This document outlines the requirements for organizations seeking validation or certification of their security programs against the HITRUST Common Security Framework (CSF). It describes the roles of HITRUST, member organizations, and qualified assessors. Organizations can have their security program assessed at three levels - self assessment, CSF Validated after independent testing, or CSF Certified which requires annual reviews. HITRUST oversees the program and provides methodology, tools and final validation or certification based on assessment results and corrective action plans. The goal is to improve efficiencies and reduce costs for healthcare organizations through a consistent compliance assessment process.