What Is HITRUST Certification? A Guide for SaaS Vendors
HITRUST certification is a credential for commercial healthcare procurement and third-party risk management. The HITRUST Common Security Framework (CSF) consolidates requirements from multiple regulations and standards, including the Health Insurance Portability and Accountability Act (HIPAA), the National Institute of Standards and Technology (NIST) SP 800-53 Rev5, and International Organization for Standardization (ISO) 27001, into a single certifiable control library.
The assessment tier must align with the deals in the pipeline, and healthcare SaaS vendors need to understand what the assessment process entails. Vendors must also determine whether the investment carries forward when federal health buyers enter the roadmap.
Key Takeaways
- Assessment Tiers Differ. e1 covers a smaller fixed set of requirements with a shorter validity cycle, i1 covers a larger fixed set with the same validity cycle, and r2 uses a risk-tailored requirement set with a longer validity cycle and an interim assessment.
- Certification Has Defined Stages. Scoping, readiness and remediation, evidence collection in MyCSF, a validated assessment by an authorized external assessor, and HITRUST quality assurance review precede issuance.
- Federal Authorization Remains Separate. The Federal Risk and Authorization Management Program (FedRAMP) remains separate. The CSF includes FedRAMP mappings, yet federal agencies still require FedRAMP authorization and an agency-issued Authority to Operate (ATO).
- Prior Work Carries Forward. System and Organization Controls (SOC) 2 evidence maps into the HITRUST control set, and HITRUST's NIST SP 800-53 mappings provide a crosswalk that can help vendors organize pre-existing evidence for later federal work.
HITRUST Certification Validates Security Maturity Against a Common Framework
The HITRUST CSF is a unified control library maintained by the HITRUST Alliance, a private organization. Its core structure is built on the ISO/International Electrotechnical Commission (IEC) 27001 and 27002 standards. It organizes controls into control categories and control objectives and includes detailed control specifications.
The CSF harmonizes authoritative sources. Those sources include:
- HIPAA
- NIST SP 800-53 Rev5
- Payment Card Industry Data Security Standard (PCI DSS)
- General Data Protection Regulation (GDPR)
- Cybersecurity Maturity Model Certification (CMMC) 2.0
- The CMS Acceptable Risk Safeguards, among others
Certification requires a validated assessment by a HITRUST Authorized External Assessor and a quality assurance (QA) review by HITRUST before it issues a report. Commercial healthcare buyers accept HITRUST certification as a vendor risk signal.
HITRUST Offers Assessment Tiers Based on Assurance Level
The assessment tiers are nested. Every e1 requirement sits inside i1, and the i1 baseline forms the foundation of every r2.
- e1 (Essentials). A smaller fixed set of requirement statements, with no tailoring. Uses a shorter certification cycle, with full reassessment and no interim option. Only the Implemented maturity level is scored, which can keep end-to-end timelines comparatively short.
- i1 (Leading Practices). A larger fixed set of requirement statements, with the same shorter certification cycle. Like e1, it scores only on implementation, but the larger control set is designed to be threat-adaptive and of moderate assurance. First-time certification timelines vary by organizational readiness and scope, and a Rapid Recertification option is available in a subsequent certification cycle.
- r2 (Risk-Based). A tailored control set selected from the CSF library through a risk-based scoping questionnaire in MyCSF. Uses a longer certification cycle, with a required interim assessment at the midpoint. All maturity levels are scored, so the tailored r2 assessment generally requires more assessment work than e1 or i1.
The scoring model behind these tiers follows the Policy, Procedure, Implemented, Measured, and Managed (PRISMA) maturity approach. Each evaluated level is rated from Non-Compliant to Fully Compliant, then weighted, with implementation carrying the heaviest weight.
Scores roll up into domain averages across HITRUST's control domains. Each assessment tier must meet its applicable domain-specific scoring threshold to be certified. Corrective Action Plans (CAPs) are mandatory for any required control scoring below the applicable threshold.
