide, the Control RACI Master and the Validated Assessment Readiness and Preparation Guide are in the HITRUST CSF v11 Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.