Is the Payment Card Industry – Data Security Standard (PCI-DSS) a Risk Management Framework (RMF)?
A validated assessment may lead to either a validated report or a validated report with certification.
Is additional work required by the assessor to generate the NIST Cybersecurity Framework Report?
For an r2 assessment, HITRUST requires a Corrective Action Plan (CAP) when the Control Reference required for certification scored a 70 or less, and Implementation scores less than 100%.