Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

The three HITRUST assessment types

HITRUST Assessments: A Clear Guide to e1, i1 and r2

HITRUST assessments come in three sizes, and choosing the wrong one is the most expensive decision in the whole programme. The e1, the i1 and the r2 differ in how many requirements you answer, how long the result lasts, and what a customer can conclude from it — and moving up a level later is not a discount on work already done.

This guide sets out what each assessment contains, how long each certification lasts, and the test for deciding which one your customers actually need.

HITRUST assessments compared: e1, i1 and r2 by requirements, validity and purpose
Three assessments, three levels of assurance — and three different renewal cycles.

The three HITRUST assessments compared

  e1 i1 r2
Scale 43 foundational controls 182 core requirements Tailored by a risk questionnaire — commonly several hundred
What it demonstrates Essential cybersecurity hygiene, independently validated Leading practices implemented across a broad control set Risk-based assurance tailored to the organization and its regulatory scope
Validity One year One year, with a rapid recertification option Two years, with an interim assessment at year one
Typical fit Small vendors, low-risk services, first entry into the programme Mid-market vendors whose customers ask for real assurance Organizations handling regulated data at scale, or contractually required to certify

Why the sizes are not simply “more controls”

The three HITRUST assessments are not simply the same exercise at three sizes. The e1 is a fixed set of foundational controls designed to be defensible quickly. The i1 is a fixed set too, but a far larger one aimed at leading practice. The r2 is different in kind: the requirement set is generated from a risk questionnaire about your organization, the data you handle and the regulatory factors that apply, so two r2 assessments are rarely the same size.

That difference drives the effort. Adding controls to a fixed set is planning work; producing an r2 is a scoping exercise with an assessor before any evidence is gathered. It is also why an r2 carries the most weight with a demanding customer — the scope was derived from your risk, not from a template.

Which of the HITRUST assessments do your customers need?

Three questions settle it in most cases:

  1. What has a customer actually asked for, in writing? Contracts that name HITRUST usually name the assessment type. If yours does not, ask before scoping — an e1 delivered against an r2 expectation is a wasted year.
  2. What data do you hold, and under what regime? Regulated health data at volume points to r2. A supporting service with narrow access may be well served by e1 or i1.
  3. How long do you need the result to last? An annual cycle at e1 or i1 is real recurring cost; the r2’s two-year term with an interim review can be cheaper across a three-year horizon despite the higher entry cost.

A common and sensible pattern is to enter at e1 to establish validated assurance quickly, then move to i1 or r2 as customer demands sharpen. What does not work is treating the e1 as a rehearsal that will be reused wholesale — the requirement statements differ, and evidence gathered for 43 controls does not populate 182.

Which CSF version your HITRUST assessments run against

HITRUST maintains the CSF on a versioned release cycle, and assessments are created against a specific version. CSF v11.7.0 became the operative release in December 2025, with defined cut-off dates after which new assessments could no longer be created on the previous version and, later, could no longer be submitted on it.

Two practical consequences. First, check which version your assessment will be created against before you scope — a late version change mid-project means re-mapping requirement statements. Second, when a customer’s questionnaire asks for “HITRUST certification”, the useful answer names the assessment type and the CSF version, because those two together are what another organization can actually rely on.

HITRUST assessments against the alternatives

HITRUST’s distinguishing feature is that it is prescriptive where other frameworks are not. HIPAA sets requirements but leaves the implementation argument open, which is precisely why healthcare vendors end up in questionnaire cycles — our guide to HITRUST vs HIPAA covers that gap. SOC 2 gives an auditor’s opinion against criteria you help select; ISO 27001 certifies a management system. HITRUST scores defined requirement statements and issues a certification with a published scope.

For a vendor selling into healthcare, the honest calculation is not which framework is best but which one ends the questionnaires. In that market, a validated HITRUST assessment usually does, and the level determines how completely.

Frequently asked questions

How many requirements are in each HITRUST assessment?
The e1 is built on 43 foundational controls and the i1 on 182 core requirements. The r2’s set is generated from a risk questionnaire, so it varies by organization and is typically much larger.

How long is each certification valid?
e1 and i1 are valid for one year — the i1 offers a rapid recertification route — and the r2 is valid for two years with an interim assessment after the first.

Can we upgrade from e1 to r2?
You can move up, but not for free. The requirement statements differ, so evidence has to be extended rather than simply reused.

Does HITRUST certification make us HIPAA compliant?
No. It gives you a defensible, independently validated control position that maps to HIPAA requirements, which is a much stronger negotiating position than an unaudited assertion — but compliance remains a legal obligation, not a certificate.

Which CSF version will our assessment use?
Whichever release is operative when the assessment is created, subject to HITRUST’s cut-off dates for creation and submission on older versions. Confirm it at scoping.

Where this leaves you

Pick the HITRUST assessment from what your customers contractually require and the data you actually hold, not from what looks achievable this quarter. Enter at e1 if you need validated assurance quickly, budget for the annual cycle at e1 and i1, and treat the r2 as a scoping exercise with an assessor rather than a bigger version of the same work. And whenever you state your position to a customer, name both the assessment type and the CSF version — that pair is the only thing they can rely on.

References

More on healthcare assurance

Control mappings, evidence records and the scoping artefacts are in the HITRUST CSF Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.