HITRUST assessments come in three sizes, and choosing the wrong one is the most expensive decision in the whole programme. The e1, the i1 and the r2 differ in how many requirements you answer, how long the result lasts, and what a customer can conclude from it — and moving up a level later is not a discount on work already done.
This guide sets out what each assessment contains, how long each certification lasts, and the test for deciding which one your customers actually need.

The three HITRUST assessments compared
| e1 | i1 | r2 | |
|---|---|---|---|
| Scale | 43 foundational controls | 182 core requirements | Tailored by a risk questionnaire — commonly several hundred |
| What it demonstrates | Essential cybersecurity hygiene, independently validated | Leading practices implemented across a broad control set | Risk-based assurance tailored to the organization and its regulatory scope |
| Validity | One year | One year, with a rapid recertification option | Two years, with an interim assessment at year one |
| Typical fit | Small vendors, low-risk services, first entry into the programme | Mid-market vendors whose customers ask for real assurance | Organizations handling regulated data at scale, or contractually required to certify |
Why the sizes are not simply “more controls”
The three HITRUST assessments are not simply the same exercise at three sizes. The e1 is a fixed set of foundational controls designed to be defensible quickly. The i1 is a fixed set too, but a far larger one aimed at leading practice. The r2 is different in kind: the requirement set is generated from a risk questionnaire about your organization, the data you handle and the regulatory factors that apply, so two r2 assessments are rarely the same size.
That difference drives the effort. Adding controls to a fixed set is planning work; producing an r2 is a scoping exercise with an assessor before any evidence is gathered. It is also why an r2 carries the most weight with a demanding customer — the scope was derived from your risk, not from a template.
Which of the HITRUST assessments do your customers need?
Three questions settle it in most cases:
- What has a customer actually asked for, in writing? Contracts that name HITRUST usually name the assessment type. If yours does not, ask before scoping — an e1 delivered against an r2 expectation is a wasted year.
- What data do you hold, and under what regime? Regulated health data at volume points to r2. A supporting service with narrow access may be well served by e1 or i1.
- How long do you need the result to last? An annual cycle at e1 or i1 is real recurring cost; the r2’s two-year term with an interim review can be cheaper across a three-year horizon despite the higher entry cost.
A common and sensible pattern is to enter at e1 to establish validated assurance quickly, then move to i1 or r2 as customer demands sharpen. What does not work is treating the e1 as a rehearsal that will be reused wholesale — the requirement statements differ, and evidence gathered for 43 controls does not populate 182.
Which CSF version your HITRUST assessments run against
HITRUST maintains the CSF on a versioned release cycle, and assessments are created against a specific version. CSF v11.7.0 became the operative release in December 2025, with defined cut-off dates after which new assessments could no longer be created on the previous version and, later, could no longer be submitted on it.
Two practical consequences. First, check which version your assessment will be created against before you scope — a late version change mid-project means re-mapping requirement statements. Second, when a customer’s questionnaire asks for “HITRUST certification”, the useful answer names the assessment type and the CSF version, because those two together are what another organization can actually rely on.
HITRUST assessments against the alternatives
HITRUST’s distinguishing feature is that it is prescriptive where other frameworks are not. HIPAA sets requirements but leaves the implementation argument open, which is precisely why healthcare vendors end up in questionnaire cycles — our guide to HITRUST vs HIPAA covers that gap. SOC 2 gives an auditor’s opinion against criteria you help select; ISO 27001 certifies a management system. HITRUST scores defined requirement statements and issues a certification with a published scope.
For a vendor selling into healthcare, the honest calculation is not which framework is best but which one ends the questionnaires. In that market, a validated HITRUST assessment usually does, and the level determines how completely.
Frequently asked questions
How many requirements are in each HITRUST assessment?
The e1 is built on 43 foundational controls and the i1 on 182 core requirements. The r2’s set is generated from a risk questionnaire, so it varies by organization and is typically much larger.
How long is each certification valid?
e1 and i1 are valid for one year — the i1 offers a rapid recertification route — and the r2 is valid for two years with an interim assessment after the first.
Can we upgrade from e1 to r2?
You can move up, but not for free. The requirement statements differ, so evidence has to be extended rather than simply reused.
Does HITRUST certification make us HIPAA compliant?
No. It gives you a defensible, independently validated control position that maps to HIPAA requirements, which is a much stronger negotiating position than an unaudited assertion — but compliance remains a legal obligation, not a certificate.
Which CSF version will our assessment use?
Whichever release is operative when the assessment is created, subject to HITRUST’s cut-off dates for creation and submission on older versions. Confirm it at scoping.
Where this leaves you
Pick the HITRUST assessment from what your customers contractually require and the data you actually hold, not from what looks achievable this quarter. Enter at e1 if you need validated assurance quickly, budget for the annual cycle at e1 and i1, and treat the r2 as a scoping exercise with an assessor rather than a bigger version of the same work. And whenever you state your position to a customer, name both the assessment type and the CSF version — that pair is the only thing they can rely on.
References
- HITRUST — e1 assessment — the foundational control count and the one-year validity.
- HITRUST — assessments and certifications — the e1, i1 and r2 portfolio.
More on healthcare assurance
- HITRUST assessments — you are here
- HITRUST vs HIPAA: five differences
- SOC 2 vs HIPAA
- The HIPAA compliance checklist
Control mappings, evidence records and the scoping artefacts are in the HITRUST CSF Toolkit, or start with the free ISO templates.