HITRUST scoring is what separates a HITRUST assessment from a control checklist. Each requirement is not marked present or absent — it is scored across maturity levels, and a control you perform reliably but never measure will still cost you points.
This guide covers the five maturity levels, how they are weighted, what the domain threshold means for certification, and where scores are lost.

The five maturity levels
HITRUST uses a maturity model derived from PRISMA. Every requirement statement is evaluated at each level:
| Level | What is being tested | Evidence |
|---|---|---|
| Policy | Is the requirement mandated in an approved document? | Approved policy covering every element of the requirement |
| Procedure | Is there a documented method, with roles and steps? | Procedure naming who does what, when and how |
| Implemented | Is it actually operating across the scope? | Configuration, records, samples, system output |
| Measured | Is its effectiveness measured, not just its existence? | Metrics, tests, audit results with thresholds |
| Managed | Does the organization act when measurement shows a problem? | Remediation records traceable to the measurement |
Each level is scored on how completely the requirement’s elements are covered — coverage — and how rigorously the maturity criteria are met — strength. The two combine into the level score, and the level scores combine into the requirement score.
The weighting nobody expects
In HITRUST scoring the first three levels carry most of the weight. Measured and Managed together are worth roughly what any one of Policy, Procedure or Implemented is worth on its own. That design is deliberate: it stops an organization with excellent documentation and no operation from scoring well, while still rewarding the continuous monitoring that distinguishes a live control from an implemented-and-forgotten one.
The practical read: you cannot certify on documentation, and you cannot reach a strong score without measuring something. Most organizations arrive with the first three levels solid and lose their margin entirely at Measured.
What HITRUST scoring requires for certification
Requirement statements are distributed across assessment domains, and the certification test is applied by domain: each domain needs an average maturity score at or above the required level. A single weak requirement rarely fails you — a domain where nothing is measured will.
That has a direct consequence for remediation planning. Sort your gaps by domain, not by severity. Three small improvements inside a failing domain are worth more than one large improvement in a domain already comfortably above the line. Our guide to the e1, i1 and r2 assessments covers which assessment type applies before you get to the scoring at all.
Where HITRUST scoring points are lost
Policy that does not cover every element. Requirement statements often contain several distinct obligations. A policy covering three of four elements does not score three-quarters by accident — it scores on the assessor’s coverage judgement, and partial coverage is expensive.
Procedure written as policy. The two levels test different things. A restatement of the policy in the procedure document scores at Policy and adds nothing at Procedure.
Implementation demonstrated in one place. Scope coverage matters. Evidence from one system, when the requirement applies to twelve, is partial implementation.
Metrics without thresholds. A number with no target is not measurement. Measured needs a defined threshold and a comparison against it.
No trace from measurement to action. Managed is about what happened when the measurement was bad. If nothing was ever bad, the more likely explanation is that nothing was ever measured properly.
Preparing so the score is not a surprise
- Run the HITRUST scoring yourself first. Score each requirement at all five levels yourself, honestly, and identify the domain averages.
- Map evidence per level. One artifact rarely serves two levels. Keep a matrix of requirement, level, artifact and owner.
- Fix by domain. Prioritise the domains below the threshold rather than the individually worst requirements.
- Build measurement early. Metrics need history. Standing up a measure a month before the assessment produces a thin record and a low score.
- Confirm the CSF version. Requirement sets change between versions, and preparing against the wrong one wastes a cycle.
Frequently asked questions
What are the HITRUST maturity levels?
Policy, Procedure, Implemented, Measured and Managed. Each requirement is scored at every level, and the level scores roll up into the requirement score.
What score is needed to certify?
Certification turns on domain averages meeting the required maturity level across the assessment domains, rather than on any single requirement passing.
Do all five levels apply to every assessment?
The maturity model applies to the validated assessments; the lighter assessment types work against a smaller requirement set. Check which model applies to the assessment you are pursuing.
Can we certify without measuring anything?
Not comfortably. Measured and Managed carry less weight than the first three levels, but a domain that scores zero on both will usually fall below the threshold.
How is HITRUST scoring different from a SOC 2 opinion?
SOC 2 produces an auditor’s opinion with exceptions described in narrative. HITRUST scoring produces a number per requirement and per domain, which is why customers can compare two HITRUST reports in a way they cannot compare two SOC 2 reports.
Where this leaves you
Treat HITRUST scoring as five separate tests per requirement, not one. Write policies that cover every element of the requirement statement, keep procedures genuinely procedural, and demonstrate implementation across the whole scope rather than one representative system. Then invest early in measurement with real thresholds and a record of what you did when a threshold was missed — that is where the margin between passing and failing a domain actually lives.
References
- HITRUST Alliance — the CSF, assessment types and scoring methodology.
- HHS — HIPAA Security Rule — the regulatory obligation most HITRUST programmes are ultimately evidencing.
More on healthcare assurance
- HITRUST scoring — you are here
- HITRUST e1, i1 and r2
- HITRUST vs HIPAA
- The HIPAA risk assessment
Policy sets, procedure templates and an evidence matrix are in the HITRUST CSF v11 Toolkit, or start with the free ISO templates.