HITRUST CSF

A practical introduction to HITRUST CSF certification, including who is asked for it, how the e1, i1, and r2 assessments differ, how the assessor and MyCSF model works, and what it costs.

healthcare · framework · assurance

What is HITRUST CSF

HITRUST CSF is a certifiable security and privacy control framework maintained by HITRUST, a private company founded in 2007 by healthcare organizations that were tired of auditing each other. The framework (HITRUST calls it the HITRUST Framework, historically the Common Security Framework or CSF) takes requirements from more than 50 laws, regulations, and standards, including HIPAA, NIST SP 800-53, ISO/IEC 27001, and PCI DSS, and consolidates them into one set of requirement statements with one scoring method and one certification.

The point is portability. A hospital that receives a HITRUST certification from a vendor knows exactly what was tested, how it was scored, and that HITRUST itself reviewed the assessor’s work before certifying. That consistency is why payers and health systems ask for it instead of running their own vendor audits, and why they often accept nothing else.

The framework is at version 11, first released in January 2023 and updated in point releases; v11.8.0 (May 7, 2026) is current. Version 11 also introduced the current portfolio of three assessments, e1, i1, and r2, which share one framework and build on each other.

The most common misconception is that HITRUST is a HIPAA certification. HIPAA has no certification, and the U.S. Department of Health and Human Services does not recognize any. HITRUST certification is a private assurance that a customer chooses to require; it can demonstrate HIPAA-mapped controls, but it is not a regulatory safe harbor. See the HIPAA page for what the law itself demands.

Who HITRUST CSF applies to

Nothing makes HITRUST mandatory. Organizations pursue it because:

  • a customer contract or vendor-risk program requires a HITRUST certification, sometimes naming the tier (r2 is common in payer contracts);
  • a health system, payer, or pharmacy benefit manager will not onboard a vendor without one, making it a de facto condition of selling into the market;
  • the organization wants one assessment that produces evidence for HIPAA, SOC 2 mappings, NIST, and state privacy laws at once; or
  • leadership wants a scored, maturity-based benchmark that customers recognize.

The surprise case is the small vendor. A 30-person SaaS company that signs one large health plan can be asked for r2 certification within eighteen months, an obligation whose cost rivals the contract’s first-year revenue. Reading the tier named in the contract, and negotiating it, matters more than anything technical.

Scope is set by you, and the certificate says what it covers. A certification can cover one application and its hosting environment and nothing else. When a customer asks for your HITRUST certification, ask which systems they expect to be inside it; when you receive a vendor’s, read the scope statement.

Although healthcare built it, the framework is industry-neutral, and HITRUST markets it to financial services, technology, and government contractors. In practice the market pull remains overwhelmingly healthcare.

Who manages and enforces HITRUST CSF

HITRUST does almost everything, which makes this simpler than most standards and also more centralized:

  • It writes and updates the framework and publishes changes through HITRUST Assurance Advisories.
  • It runs MyCSF, the mandatory online platform where assessments are scoped, scored, evidenced, and submitted.
  • It authorizes external assessor firms and lists them on its assessor directory; only those firms may validate an assessment.
  • It performs quality assurance on every submitted assessment and is the only party that issues a certification. An assessor cannot promise you a certificate.
  • It distributes results to your customers through its results distribution and report center.

There is no regulator. Enforcement is contractual: a customer requires a current certification, checks it at onboarding and renewal, and treats a lapse as a breach of contract or a reason not to renew. HITRUST can also revoke a certification if the underlying conditions were misrepresented or a required interim assessment is not completed.

Because HITRUST is a company, its rules, fees, and version timelines can change without a rulemaking process. The advisories page is the change feed; when a new framework version drops, new assessments must usually be created on it within weeks.

What is in scope

Scope in HITRUST is the set of systems, facilities, and organizational units you enter into MyCSF as the assessment boundary, plus the people and third parties that support them. HITRUST uses scoping factors (organization type, number of records, geographic footprint, regulatory obligations, and technical factors such as cloud use) to tailor the r2 requirement set; e1 and i1 use fixed sets, so scoping decides what is tested, not how many statements.

