HITRUST Certification
HITRUST runs its own assurance programme. Assessments are performed by HITRUST Authorized External Assessor firms and the certification is issued by HITRUST itself after quality assurance review, which is a different model from ISO certification.
What HITRUST Is and Who Issues the Certification
HITRUST is a private organisation that owns and maintains the HITRUST CSF, a control framework built to be assessed once and reported against many regulations and standards. It originated in the United States healthcare sector, which is why it is so closely associated with HIPAA, but it is now used across financial services, technology and other regulated industries.
The assurance model is worth understanding before you budget for it, because it does not work the way ISO certification works:
- The assessment is performed by a HITRUST Authorized External Assessor, a firm that HITRUST has approved and whose assessors hold HITRUST credentials.
- The assessor submits the results to HITRUST, which performs its own quality assurance review of the scoring and evidence.
- HITRUST issues the certification, not the assessor. This is the opposite of the ISO model, where an accredited certification body issues the certificate under its own name.
- There is no national accreditation body in the chain and no multilateral recognition arrangement. HITRUST governs the scheme end to end.
The Three Assessment Types
HITRUST offers a graduated set of assessments so that the effort can be matched to the assurance a customer actually needs.
- e1, essentials. Foundational cybersecurity assurance built on 43 core control requirements. The certification is valid for one year. It suits lower risk relationships and organisations starting their assurance journey.
- i1, implemented. Threat adaptive assurance based on 182 control requirements, with the requirement set refreshed by HITRUST to reflect current threats. The certification is valid for one year.
- r2, risk based. The most demanding option. The control requirement set is tailored to the organisation through scoping factors covering size, systems, geography and regulatory obligations. The certification is valid for two years, with an interim assessment at the one year point to confirm that the control environment has held.
The r2 assessment is also where regulatory factors are added. Selecting HIPAA, or another applicable regulation, expands the requirement set so that the resulting report speaks to that obligation as well as to the framework.
What the HITRUST CSF Covers
The HITRUST CSF is a control framework rather than a law or a standard. Its value is in the mapping: a single set of implemented controls is scored once and reported against multiple authoritative sources, which reduces duplicated audit effort.
Scoring is the part organisations underestimate. Each requirement is evaluated on maturity across several levels covering policy, procedure, implementation and, in the r2 assessment, measurement and management. A control that is implemented but has no documented procedure will not score as implemented, which is why documentation work cannot be deferred to the week before the assessment.
Common control domains include information protection programme governance, endpoint protection, access control, network protection, transmission protection, password management, audit logging and monitoring, education and awareness, third party assurance, incident management, business continuity and disaster recovery, risk management, physical and environmental security, and data protection and privacy.
How Univate Prepares an Organisation
- Assessment selection and scoping. We establish which assessment your customer actually requires and define the scope, because an over broad scope is the most expensive mistake available in a HITRUST programme.
- Control mapping. Existing ISO/IEC 27001, SOC 2 or internal control evidence is mapped to the HITRUST requirement set so that you are not rebuilding controls you already run.
- Maturity gap analysis. Each requirement is reviewed against the maturity levels used in scoring, not simply against whether a control exists.
- Remediation and evidence build. Policy, procedure, implementation evidence and, for r2, measurement and management evidence, produced in the form the assessor will ask for.
- Readiness review and assessor support. A dry run against the requirement set, then support through fieldwork, corrective action plans and the HITRUST quality assurance stage.
Points Worth Being Careful About
- HITRUST certification is not a government approval and it is not a HIPAA certification. It is certification under a private scheme, which can nonetheless be excellent evidence of HIPAA safeguards when the regulatory factor is included.
- Scoping factors drive the size of the r2 requirement set. Answering them carelessly can multiply the work with no gain in assurance.
- The quality assurance stage takes time after fieldwork ends. Build that into any deadline you have committed to a customer.
- Corrective action plans are permitted for some gaps, but they carry scoring consequences and must be closed. They are not a way of avoiding remediation.
- An e1 or i1 certification does not become an r2 certification by adding evidence later. The assessment types are separate exercises with separate scoring rules.
HITRUST Questions We Are Asked Most Often
Who actually issues a HITRUST certification?
HITRUST does. A HITRUST Authorized External Assessor firm performs the assessment and submits the results, then HITRUST carries out a quality assurance review and issues the certification. This differs from ISO certification, where an accredited certification body issues the certificate under its own name.
How long is a HITRUST certification valid?
The e1 and i1 certifications are valid for one year. The r2 certification is valid for two years and requires an interim assessment at the one year point.
Does HITRUST certification make us HIPAA compliant?
It provides strong evidence of the safeguards HIPAA requires, particularly when HIPAA is selected as a regulatory factor in an r2 assessment. It is not a government certification and no scheme can declare an organisation HIPAA compliant, because the Department of Health and Human Services operates no such programme.
Can our ISO 27001 work be reused for HITRUST?
A great deal of it. The HITRUST CSF maps to widely used sources including ISO/IEC 27001, so existing policies, risk assessments and control evidence usually transfer. The gap is normally in the granularity of the requirements and in the maturity evidence that HITRUST scoring expects.
What is the difference between HITRUST and SOC 2?
SOC 2 is an attestation engagement performed by a licensed CPA firm under standards set by the American Institute of Certified Public Accountants, and the practitioner sets the controls in consultation with management. HITRUST assesses a prescribed control requirement set with prescribed scoring, and HITRUST itself issues the certification.
Tell us which assessment your customer is asking for and what systems are in scope. We will map your existing controls to the HITRUST CSF, size the gap and plan the readiness work before you engage an external assessor.
Related Services & Resources
Univate supports certification, assessment and compliance programmes for organisations operating across international markets. Talk to our team about scope, effort and the route that genuinely applies to your organisation.