Achieving HITRUST Certification Follows a Defined Assessment Path
The certification process moves through five defined stages, each with its own deliverables and dependencies. Understanding what happens at each stage helps vendors plan realistic timelines and allocate the right internal resources.
1. Scope the Assessment and Select a Tier
Every assessment requires a MyCSF subscription and an engagement with a HITRUST Authorized External Assessor. For r2, a risk-based scoping questionnaire in MyCSF determines which requirements apply; e1 and i1 use pre-defined sets. Scoping duration depends on the assessed organization and assessment scope.
2. Run a Readiness Assessment and Remediate Gaps
The assessor performs an initial gap assessment, the assessed organization submits inheritance requests in MyCSF, books a QA reservation date, and closes evidence gaps. Timing matters here: implemented controls and new policies and procedures must be in place for prescribed periods before fieldwork begins. Remediation time varies according to the gaps identified.
3. Collect Evidence and Self-Score in MyCSF
MyCSF is the system of record for the entire lifecycle. The assessed organization self-scores each control, resolves any triggered quality issues, signs the Validated Report Agreement, and submits each completed domain to the external assessor for validation.
4. Complete the Validated Assessment
The external assessor interviews control owners directly (proxies are not permitted, though on-site presence is not required) within the prescribed fieldwork window. Promptly after fieldwork ends, the assessed organization must enter all required CAPs and sign the Management Representation Letter.
5. Pass HITRUST QA Review and Receive Certification
HITRUST reviews the submission and may request additional evidence. QA review duration varies by tier and complexity. The assessed organization then reviews the draft report before HITRUST issues final certification to assessed organizations meeting the scoring thresholds.
These stages form a sequential path where each step depends on the prior one being complete and well-documented. Vendors who invest in disciplined scoping and readiness work upfront typically move through validation and QA review with fewer surprises.
HITRUST and FedRAMP Overlap on Controls but Serve Different Buyers
HITRUST and FedRAMP share portions of the same control foundation, but they serve different procurement and authorization functions. The mappings identify reusable work without converting one credential into the other.
Where the Frameworks Map Together
NIST SP 800-53 Rev5, the control catalog FedRAMP baselines draw from, is a HITRUST authoritative source. The CSF also includes mappings for:
- FedRAMP Rev5,
- the State Risk and Authorization Management Program (StateRAMP) Rev5,
- the Texas Risk and Authorization Management Program (TX-RAMP) Rev5.
Within the CSF, FedRAMP is treated as a segment-specific implementation level available only in r2 assessments; it does not appear in the e1 or i1 baselines. No authoritative source publishes a verified percentage overlap between HITRUST r2 and the FedRAMP Rev5 control baselines, released May 30, 2023, including the Moderate or High baselines, so any specific overlap figure a vendor quotes should be treated as an estimate rather than a documented crosswalk result.
HITRUST and FedRAMP Diverge in Authorization and Validity
FedRAMP is mandated by the Office of Management and Budget (OMB) under OMB Memorandum M-24-15 for cloud services handling federal information. HITRUST is voluntary, a trust signal adopted by commercial healthcare buyers for third-party risk management.
The granting authorities differ too. FedRAMP requires an assessment by an accredited Third-Party Assessment Organization (3PAO) and a federal agency to issue an ATO; HITRUST certification is issued by the HITRUST Alliance itself.
Validity models diverge as well: HITRUST certifications use shorter validity cycles for e1 and i1 or a longer validity cycle for r2, while FedRAMP authorization has no fixed expiration and is instead maintained through Continuous Monitoring (ConMon), with monthly vulnerability scans and Plan of Action and Milestones (POA&M) updates. Agency authorization requires a separate FedRAMP process.
The practical consequence is that HITRUST maturity can support, but cannot substitute for, federal authorization.