Scope spreads in predictable directions:

  • People: everyone with access to in-scope systems, including administrators at your managed service provider.
  • Suppliers and cloud platforms: HITRUST allows inheritance, where a provider that holds its own HITRUST certification (major cloud platforms do) lets you inherit its scores for shared controls. Inheritance can remove a large share of your testing burden; it is also the first thing to confirm with your assessor.
  • Interfaces: where in-scope systems exchange data with out-of-scope systems. Assessors test the boundary controls.
  • Locations: every office or data center where in-scope systems or their administrators sit.

A scope exercise you can run this week:

  1. List the product or service the customer is buying.
  2. Name every system that stores, processes, or transmits its data, including logging, backup, and support tools.
  3. Identify the cloud providers and vendors involved, and check which hold HITRUST certifications you could inherit from.
  4. List the teams and locations that administer those systems.
  5. Write a scope statement of two or three sentences and check it against the customer’s expectation.

Narrow scopes are legitimate and cheaper. They do not reduce the obligations inside the boundary, and a scope that excludes the system the customer actually uses fails the customer even if it passes HITRUST.

What HITRUST CSF requires

The framework organizes requirement statements into 19 assessment domains (information protection program, endpoint protection, portable media, mobile devices, wireless, configuration management, vulnerability management, network protection, transmission protection, password management, access control, audit logging and monitoring, education and awareness, third-party assurance, incident management, business continuity, risk management, physical security, data protection and privacy). Each statement is mapped to the authoritative sources it satisfies, so a single piece of evidence can count toward HIPAA, NIST, and ISO at once.

What you are tested against depends on the assessment:

  • e1 (Essentials, one year) tests 43 requirement statements covering foundational hygiene. Only the Implemented maturity level is scored.
  • i1 (Implemented, one year) tests 182 requirement statements, including all e1 statements, chosen by HITRUST to address current threat activity. Implemented level only. In year two, a rapid recertification retests about 60 statements when scope has not materially changed.
  • r2 (Risk-based, two years) tests a tailored set averaging around 350 statements, selected from the scoping factors, and scores each on five maturity levels: policy, procedure, implemented, measured, and managed. Certification requires meeting a scoring threshold in every domain, with corrective action plans for gaps, and an interim assessment at twelve months to keep the certificate for its second year.

The sets are cumulative: e1 statements are inside i1, and i1 statements are inside r2, so work carries upward if you move tiers.

The documents that matter, and how much weight each carries:

  • The HITRUST Framework itself is downloadable free for internal use after registration; the working copy lives in MyCSF.
  • The HITRUST Assessment Handbook is the rulebook for how assessments are scoped, scored, validated, and certified. It is the document to read before you budget.
  • HITRUST Assurance Advisories are binding program changes, including version deadlines for new assessments.
  • The assessment pages for e1, i1, and r2 describe the current tier definitions.

HITRUST also offers add-on assessments (an AI security assessment, and NIST Cybersecurity Framework and other authoritative-source reports generated from the same data). Ask whether a customer needs any of them before buying; most do not.

How compliance is validated

HITRUST is validated by certification, and the path has more moving parts than a typical audit:

  1. Self-assessment in MyCSF. You, or a consultant on your behalf, score every requirement statement in scope against the maturity levels being tested and attach evidence.
  2. Validation by an Authorized External Assessor. The assessor firm tests your scores and evidence (interviews, inspection, sampling) inside a fieldwork window of up to 90 days, adjusts scores it cannot support, and submits the validated assessment to HITRUST.
  3. HITRUST quality assurance. HITRUST reviews the assessor’s work, can send it back with questions, and decides. This queue adds weeks and is outside anyone’s control but HITRUST’s.
  4. Certification and report. HITRUST issues the report and certification letter, and results become shareable with customers.

A readiness assessment is an optional, unvalidated pass through the same MyCSF object to find gaps before paying for validation. Most first-time organizations do one.

