HITRUST CSF
HITRUST Readiness Guide
Cycore's guide to the three HITRUST assessment types. Compare e1, i1, and r2, settle version and scope first, and take the right questions to your assessor.
We wrote this guide for health care and technology teams weighing a HITRUST assessment, usually because a customer or contract asked for one. It compares the three assessment types, tells you what to settle before anyone creates an assessment in MyCSF, and gives you the questions to bring to an authorized external assessor.
What's inside
- Check the CSF version first. As of 2026-09-01, CSF v11.8 is current for newly created e1 and i1 assessments, and transition rules apply to one already created under v11.7.
- The three assessment types. e1, i1, and r2 compared by assurance depth, scope, validation, certification period, and tailoring, with the counts cited to HITRUST's 2026 Trust Report.
- How to choose. Start from what your customers and contracts require.
- Where the requirement statements come from. The authoritative sources HITRUST builds the CSF from, and what selecting one into your assessment does.
- Version and scope questions to settle first. Seven decisions: version, assessment type, systems in scope, risk factors, authoritative sources, inheritance, and evidence owners.
- Common mistakes we see. Five, with what to do instead.
- Questions to bring to your assessor. Eleven, ready for your agenda.
How to use it
Read it before your first assessor conversation. Confirm the CSF version in MyCSF, get the assessment requirement in writing from whoever is asking, and work through the seven decisions with your team. Then take the eleven questions into the meeting. Download the PDF below.
proof of work
Anterior's result
Cycore reports that Anterior became HITRUST-ready within seven weeks.
Read the case study