HITRUST now offers three validated assessments — e1, i1 and r2 — each giving a different level of assurance. Choosing the wrong one is expensive: go too low and your healthcare customer rejects it, go too high and you spend a year on requirements nobody asked for.
The three HITRUST assessments at a glance
| e1 (Essentials, 1-year) | i1 (Implemented, 1-year) | r2 (Risk-based, 2-year) | |
|---|---|---|---|
| Purpose | Foundational cyber hygiene | Leading-practice security | Comprehensive, risk-tailored assurance |
| Approximate requirements | ~44 | ~182 | Tailored, often several hundred |
| Scoring focus | Implementation | Implementation | Policy, procedure, implementation (plus measured/managed optional) |
| Certification validity | 1 year | 1 year | 2 years, with interim assessment |
| Typical effort | Lowest | Moderate | Highest |
| Best for | Startups, low-risk vendors | Growing vendors handling PHI | Large vendors, high-risk data, strict customers |
Requirement counts change as HITRUST updates the CSF, so always confirm against the current version.
HITRUST e1: the essentials
The e1 covers a curated set of foundational controls — access control, MFA, patching, malware protection, backups, incident response basics. It suits smaller organizations or lower-risk relationships and is a sensible first step toward i1 or r2.
HITRUST i1: leading practices
The i1 expands to a broader, threat-adaptive set of requirements that HITRUST refreshes to address current threats. Many healthcare customers now accept i1 for mid-risk vendors because it offers strong assurance without the full r2 effort.
HITRUST r2: the gold standard
The r2 is tailored to your organization through risk factors (size, data volume, systems, regulatory scope) and can map to HIPAA, NIST, ISO 27001, PCI DSS and more. It evaluates maturity across policy, procedure and implementation, and remains the most widely required option for large payers, providers and health systems.
How to choose
- Ask your customer first. Many contracts or vendor questionnaires name the exact assessment. That answer overrides everything else.
- Assess your data risk. High volumes of PHI or critical services usually point to r2.
- Check your maturity. If you lack documented policies and consistent evidence, start with e1 or i1 and build up.
- Consider inheritance. Hosting on a HITRUST-certified cloud lets you inherit controls and reduce effort at any tier.
- Plan the path. e1 to i1 to r2 is a common progression; work done at lower tiers carries forward.
Typical timeline
- Readiness and scoping: 1–2 months
- Remediation: 2–6 months depending on gaps
- Validated assessment fieldwork: a few weeks for e1, longer for i1 and r2
- HITRUST QA review: several weeks after submission
Common mistakes
- Choosing r2 by default when the customer only asked for i1
- Scoping too broadly and pulling in systems that do not touch sensitive data
- Starting the validated assessment before evidence is ready
- Ignoring control inheritance from certified cloud providers
For the full process, read our step-by-step HITRUST certification guide and what changed in HITRUST CSF v11.
FAQs
Is HITRUST only for healthcare? It started in healthcare and is most common there, but financial services, technology and other sectors use it as a certifiable, multi-framework control set.
Can we move from i1 to r2 later? Yes. Much of the i1 evidence and control work carries into an r2, which makes i1 a practical stepping stone.
Does HITRUST replace SOC 2? Not always. Many vendors hold both; HITRUST mappings can reduce duplicate effort when you prepare for SOC 2 alongside it.
ICyberWave supports HITRUST e1, i1 and r2 readiness, implementation and assessment preparation — talk to our team.