The result is a point-in-time certification tied to a scope: e1 and i1 for one year, r2 for two years contingent on the interim assessment. It is not a permanent seal, and HITRUST can revoke it.

Who may perform the work

Only firms on HITRUST’s Authorized External Assessor list may validate an assessment, and their staff must hold HITRUST practitioner credentials. The same firm may not both build your program and validate it in the same cycle, so readiness consultants and assessors are usually different companies. Aeris Secure performs readiness and remediation work; it does not validate or certify HITRUST assessments.

Verify an assessor by finding it on HITRUST’s list, not by the firm’s marketing. Verify a certification by asking for the HITRUST-issued report and letter, and note the scope, tier, and dates on it.

The HITRUST CSF certification process

A first certification usually runs three to four months for an e1, six to nine for an i1, and nine to fifteen for an r2. The steps:

  1. Confirm the obligation. Which tier, which scope, by when, and whether the customer will accept a lower tier or a SOC 2 report in the meantime.
  2. Subscribe to MyCSF and create the assessment object on the current framework version. Answer the scoping factors.
  3. Readiness. Self-score, identify gaps, and confirm inheritance from cloud providers.
  4. Remediate, focusing on statements scored below threshold; for r2, documented policies and procedures count as much as implementation.
  5. Engage the assessor for validation fieldwork.
  6. HITRUST QA and certification.
  7. Maintain. Recertify annually (e1, i1) or complete the r2 interim assessment and recertify at two years.

Who decides, and what to ask them

The party that decides your real obligation is the customer’s vendor risk, security, or procurement team that wrote HITRUST into the contract or questionnaire. Your sales contact relayed the ask; get the security contact directly.

Ask, and keep the answers in writing:

  • Which assessment tier satisfies them: e1, i1, or r2? If r2, is that negotiable for your risk profile?
  • Which systems and services must be inside the scope?
  • What is the deadline, and is it tied to signature, go-live, or renewal? Will a readiness letter or a scheduled assessment date satisfy them in the meantime?
  • Will they accept a SOC 2 report or an ISO/IEC 27001 certificate instead, permanently or as a bridge?
  • Do they need any add-on reports (NIST CSF, AI security)?
  • How will they receive the results: through HITRUST’s distribution, or a copy of the report?

The tier answer is the budget. An e1 and an r2 can differ by a factor of five to ten in assessor fees and by a year in calendar time.

Reality check: the calendar is consumed by remediation, evidence gathering, and the HITRUST QA queue, not by assessor fieldwork. Assessor firms and HITRUST QA both book weeks out, so engage early.

Cost, time, and internal effort

The cost range on this page covers external assessor fees plus the HITRUST report credit for an i1 validated assessment, the tier most first-time vendor certifications now target. That definition keeps standards comparable across this site, and it is the number you can check against a quote.

By tier, the fees paid to the assessor and to HITRUST:

  • e1: roughly $18,000 to $45,000, including a report credit of about $6,000.
  • i1: roughly $40,000 to $90,000, including a report credit of about $7,000. Rapid recertification in year two is materially cheaper.
  • r2: roughly $70,000 to $260,000, including a report credit of about $8,000 to $9,000, with large multi-site scopes exceeding that. The interim assessment at twelve months adds a smaller fee.
  • MyCSF subscription: $3,000 to $35,000 per year, paid to HITRUST and required. Short-term access covers an e1; enterprise tiers cover multi-system r2 programs.

Outside the range above:

  • readiness consulting, commonly $10,000 to $50,000 for an i1 and $25,000 to $120,000 for an r2 when used;
  • remediation, penetration testing, and tooling the readiness pass shows you need;
  • internal hours, which published estimates put at 150 to 300 for an e1, 250 to 500 for an i1, and 300 to 600 or more for an r2, with large r2 scopes running far higher; and
  • second-cycle costs, since certifications expire every one or two years.

The page’s cost and effort ranges are directional, not a quote. The best predictors are the tier, the number of systems and locations in scope, how much you can inherit from certified cloud providers, and how far your documented policies and procedures are from the maturity levels scored.

