HITRUST

    HITRUST e1 vs i1 vs r2: Which Assessment Is Right for Your Organization?

    ICyberWave Editorial
    Sep 28, 2026
    HITRUST
    Three stacked tiers representing HITRUST e1, i1 and r2 assurance levels under a healthcare shield

    HITRUST now offers three validated assessments — e1, i1 and r2 — each giving a different level of assurance. Choosing the wrong one is expensive: go too low and your healthcare customer rejects it, go too high and you spend a year on requirements nobody asked for.

    The three HITRUST assessments at a glance

    e1 (Essentials, 1-year)i1 (Implemented, 1-year)r2 (Risk-based, 2-year)
    PurposeFoundational cyber hygieneLeading-practice securityComprehensive, risk-tailored assurance
    Approximate requirements~44~182Tailored, often several hundred
    Scoring focusImplementationImplementationPolicy, procedure, implementation (plus measured/managed optional)
    Certification validity1 year1 year2 years, with interim assessment
    Typical effortLowestModerateHighest
    Best forStartups, low-risk vendorsGrowing vendors handling PHILarge vendors, high-risk data, strict customers

    Requirement counts change as HITRUST updates the CSF, so always confirm against the current version.

    HITRUST e1: the essentials

    The e1 covers a curated set of foundational controls — access control, MFA, patching, malware protection, backups, incident response basics. It suits smaller organizations or lower-risk relationships and is a sensible first step toward i1 or r2.

    HITRUST i1: leading practices

    The i1 expands to a broader, threat-adaptive set of requirements that HITRUST refreshes to address current threats. Many healthcare customers now accept i1 for mid-risk vendors because it offers strong assurance without the full r2 effort.

    HITRUST r2: the gold standard

    The r2 is tailored to your organization through risk factors (size, data volume, systems, regulatory scope) and can map to HIPAA, NIST, ISO 27001, PCI DSS and more. It evaluates maturity across policy, procedure and implementation, and remains the most widely required option for large payers, providers and health systems.

    How to choose

    1. Ask your customer first. Many contracts or vendor questionnaires name the exact assessment. That answer overrides everything else.
    2. Assess your data risk. High volumes of PHI or critical services usually point to r2.
    3. Check your maturity. If you lack documented policies and consistent evidence, start with e1 or i1 and build up.
    4. Consider inheritance. Hosting on a HITRUST-certified cloud lets you inherit controls and reduce effort at any tier.
    5. Plan the path. e1 to i1 to r2 is a common progression; work done at lower tiers carries forward.

    Typical timeline

    • Readiness and scoping: 1–2 months
    • Remediation: 2–6 months depending on gaps
    • Validated assessment fieldwork: a few weeks for e1, longer for i1 and r2
    • HITRUST QA review: several weeks after submission

    Common mistakes

    • Choosing r2 by default when the customer only asked for i1
    • Scoping too broadly and pulling in systems that do not touch sensitive data
    • Starting the validated assessment before evidence is ready
    • Ignoring control inheritance from certified cloud providers

    For the full process, read our step-by-step HITRUST certification guide and what changed in HITRUST CSF v11.

    FAQs

    Is HITRUST only for healthcare? It started in healthcare and is most common there, but financial services, technology and other sectors use it as a certifiable, multi-framework control set.

    Can we move from i1 to r2 later? Yes. Much of the i1 evidence and control work carries into an r2, which makes i1 a practical stepping stone.

    Does HITRUST replace SOC 2? Not always. Many vendors hold both; HITRUST mappings can reduce duplicate effort when you prepare for SOC 2 alongside it.

    ICyberWave supports HITRUST e1, i1 and r2 readiness, implementation and assessment preparation — talk to our team.

    Hi! I'm your AI Assistant 💬