Back to HITRUST

HITRUST Compliance Checklist: e1, i1 and r2 Requirements Explained

Photo: Unsplash

HITRUST compliance checklist

HITRUST is the most prescriptive framework in this space, and that cuts both ways. Unlike SOC 2, where you design your own controls, HITRUST hands you specific requirement statements you must satisfy. There is far less ambiguity about what to build, and far less room to argue your way out of a gap.

This checklist covers the decisions that determine how much work you are taking on, the domains you will be assessed against, and how the scoring model actually decides whether you certify.

Key takeaways

  • HITRUST publishes the CSF, a framework that harmonises HIPAA, ISO 27001, NIST, PCI DSS and others into one set of requirement statements, so one assessment can evidence several obligations.
  • There are three assessment types. e1 covers 44 requirement statements, i1 covers 182, and r2 is tailored by risk factors and commonly runs into the hundreds.
  • Only r2 uses the full maturity model. e1 and i1 are scored on implementation alone, which is why they are dramatically less work.
  • A certification requires validation by a HITRUST Authorized External Assessor. You cannot self-certify.
  • e1 and i1 certifications are valid for one year. r2 is valid for two, with an interim assessment in between.

What HITRUST actually is

Three things get conflated, so it is worth separating them:

  • The HITRUST CSF is the framework: a library of control requirements mapped to dozens of underlying authoritative sources.
  • MyCSF is the platform you must use. Assessments are scoped, scored, evidenced and submitted through it. This is not optional and it carries a subscription cost.
  • HITRUST certification is the outcome, issued by HITRUST itself after an Authorized External Assessor validates your assessment and HITRUST performs its own quality review.

The reason healthcare buys into this: HIPAA tells you to be reasonable and appropriate without telling you what that means. HITRUST turns that into testable requirement statements, which is why health systems and payers increasingly ask vendors for it by name rather than accepting a HIPAA self-attestation.

Step 1: choose your assessment type

This is the decision that determines your cost and timeline. Choose wrong and you either overspend or produce a certificate your customer does not accept.

e1 i1 r2
Full name Essentials, 1-year Implemented, 1-year Risk-based, 2-year
Requirement statements 44 182 Tailored, commonly 300 or more
Scoring Implementation only Implementation only Full maturity model
Tailored to your risk? No, fixed set No, fixed set Yes, via risk factors
Validity 1 year 1 year 2 years, with interim assessment
Typical effort Months 4 to 8 months 9 to 18 months
Use when Lowest-risk vendors, or establishing a baseline The common middle choice for SaaS vendors to healthcare A large customer contractually requires r2, or you handle high volumes of sensitive data

Practical guidance: ask your customer which one they will accept, in writing, before you scope anything. Many vendors assume r2 is required because it is the most recognised, spend a year on it, and discover an i1 would have closed the deal. Equally, some large health systems will only accept r2, and an i1 in that situation is a wasted year.

Step 2: scope the assessment in MyCSF

Scoping happens inside MyCSF and is driven by risk factors you declare about your organisation and system:

  • Organisational factors: size, revenue, number of records held
  • System factors: whether the system is internet-facing, whether it transmits or stores sensitive data, transaction volumes, number of interfaces
  • Regulatory factors: which regimes apply, such as HIPAA, HITECH, state privacy laws, PCI DSS

For r2, these factors directly determine how many requirement statements you are assessed against. Declaring a broader scope or higher-risk profile than you need is the most common self-inflicted cost increase in HITRUST.

Checklist for this step:

  • System boundary defined and documented, including which environments and data stores are in scope
  • Risk factors answered accurately and defensibly, since your assessor will challenge them
  • Inheritance identified where you rely on an underlying provider that holds its own HITRUST certification, which can reduce your evidence burden materially
  • Scope agreed with your external assessor before you begin remediation

Step 3: work the 19 assessment domains

HITRUST organises requirements into 19 assessment domains. Your score is calculated per domain, and a weak domain can block certification even if your overall average looks healthy.

Domain What it covers Where vendors commonly fall short
Information Protection Program Governance, programme structure, risk management Programme documented but not demonstrably operating
Endpoint Protection Malware defence, device hardening Coverage gaps on contractor devices
Portable Media Security Removable media controls No policy enforcement, only a policy
Mobile Device Security MDM, BYOD controls Personal devices accessing data outside MDM
Wireless Security Wireless network controls Guest network segregation
Configuration Management Baselines, change control No documented hardening baseline
Vulnerability Management Scanning, patching, remediation SLAs Scanning without tracked remediation
Network Protection Segmentation, perimeter, monitoring Flat internal networks
Transmission Protection Encryption in transit Legacy integrations without TLS
Password Management Authentication controls Service accounts exempt from policy
Access Control Authorisation, least privilege Access reviews not performed on cadence
Audit Logging and Monitoring Log generation, retention, review Retention period undefined, logs never reviewed
Education, Training and Awareness Security and privacy training Completion not tracked to individuals
Third Party Assurance Vendor risk management Vendor register with no assessments
Incident Management Detection, response, reporting No evidence of the plan being exercised
Business Continuity and Disaster Recovery Continuity planning, testing Plan exists, test never performed
Risk Management Risk assessment and treatment Assessment performed once
Physical and Environmental Security Facility controls Cloud-hosted vendors ignoring office controls
Data Protection and Privacy Privacy controls, data handling No record of data flows

Step 4: understand how scoring works

This is the part that surprises people, and it is the single biggest difference between HITRUST and every other framework here.

e1 and i1: implementation only

Each requirement statement is evaluated on whether it is implemented. Straightforward, and closer to how a SOC 2 auditor thinks.

r2: the full maturity model

Each requirement statement is scored across five maturity levels:

  1. Policy. Is the requirement stated in an approved policy?
  2. Procedure. Is there a documented procedure describing how it is carried out?
  3. Implemented. Is it actually in place and operating?
  4. Measured. Do you measure whether it is working, with metrics?
  5. Managed. Do you act on those measurements to improve?