Time follows the same pattern. An e1 at a small, cloud-hosted vendor can finish in a few months. A first r2 at an organization without written policies is a year or more, most of it before the assessor arrives.

Maintaining compliance

Certification runs on a one- or two-year clock, and the framework version moves underneath you. A typical operating rhythm:

  • Recertify on time. e1 and i1 expire at one year; a new validated assessment (or an i1 rapid recertification) must complete before then. r2 requires the interim assessment in the 90-day window before the first anniversary or the certificate lapses at twelve months.
  • Track framework versions. New e1 and i1 assessments must be created on the current version (v11.8.0 as of May 2026); HITRUST announces creation and submission deadlines in advisories with as little as 90 days’ notice.
  • Work corrective action plans. r2 gaps carry documented plans that the interim assessment checks.
  • Keep evidence flowing: access reviews, training records, vulnerability scans, log review, vendor reviews, and incident records, on the cadences your policies state.
  • Run the risk assessment the framework’s risk management domain requires, at least annually and after major changes. The free risk assessment tool on this site produces a risk register and report in the browser without sending data anywhere.
  • Maintain the MyCSF subscription; lapsing it complicates the next assessment.

Scope changes silently: a new product, acquisition, cloud migration, or managed service provider can land inside or beside the boundary. Wire the assessment scope into change management and procurement so changes are reviewed before the assessor, or the customer, notices.

How to get started

If HITRUST has just landed on your desk, begin with five concrete actions:

  1. Get the tier and scope in writing. Ask the requesting customer which assessment they require, which systems must be inside it, and the deadline. Ask whether e1 or i1 would satisfy them if they said r2.
  2. Read the Assessment Handbook. The HITRUST Assessment Handbook explains scoring, validation, and certification rules in one place.
  3. Draft the scope statement and inheritance list. Name the systems, locations, and teams inside the boundary, and check which of your cloud providers hold HITRUST certifications you can inherit from.
  4. Run a first risk assessment and a readiness pass. Use a simple method (the risk assessment tool works) and walk the requirement statements for your target tier, scoring honestly. That draft becomes your MyCSF self-assessment.
  5. Get quotes from two or three Authorized External Assessors on the same scope and tier, ask each for its earliest fieldwork window, and confirm each on HITRUST’s assessor list before signing. Budget the MyCSF subscription separately.

For official starting points, use the HITRUST Framework page for the framework and version, the tier pages for e1, i1, and r2, and the advisories for deadlines.

The first goal is not 350 requirement statements. It is knowing which tier your customer will accept, for which scope, by when. Once those three answers are written down, the assessment is a project plan with a price, and the tier decision alone can save you more than any technical shortcut.

Assessments

e1

Who does it apply to?
Low-risk vendors, early-stage companies, and organizations taking a first step toward a higher tier. Also used by larger organizations to assure lower-risk suppliers.
Who audits / assesses?
A HITRUST Authorized External Assessor validates your MyCSF self-assessment; HITRUST performs quality assurance and issues the certification.
What report is required?
HITRUST e1 validated assessment report and certification, valid for one year. A full e1 assessment is repeated annually.
Typical cost
$18,000 – $45,000
Org effort
100 – 300 hours

The e1 (Essentials, one-year) is the smallest HITRUST assessment: 43 requirement statements covering foundational cybersecurity hygiene such as patching, access control, logging, and endpoint protection. Only the Implemented maturity level is scored, so the question for each statement is whether the control is in place and working, not whether it is documented and measured.

It exists for organizations whose customers want independent validation without the cost of an i1 or r2: startups, low-risk service providers, and suppliers to organizations that use e1 as a floor for their own vendor programs. HITRUST describes fieldwork completing in as little as four to six weeks for ready organizations; three to four months from decision to certification is typical.

