Certification · Last verified
HITRUST CSF
HITRUST CSF is a certifiable framework owned by HITRUST, serving as the control set for HITRUST assessments at the e1, i1 and r2 levels. The e1 and i1 assessments are valid for one year and the r2 assessment for two, and the current version of the framework is CSF v11.8.
- Class
- Certification
- Owner
- HITRUST Services LLC
- Last verified
What it is
HITRUST describes the HITRUST CSF as "a comprehensive framework designed to help organizations manage information security, privacy, and risk in a consistent and scalable way." In HITRUST's own words, the CSF "serves as the foundational control set for HITRUST assessments, including e1, i1, and r2." The current version is CSF v11.8.
Who owns it
The HITRUST CSF is owned by HITRUST Services LLC (per the site's own copyright notice).
Levels
- e1 —
Foundational cybersecurity assurance with 43 core controls - valid for 1 year
- i1 —
Threat-adaptive assurance with 182 control requirements - valid for 1 year
- r2 —
Tailored assurance with the highest level of control requirements - valid for 2 years
Sources
- HITRUST — the HITRUST CSF (scheme owner) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.