The HITRUST interim assessment is the year-one checkpoint inside a two-year r2 certification: HITRUST’s own statement is that the r2 “is valid for two years”, that “organizations must complete an interim assessment after one year to confirm continued compliance”, and that “a full assessment is required at the end of the two-year certification period to maintain status”. It is the reason the r2’s higher entry cost spreads over two years, and it is the step most often mishandled — treated either as a formality or as a second full assessment, when it is neither.
The i1 has its own year-two mechanism, the rapid recertification on approximately 60 core controls, and the e1 has none: it renews in full every year. This guide sets out what the interim confirms and how it differs from the full assessment, what evidence it needs, how it interacts with changes to the environment, the rapid recertification for i1, the timing that keeps a certificate continuous, and the five ways year two goes wrong.

What the HITRUST interim assessment confirms
The r2 certificate rests on a validated assessment of a tailored requirement set scored on maturity. A year later, the interim asks a narrower question: is the organisation still operating the controls at the level certified, and have the corrective action plans agreed at certification been carried out? It is performed with the External Assessor, submitted through MyCSF, and reviewed by HITRUST; if it confirms continued compliance the certificate runs to the end of its second year, and if it does not, the certificate is at risk. It is not a re-scoring of every requirement — that is the full assessment at the end of year two. Our guide to HITRUST assessments covers the r2 alongside the e1 and i1.
HITRUST interim assessment against the full assessment
| Full r2 validated assessment | HITRUST interim assessment | |
|---|---|---|
| When | Before certification, and again at the end of the two-year period | After year one of the certificate |
| Scope | Every requirement statement in the tailored set, scored across the maturity levels | Continued compliance: a sample of controls, the corrective action plans, and any changes to scope or environment |
| Purpose | Establish the certification | Confirm it still holds so the certificate continues |
| Assessor effort | Full testing and validation | Materially less — a fraction of the full engagement |
| HITRUST review | Full quality assurance | Review of the interim submission |
| Outcome | Certification for two years | Certificate continues to the end of year two, or is placed at risk |
What the HITRUST interim assessment needs
- Corrective action plan evidence. Requirements certified with CAPs — gaps accepted at certification with a remediation commitment — are the first thing checked; a CAP not completed on schedule is the classic interim finding.
- Operating evidence for the sampled controls. Logs, records and metrics from the intervening year; controls that were implemented at certification and never operated since fail here.
- A change record. New systems, facilities, providers or services since certification; material changes can widen scope or require re-validation of affected requirements.
- Inheritance status. Inherited controls depend on the provider’s certificate remaining valid; a lapsed provider certificate breaks the inheritance.
- The measured and managed levels, still running. The metrics and the actions on them that earned the maturity score at certification have to exist for the year in between.
The i1 rapid recertification
The i1 is valid for one year, and HITRUST’s page describes its year-two mechanism: “a rapid recertification process in year two” that focuses “on approximately 60 core controls rather than the full 182-control set”, reducing “the time and effort required to maintain their validated status”. It is the i1’s equivalent of the interim — a lighter year-two engagement — with the difference that it produces a new one-year certification rather than continuing an existing one, and that year three returns to the full 182-control assessment. Our guide to HITRUST certification cost works the three-year arithmetic for each level.
Timing that keeps the certificate continuous
| Milestone | r2 | i1 | e1 |
|---|---|---|---|
| Certification issued | Month 0 | Month 0 | Month 0 |
| Year-two engagement | Interim assessment due after year one — plan the assessor engagement from month 9 | Rapid recertification before the one-year expiry — plan from month 8 | Full assessment before the one-year expiry |
| Renewal | Full validated assessment before the end of month 24 — plan from month 18 | Full 182-control assessment before the end of year two’s certificate | Every year |
| Risk | A late interim or a failed one puts the certificate at risk mid-term | A gap between certificates if the rapid recertification runs late | Annual gap risk |
Two dates matter more than the rest: the HITRUST interim assessment has to be completed, not started, after year one, and the year-two full assessment has to be validated and quality-assured before the certificate expires — which, given assessor scheduling and HITRUST review time, means starting in the third quarter of the second year.
Five ways year two goes wrong
- CAPs forgotten. The remediation plan agreed at certification had owners who left; the interim finds it untouched.
- Controls that stopped. A quarterly access review performed once, for the assessor, in year one.
- Scope drift. A new product on new infrastructure, never declared, discovered at the interim.
- Provider certificate lapsed. Inherited controls with no valid result behind them.
- Late start. The full year-two assessment begun in month 22, with the certificate expiring before HITRUST’s review completes.
Running year two well
- Track CAPs monthly from the day the certificate issues.
- Keep the measured-level metrics running and the managed-level actions recorded.
- Log every material change against the certified scope and assess its effect with the assessor as it happens.
- Monitor inherited providers’ certificates.
- Book the interim from month 9 and the renewal from month 18, in MyCSF, with the same assessor where possible. Our guide to MyCSF covers where all of this is recorded.
Frequently asked questions
What is the HITRUST interim assessment?
The year-one checkpoint in a two-year r2 certification: HITRUST requires an interim assessment after one year to confirm continued compliance, with a full assessment at the end of the two-year period to maintain status. It samples controls, checks corrective action plans and changes, and is materially lighter than the full assessment.
Does the i1 have an interim?
Not as such; the i1 is valid for one year and offers a rapid recertification in year two on approximately 60 core controls instead of the full 182, returning to a full assessment the year after.
Does the e1 have one?
No. The e1 is valid for one year and is renewed with a full assessment annually.
What happens if the interim finds problems?
The certificate is at risk; uncompleted corrective action plans and controls that stopped operating are the usual findings, and remediation on a timeline agreed with the assessor and HITRUST is the usual route.
Who performs it?
The organisation’s authorised External Assessor, through MyCSF, with HITRUST reviewing the submission.
Where this leaves you
Plan the HITRUST interim assessment from the day the r2 certificate issues: CAPs tracked, metrics running, changes logged, providers monitored, and the assessor booked from month nine — then the year-two full assessment from month eighteen. The interim is lighter than the full assessment and heavier than a formality; the certificate depends on treating it as the second.
References
- HITRUST: r2 assessment — Two-year validity, the interim assessment after one year and the full assessment at the end of the period.
- HITRUST: i1 assessment — Rapid recertification in year two on approximately 60 core controls.
- HITRUST: e1 assessment — One-year validity, renewed annually.
More on HITRUST
- HITRUST interim assessment — you are here
- HITRUST assessments: e1, i1 and r2
- HITRUST certification cost
- MyCSF: the assessment platform
- HITRUST scoring: the five maturity levels
- Choosing a HITRUST External Assessor
The Continuous Monitoring and Interim Assessment Strategy, the Plan of Action and Milestones Template, the Internal Assessment Plan and Report, the Metrics and KPI Catalog and the Exception Register are in the HITRUST CSF v11 Toolkit, or start with the free templates.