Blog
Why We Are Pursuing the GTIA Cybersecurity Trustmark First
We are currently undergoing assessment for the GTIA Cybersecurity Trustmark. Here is what the Trustmark is, where we are in the process, and why we chose it ahead of SOC 2.
Where We Are
3rd Element Consulting is currently undergoing assessment for the GTIA Cybersecurity Trustmark. We have not been awarded it. The work is in progress, and we will say so plainly until the assessment is complete.
We are writing about it now for the same reason we publish our standards work generally. A provider that asks clients to run to a standard should be able to show what standard it holds itself to, and where it is in the process of proving it.
What the GTIA Cybersecurity Trustmark Is
The GTIA Cybersecurity Trustmark is an independent, industry-accepted security accreditation designed specifically for managed service providers and IT solution partners.
It is built on the Center for Internet Security (CIS) 18 Critical Security Controls, alongside frameworks including NIST, HIPAA, and ISO 27001. The assessment evaluates 177 distinct safeguards covering system hardening, incident response, HR policies, and employee security awareness.
The part that matters most is how it is scored. The Trustmark looks at how security controls are actually executed in daily operations, not just at static paperwork or conceptual answers. It is also not a one time badge. It requires annual independent audits and continuous improvement to stay current.
- Built on the CIS 18 Critical Security Controls, with mapping to NIST, HIPAA, and ISO 27001
- 177 distinct safeguards across hardening, incident response, HR policy, and security awareness
- Assessed on operational execution, not documentation alone
- Independent, so clients and cyber insurance carriers can verify security hygiene rather than take claims on faith
- Annual independent audit and continuous improvement, not a single certificate
Why the Trustmark Before SOC 2
This is a sequencing decision, and one that proves us as a capable and standards led MSP. SOC 2 is a real and useful attestation, and proof of safeguarding and handling of client data. Plenty of good providers hold it. We are starting with the Trustmark because of what it measures.
SOC 2 is a general purpose attestation. It reports on controls at a service organization against broad trust services criteria, and the scope is defined largely by the organization being examined. In other words, the organization can scope out anything it doesn't want to measure. The Trustmark is purpose built for managed service providers, and it assesses how security is actually run day to day across 177 safeguards mapped to the CIS Controls. You don't have the option of putting your systems out of scope.
That difference lines up with the question our clients and their insurers are actually asking. They are not asking whether we can produce a report. They are asking whether the provider running their environment holds itself to the same standard it sets for them. The Trustmark answers that question more directly, in the language of the controls we already use with clients through our security baseline work.
The annual audit requirement is part of the appeal rather than a drawback. A credential that expires unless the work continues is a better fit for how security actually behaves. Nothing here rules out SOC 2 later. It is a question of order, and this is the one that answers the buyer's question first.
What This Means If You Are Evaluating Providers
Ask any provider you are considering what independent standard they hold themselves to, and ask them to show where they are in that process. An honest in progress answer is more useful than a vague claim about best practices.
If you want the same kind of look at your own environment, that is what an IT Environment Review is for. It is the same posture applied to your side of the relationship: what is working, what is unclear, and what needs attention next.
Common questions
Questions leadership usually asks first.
Continue reading
Related reading.
Cybersecurity Services
The security baseline work the Trustmark safeguards map to.
Read more: Cybersecurity ServicesIT Environment Review
The same standards posture applied to your environment instead of ours.
Read more: IT Environment ReviewCyber Insurance Readiness
What carriers ask for, and the evidence that actually satisfies them.
Read more: Cyber Insurance ReadinessAbout 3rd Element
How the standards-led approach came about, and who runs it.
Read more: About 3rd ElementNext step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
