HITRUST Assessment Types
HITRUST offers three assessment types designed for different organizational needs, risk profiles, and maturity levels: the e1, the i1, and the r2. All three draw from the same CSF, all three run through MyCSF, all three are validated by an external assessor and quality-assured by HITRUST, and all three produce a genuine HITRUST certification. What differs is scope, scoring depth, cost — and, critically, what your customers will accept.
Understanding the differences helps you choose the right starting point and plan your HITRUST journey without over-buying assurance you do not need or under-buying assurance your contracts require.
The portfolio is deliberately nested: the e1's 44 requirements are a subset of the i1's roughly 180, which are in turn a subset of the r2's risk-based set. Work done at one level carries forward to the next — HITRUST calls this the traversable "assessment portfolio," and it is the foundation of the progression strategy at the end of this lesson.
e1 Assessment (Essentials)
The e1 is HITRUST's entry-level certifiable assessment, covering 44 foundational requirement statements focused on essential cybersecurity hygiene: access control, MFA, patching, endpoint protection, logging basics, incident response fundamentals. It is scored on implementation only — is the control actually operating — with no policy/procedure maturity scoring. The e1 results in a one-year certification.
Do not confuse "essentials" with "informal": the e1 goes through the same external assessor validation and centralized HITRUST QA as an r2. It is a real certification with the credibility of the HITRUST QA process behind it, which is exactly why it has become popular as a first proof point and as a vendor-tiering tool for large organizations assessing their lower-risk suppliers.
Best for: startups facing their first healthcare security reviews, lower-risk vendors in a customer's third-party program, and organizations beginning a deliberate progression toward i1 or r2. Timeline: roughly 3 to 6 months including preparation. Cost: commonly $20,000 to $50,000 all-in, including assessor fees and the MyCSF subscription.
i1 Assessment (Implemented)
The i1 is the moderate-assurance assessment, covering approximately 180 requirement statements representing leading security practices. Its requirement selection is threat-adaptive: HITRUST tunes the i1 control set against current attack data (ransomware, phishing, credential abuse) with each CSF release, so an i1 certification asserts coverage of the techniques actually being used against organizations now. Like the e1, the i1 scores implementation only — controls must demonstrably operate, but you are not scored on policy and procedure maturity. The i1 results in a one-year certification, with an important efficiency feature: in alternating years, qualifying organizations can use a rapid recertification, a lighter-weight validation that tests a sample of requirements rather than the full set, roughly halving the effort of every second year.
Best for: mid-sized health tech vendors, organizations whose customers want "real HITRUST" but do not name r2, and companies staging toward r2. Timeline: roughly 4 to 8 months. Cost: commonly $30,000 to $80,000 including assessor fees.
r2 Assessment (Risk-Based)
The r2 is the comprehensive, expanded-practices assessment — what most people historically meant by "HITRUST certified." Its requirement set is generated from your risk factors in MyCSF (organizational, system, and regulatory), typically producing 250 to 400 or more requirement statements. Unlike e1 and i1, the r2 is scored on the PRISMA maturity model: every requirement is evaluated for policy, procedure, and implementation, with measured and managed earning additional credit — the scoring mechanics are detailed in the CSF lesson. Each of the 19 assessment domains must independently clear the certification threshold.
The r2 results in a two-year certification, contingent on an interim assessment at the one-year mark, where your assessor verifies a sample of controls and progress on corrective action plans. There is also a bridge assessment option — a short extension certificate for organizations whose r2 is expiring before recertification completes.
Best for: organizations whose customers or contracts explicitly require r2, vendors handling PHI at scale for major payers and health systems, and companies consolidating many frameworks into one program. Timeline: 6 to 18 months for a first certification. Cost: $50,000 to $200,000 or more across the cycle, with internal effort the biggest hidden cost.
Side-by-Side Comparison
| Dimension | e1 | i1 | r2 |
|---|---|---|---|
| Requirement statements | 44 fixed | ~180 fixed, threat-adaptive | ~250–400+, risk-factor tailored |
| Scoring | Implementation only | Implementation only | Full PRISMA maturity (policy, procedure, implemented, plus measured/managed credit) |
| Certification term | 1 year | 1 year (rapid recert alternate years) | 2 years with year-1 interim assessment |
| Assurance level | Essential hygiene | Leading practices, moderate assurance | High assurance, risk-based |
| External assessor + HITRUST QA | Yes | Yes | Yes |
| Corrective action plans (CAPs) | No gaps allowed for certified items | Limited | Yes, required for lower-scoring requirements |
| Typical timeline | 3–6 months | 4–8 months | 6–18 months |
| Typical all-in cost | $20k–$50k | $30k–$80k | $50k–$200k+ |
| Typical buyer acceptance | Vendor tiering, early-stage proof | Many enterprise reviews | Explicit r2 mandates, highest-risk relationships |
Choosing Your Assessment
Start with what your customers require — in writing, not in hallway summaries. The decision logic most organizations should follow:
- A contract or security addendum names r2? That is your target; the only question is timeline and whether an e1 or i1 can serve as an interim milestone the customer will accept.