The consequence is that a control can be fully implemented and still score poorly. If it works in production but is not written into a policy, has no documented procedure, and nobody measures it, three of the five levels score low. Domain scores are calculated from these levels, and HITRUST requires each domain to reach a defined threshold for certification.

This is why r2 is so much heavier than it first appears. Levels 4 and 5 in particular demand a measurement and improvement discipline that many otherwise well-run security programmes simply do not have.

Gaps become Corrective Action Plans (CAPs). A small number of CAPs will not necessarily block certification, but each needs an owner, a remediation plan and a date, and they are followed up.

Step 5: external assessor validation

  • Select a HITRUST Authorized External Assessor. Only firms on HITRUST's authorised list can validate an assessment.
  • Run a readiness assessment first. This is a self-assessment in MyCSF, ideally reviewed by your assessor, and it tells you your likely score before you pay for validation. Skipping it is how organisations discover a failing domain during the validated assessment.
  • Remediate, then generate evidence. For r2, remember that levels 4 and 5 need a measurement history, so leaving remediation until the last month caps your score regardless of what you fixed.
  • Validated assessment. Your assessor tests requirement statements and reviews evidence.
  • HITRUST quality assurance review. HITRUST performs its own QA on the submitted assessment. This step takes weeks and can send items back.
  • Certification issued, and listed if you choose.

Timeline and cost

e1 i1 r2
Readiness to certification 2 to 4 months 4 to 8 months 9 to 18 months
Cost drivers MyCSF subscription, assessor fees MyCSF, assessor fees, remediation MyCSF, assessor fees, remediation, measurement programme
Relative total cost Lowest Moderate Several times an i1

Costs to budget for in all three cases: the MyCSF subscription, external assessor fees, internal effort, and remediation. For r2, add the cost of building measurement and improvement practices that may not exist today.

Note the renewal cadence: e1 and i1 require annual recertification, so the cost recurs yearly rather than being a one-off.

Where HITRUST projects go wrong

  1. Choosing r2 when the customer would accept i1. Confirm in writing first.
  2. Scoping risk factors too broadly, inflating the requirement count for no commercial benefit.
  3. Treating r2 like SOC 2. Implementing controls without policies, procedures, metrics and improvement evidence caps your maturity score.
  4. Leaving remediation late. Levels 4 and 5 need history, and history cannot be backdated.
  5. Skipping the readiness assessment. Paying for validation without knowing your score is an expensive way to find a failing domain.
  6. Ignoring one weak domain. Per-domain thresholds mean a single neglected area can block certification.
  7. Forgetting the annual renewal. e1 and i1 lapse after a year, and a lapsed certificate can breach a customer commitment.

How SecureSlate helps

SecureSlate maintains one control set mapped across frameworks, so the policies, procedures and evidence behind a HITRUST domain also serve your SOC 2 and ISO 27001 obligations. Access reviews, vendor assessments, training completion and vulnerability remediation are tracked continuously with dated records, which is what the higher maturity levels require and what teams most often cannot produce retroactively.

Get started for free

Related guides:

FAQ

What is the difference between e1, i1 and r2?
e1 assesses 44 requirement statements, i1 assesses 182, and both are scored on implementation only. r2 is tailored to your declared risk factors, commonly covers several hundred requirement statements, and is scored across the full five-level maturity model. e1 and i1 certifications last one year; r2 lasts two with an interim assessment.

Can we self-certify HITRUST?
No. You can perform a readiness self-assessment in MyCSF, but certification requires validation by a HITRUST Authorized External Assessor followed by HITRUST's own quality review.

Is HITRUST required for HIPAA compliance?
No. HIPAA does not require HITRUST or any certification. HITRUST is a voluntary framework that many covered entities and business associates use to demonstrate HIPAA-aligned controls, and some health systems require it contractually from vendors.

Does HITRUST replace SOC 2?
Not usually. They serve different audiences, and many vendors are asked for both. There is substantial control overlap, so a single well-maintained control set can support both assessments.

How long does HITRUST certification last?
e1 and i1 certifications are valid for one year. r2 certifications are valid for two years, with an interim assessment at roughly the one-year mark.

Do we have to pay for MyCSF?
Yes. Assessments are scoped, scored and submitted through MyCSF, and the subscription is a required cost separate from your assessor fees.

Disclaimer (legal note)

This article is for general information only and is not legal, regulatory, or professional advice. HITRUST CSF requirements, assessment types, and scoring rules are revised over time; verify current details against official HITRUST guidance and the CSF version applicable to your assessment. Consult a HITRUST Authorized External Assessor and qualified advisors for your specific obligations.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Keep reading

Jun 4, 2026 · ISO 42001Checklists

ISO 42001 Checklist: AI Management System Requirements and Annex A Controls

Jun 3, 2026 · ISO 27001Checklists

ISO 27001 Checklist: Clauses 4 to 10, All 93 Annex A Controls and Audit Prep

Jun 3, 2026 · SOC 2Checklists

SOC 2 Compliance Checklist: Every Requirement, Control and Evidence Item

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?