| e1 - Essentials | i1 - Implemented | r2 – Risk-Based | |
| Year 1 | 44 Pre-Set Requirement Statements | 182 Pre-Set Requirement Statements | Average Assessment ~375 (up to 1,000 +) Requirement Statements based on Organizational Factors |
| Year 2 | 44 Pre-Set Requirement Statements | ~60 Requirement Statements with Rapid Recertification | ~40 Requirement Statements based on a sample of 19 plus Corrective Action Plans (CAPs) |
| Certification Period | Successful Assessment Results in One-Year Certification | Successful Assessment Results in One Year Certification (rapid recert available in even years) | Successful Assessment Results in Two-Year Certification (interim assessment during even years) |
| Assessment Measures | Measures Implementation of Controls w/ Light Reliance on Policies & Processes | Measures Implementation of Controls w/ Light Reliance on Policies & Processes | Measures Policies, Processes, & Implementation (Measured and Managed are optional) |
| Authoritative Sources for Requirement Statements | CISA Cyber Essentials, Health Industry Cybersecurity Practices (HICP) for Small Healthcare Organizations, NIST 171’s Basic Requirements, NIST IR 7621 | NIST SP 800-171 (Basic and Derived Requirements), HIPAA Security Rule, and HICP for Medium-Sized Organizations | NIST SP 800-53, ISO 27001, HIPAA, FedRAMP, NIST CSF, PCI DSS, GDPR, and Other Frameworks |
| Level of Assurance (also the level of effort) | Low Assurance Level – Essential Security Hygiene | Moderate Assurance Level – Information Security Leading Practices | High Assurance Level – Risk-Based Practices |