- Customers say "HITRUST" without a level? Ask. Many security teams accept i1 for moderate-risk services; some accept e1 for low-risk ones. The difference is months of effort and six figures over a couple of years.
- No customer requirement yet, but healthcare is your market? e1 first. It is achievable, real, and upgradeable — and it forces the operational foundations every later level reuses.
- Handling massive PHI volumes or acting as core infrastructure for payers/providers? Skip the staging debate and plan for r2; your buyers will get there quickly anyway.
Also factor in your internal state honestly: an organization without documented policies and procedures should not start an r2, because the maturity scoring will punish exactly that gap. Get the e1 or i1 discipline of operating controls first, then build the documentation layer r2 demands.
The Progression Path
HITRUST designed the portfolio as a progression, and the nesting makes it efficient:
- Year 1 — e1. Certify the 44 essentials. Every one of them appears in the i1 and r2, so nothing is throwaway. Use the year to build evidence habits and fix hygiene gaps.
- Year 2 — i1. Add the remaining ~140 requirements. Your e1 evidence pipeline extends rather than restarts; rapid recertification later halves alternate-year effort.
- Year 3+ — r2 if demanded. The step change is not new controls so much as new depth: policies and procedures scored per requirement, maturity thresholds per domain, interim assessments. Begin drafting the policy/procedure layer during your i1 year so the r2 readiness phase shrinks.
Along the way, use inheritance aggressively: scores from certified cloud providers (AWS, Azure, GCP) can be imported for the requirements they operate on your behalf, at every assessment level. For cloud-native companies this removes a meaningful slice of physical, environmental, and infrastructure work.
Assessment Selection Checklist
- Customer requirements collected in writing, with specific assessment level named
- Prospect pipeline reviewed for near-term HITRUST mandates (12–24 months out)
- Data risk profile assessed: PHI volume, record counts, criticality to customers
- Internal maturity honestly rated: are policies and procedures documented, or only practiced?
- Budget modeled for the full cycle: MyCSF subscription, assessor, HITRUST fees, remediation, internal time
- Renewal cadence accepted: annual (e1/i1) or biennial with interim (r2)
- Progression plan drafted (e1 → i1 → r2) with trigger conditions for each step
- Cloud inheritance availability confirmed with your providers
- Assessor quotes compared across at least two or three authorized firms
- Milestone communicated to customers so an interim e1/i1 buys patience for a later r2
Frequently Asked Questions
Is an e1 a "real" HITRUST certification?
Yes. It is validated by an authorized external assessor and quality-assured by HITRUST centrally, exactly like an i1 or r2 — the difference is breadth and scoring depth, not legitimacy. Whether it satisfies a particular customer is a different question: always confirm the required level before relying on it.
Can we do a self-assessment instead of a validated one?
HITRUST supports self-assessments in MyCSF as readiness exercises, and they are genuinely useful for gap analysis. But they are not certifications and rarely satisfy customer demands. Treat self-assessment as phase one of the certification process, not a substitute for it.
Does work on an e1 count toward an i1 or r2?
Directly. The portfolio is nested — e1 requirements are contained in the i1, and i1 requirements in the r2 — so controls, evidence pipelines, and assessor familiarity all carry forward. The genuinely new r2 work is the policy/procedure documentation layer and the expanded risk-based requirements.
What happens if we fail to hit the thresholds?
For an r2, requirements scoring below threshold in otherwise-passing domains generate corrective action plans (CAPs) you must remediate on a schedule; domains below the passing bar block certification until fixed. For e1 and i1, gaps generally must be remediated before certification issues. Practically, a competent readiness phase means you should know your outcome before validation starts — surprises at QA are a planning failure.
How disruptive is the r2 interim assessment at year one?
Moderate. The assessor tests a sample of controls and reviews CAP progress rather than re-running the full assessment — typically days of effort, not months. The organizations that find interims painful are the ones that stopped operating their evidence collection after certification; continuous compliance tooling makes interims routine.
Which type do large payers and health systems actually accept?
It varies by buyer and by your risk tier in their vendor program. High-risk vendors (core clinical systems, large PHI processors) are commonly held to r2. Moderate-risk SaaS vendors increasingly clear review with an i1. Low-risk vendors may pass with an e1 or even a strong SOC 2. The trend is toward tiered acceptance — which is exactly why the three-level portfolio exists.
In the next lesson, we will cover HITRUST control categories in detail.
Choosing an assessment level goes hand in hand with choosing an assessor and a readiness platform. AuditXYZ helps you compare compliance automation platforms and auditors so you can match the right partners to the right assessment.