HITRUST releases CSF v11.8.0; new e1 and i1 assessments must use it

On May 7, 2026, HITRUST issued Assurance Advisory HAA 2026-002 announcing HITRUST CSF v11.8.0, available in MyCSF and for download the following day. A companion advisory, HAA 2026-003, made v11.8.0 mandatory for all new e1, i1, and rapid assessment objects created in MyCSF from that date. Existing e1 and i1 assessments on v11.7.0 may still be submitted; HITRUST will give at least 90 days’ notice before closing that window.

This item was added to the change feed when the HITRUST CSF page launched on this site, so followers can see the kind of framework release a subscription covers. It is not a new announcement.

What changed

Version 11.8.0 continues HITRUST’s consolidation of overlapping requirement statements and adds or refreshes mappings to the laws and standards the framework harmonizes:

  • New authoritative sources: NIST SP 800-137 (continuous monitoring), ISO/IEC 29100:2024 (privacy framework), the Commonwealth of Virginia SEC530 standard, and the OWASP Top 10 for LLM Applications 2025, each with a selectable compliance factor in MyCSF.
  • Refreshed sources: PCI DSS v4.0.1, the AICPA SOC 2 Trust Services Criteria, and the Texas Medical Records Privacy Act.
  • Two e1 and i1 baseline statements changed. The more significant one, in the Third Party Assurance domain, now requires organizations that let third parties access scoped systems or information to independently verify those third parties’ compliance with contract provisions, replacing a more subjective wording about the suitability of their security practices. Because every e1 statement is inside i1 and r2, the change reaches all three assessments.

What did not change

The portfolio structure is the same: e1 (43 statements, one year), i1 (182 statements, one year, with rapid recertification), and r2 (risk-tailored, two years, with an interim assessment). Assessments already in progress on v11.7.0 are not invalidated. Certification still requires validation by an Authorized External Assessor and HITRUST’s own quality review.

What to do now

  1. If you are starting an e1 or i1, create the MyCSF object on v11.8.0 and read the v11.7.1 to v11.8.0 comparison before scoping.
  2. Review your third-party assurance process against the new wording: can you show independent verification of each vendor’s compliance with its contract, not just a collected SOC 2 report?
  3. If you have an i1 or e1 in flight on v11.7.0, plan to submit it well before HITRUST announces the submission deadline.
  4. See the HITRUST CSF page for how the three assessments differ, who validates them, and what each costs.
  5. Follow HITRUST CSF on this site for the v11.7.0 submission deadline and future framework releases.

#version-updates#program-changes

← Back to news