Every e1 statement is also part of the i1 and r2 sets, so an e1 is a building block rather than a dead end. If the customer’s contract says “HITRUST certification” without a tier, confirm in writing that an e1 satisfies them before you scope one; many payers mean r2.

i1

Who does it apply to?
Growing vendors and SaaS providers entering healthcare markets whose customers require moderate, independently validated assurance but do not name r2.
Who audits / assesses?
A HITRUST Authorized External Assessor validates your MyCSF self-assessment; HITRUST performs quality assurance and issues the certification.
What report is required?
HITRUST i1 validated assessment report and certification, valid for one year. Year two may use a rapid recertification that retests about 60 statements when scope has not materially changed.
Typical cost
$40,000 – $90,000
Org effort
250 – 500 hours

The i1 (Implemented, one-year) tests 182 requirement statements, the 43 e1 statements plus 139 more that HITRUST selects and refreshes to address current threat activity. It is a fixed set, so scoping decides which systems are tested, not how many statements. Only the Implemented maturity level is scored.

The i1 has become the common first certification for vendors selling into health systems and payers that want more than an e1 but have not written r2 into the contract. Six to nine months from decision to certification is typical; the assessor’s fieldwork window is capped at 90 days.

Maintenance is lighter than r2’s: the certificate lasts one year, and if scope has not materially changed, year two can use a rapid recertification that retests roughly 60 statements at a lower fee, followed by a full i1 again in year three. Because every i1 statement sits inside r2, i1 work carries forward if a customer later requires the higher tier.

r2

Who does it apply to?
Organizations whose customers require HITRUST's highest assurance, most often business associates and vendors to large payers and health systems, and any contract that names r2 specifically.
Who audits / assesses?
A HITRUST Authorized External Assessor validates your MyCSF self-assessment across five maturity levels; HITRUST performs quality assurance and issues the certification.
What report is required?
HITRUST r2 validated assessment report and certification, valid for two years, contingent on an interim assessment completed in the 90 days before the first anniversary.
Typical cost
$70,000 – $260,000
Org effort
500 – 1,200 hours

The r2 (Risk-based, two-year) is HITRUST’s most rigorous assessment. Instead of a fixed set, MyCSF tailors the requirement statements from your scoping factors (organization type, record volume, geography, regulatory obligations, and technical factors such as cloud and remote access), producing a set that averages around 350 statements and can run much higher. Each statement is scored on five maturity levels: policy, procedure, implemented, measured, and managed. Certification requires meeting a scoring threshold in every domain, with corrective action plans for the rest.

The r2 is what large payers and health systems usually mean when they write “HITRUST certification” into a contract, and it is the tier that maps most completely to HIPAA, NIST SP 800-53, and other regulatory sources. Nine to fifteen months from decision to certification is typical for a first r2, most of it spent writing policies and procedures and gathering evidence, because documentation is scored, not just implementation.

The certificate lasts two years, but only if an interim assessment is completed in the 90-day window before the first anniversary. The interim retests one statement per domain and reviews progress on corrective action plans. Miss the window and the certificate lapses at twelve months. Inheritance from HITRUST-certified cloud providers matters most at this tier, where it can remove a large share of the tailored statements from your own testing.

Version history

VersionStatusReleasedEffectiveRetiredSummary
v11 current Jan 18, 2023Jan 18, 2023n/aIntroduced the portfolio of e1, i1, and r2 assessments on one framework with cumulative requirement sets, so results carry forward between tiers. Point releases roughly twice a year add and refresh authoritative source mappings; v11.8.0 (May 7, 2026) is current and required for new e1 and i1 assessments.
v9 retired
→ v11
Sep 1, 2017n/aJan 18, 2023The long-running series (v9.0 through v9.6) that most healthcare organizations first certified against. Introduced the NIST Cybersecurity Framework mapping and, in v9.x, the i1 assessment ahead of the v11 portfolio.
v1 retired
→ v9
Mar 1, 2009n/aSep 1, 2017First release of the Common Security Framework, built for healthcare on ISO/IEC 27001 and 27002 with HIPAA, PCI DSS, and state law mappings. Intermediate releases through v8 expanded the sources and the assessment program.

New versions are announced in news. Follow this standard to get notified.