Skip to content

Blog

Regulatory & Compliance

Why We Are Pursuing the GTIA Cybersecurity Trustmark First

We are currently undergoing assessment for the GTIA Cybersecurity Trustmark. Here is what the Trustmark is, where we are in the process, and why we chose it ahead of SOC 2.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting

Where We Are

3rd Element Consulting is currently undergoing assessment for the GTIA Cybersecurity Trustmark. We have not been awarded it. The work is in progress, and we will say so plainly until the assessment is complete.

We are writing about it now for the same reason we publish our standards work generally. A provider that asks clients to run to a standard should be able to show what standard it holds itself to, and where it is in the process of proving it.

What the GTIA Cybersecurity Trustmark Is

The GTIA Cybersecurity Trustmark is an independent, industry-accepted security accreditation designed specifically for managed service providers and IT solution partners.

It is built on the Center for Internet Security (CIS) 18 Critical Security Controls, alongside frameworks including NIST, HIPAA, and ISO 27001. The assessment evaluates 177 distinct safeguards covering system hardening, incident response, HR policies, and employee security awareness.

The part that matters most is how it is scored. The Trustmark looks at how security controls are actually executed in daily operations, not just at static paperwork or conceptual answers. It is also not a one time badge. It requires annual independent audits and continuous improvement to stay current.

  • Built on the CIS 18 Critical Security Controls, with mapping to NIST, HIPAA, and ISO 27001
  • 177 distinct safeguards across hardening, incident response, HR policy, and security awareness
  • Assessed on operational execution, not documentation alone
  • Independent, so clients and cyber insurance carriers can verify security hygiene rather than take claims on faith
  • Annual independent audit and continuous improvement, not a single certificate

Why the Trustmark Before SOC 2

This is a sequencing decision, and one that proves us as a capable and standards led MSP. SOC 2 is a real and useful attestation, and proof of safeguarding and handling of client data. Plenty of good providers hold it. We are starting with the Trustmark because of what it measures.

SOC 2 is a general purpose attestation. It reports on controls at a service organization against broad trust services criteria, and the scope is defined largely by the organization being examined. In other words, the organization can scope out anything it doesn't want to measure. The Trustmark is purpose built for managed service providers, and it assesses how security is actually run day to day across 177 safeguards mapped to the CIS Controls. You don't have the option of putting your systems out of scope.

That difference lines up with the question our clients and their insurers are actually asking. They are not asking whether we can produce a report. They are asking whether the provider running their environment holds itself to the same standard it sets for them. The Trustmark answers that question more directly, in the language of the controls we already use with clients through our security baseline work.

The annual audit requirement is part of the appeal rather than a drawback. A credential that expires unless the work continues is a better fit for how security actually behaves. Nothing here rules out SOC 2 later. It is a question of order, and this is the one that answers the buyer's question first.

What This Means If You Are Evaluating Providers

Ask any provider you are considering what independent standard they hold themselves to, and ask them to show where they are in that process. An honest in progress answer is more useful than a vague claim about best practices.

If you want the same kind of look at your own environment, that is what an IT Environment Review is for. It is the same posture applied to your side of the relationship: what is working, what is unclear, and what needs attention next.

Common questions

Questions leadership usually asks first.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.