HITRUST Maturity Doesn't Substitute for a Federal Authorization
The CMS security and privacy policy states at control CMS-CLD-1: "All cloud service implementations used must have an approved Federal Risk and Authorization Management Program (FedRAMP) Authorization and CMS-issued ATO." VA Notice 25-06 similarly requires VA organizations that contract for commercial cloud services to comply with FedRAMP, as outlined in OMB M-24-15. The CMS security policy does not present HITRUST as an alternative, and neither does the VA notice.
Under FedRAMP's Rev5 baselines, federal authorization requires four parallel obligations:
- Implementing and documenting the full control baseline drawn from NIST SP 800-53 Rev5.
- Completing an assessment by an accredited 3PAO.
- Preparing a System Security Plan (SSP) in FedRAMP's format and securing an agency ATO.
- Meeting monthly ConMon reporting requirements.
These obligations extend beyond the evidence produced through HITRUST certification. A HITRUST-certified vendor still has meaningful work ahead before it can serve federal health buyers.
HITRUST Investment Still Shortens the FedRAMP Road
While HITRUST cannot stand in for federal authorization, the control work behind a certification is not wasted when a vendor later pursues FedRAMP. Much of the documentation, policies, and evidence produced for HITRUST map directly to the FedRAMP effort, reducing duplicate work across several layers of the baseline.
Several pieces of prior work carry forward in particular:
- SOC 2 alignment. The e1 requirements map to SOC 2 controls and portions of the SOC 2 Trust Services Criteria, so evidence already produced for SOC 2 feeds the HITRUST side and, in turn, the FedRAMP side.
- ISO/IEC 27001 and 27002 foundation. Because the CSF's structure sits on ISO/IEC 27001 and 27002, an existing information security management system (ISMS) can reduce the amount of HITRUST work that must be rebuilt.
- Risk register and policy set. An existing risk register and policy set can do the same, connecting policies with risk assessments in a form both frameworks recognize.
- NIST SP 800-53 mappings. An r2 scoped against NIST SP 800-53 mappings can help organize control evidence for a later FedRAMP effort. Existing policies and procedures can be reused, but they have to be mapped to specific NIST SP 800-53 controls and expanded in depth.
These overlaps meaningfully compress the application-layer work a HITRUST-certified vendor faces when moving to FedRAMP. What HITRUST cannot supply is the infrastructure boundary required for the remaining controls. A healthcare SaaS vendor targeting federal health agencies must therefore decide who should own the infrastructure layer that carries the bulk of the FedRAMP baseline: inherit it from a pre-authorized boundary, or build and authorize it in-house.
That decision makes tier selection part of a broader federal sales strategy.
HITRUST Can Support a Federal Sales Strategy
Tier selection is ultimately a commercial decision rather than a security one. A vendor selling into commercial health systems may favor i1's moderate-assurance scope and shorter validity cycle when speed matters. A vendor whose roadmap includes federal health agencies should weigh r2 with the selected FedRAMP compliance factor, because that choice pre-stages NIST-depth evidence that the federal process will demand anyway. Sequenced deliberately, the certification and the authorization compound rather than compete.
Knox Systems is a FedRAMP-as-a-Service platform built around a pre-authorized FedRAMP boundary with automated continuous monitoring capabilities. Vendors deploying inside it inherit the infrastructure-layer controls that HITRUST evidence cannot satisfy, the same controls that would otherwise slow both a HITRUST r2 effort scoped against FedRAMP mappings and a full federal authorization. Because those inherited controls span both frameworks, customers not only achieve federal authorization in approximately 90 days at 90% less cost than the traditional path, but also reduce the infrastructure-layer work required for their HITRUST certification.
If federal health buyers are in your pipeline, book a meeting.
FAQs about HITRUST Certification
How Much Does HITRUST Certification Cost?
Build a budget only after selecting a tier and defining scope, because assessor fees, remediation needs, and MyCSF access vary. Request current estimates against the same assessment scope so options can be compared consistently.
When Should HITRUST Planning Begin?
Begin planning early enough to complete scoping, reserve QA, and remediate gaps before validated fieldwork. The appropriate start date depends on organizational readiness and the operating periods required for new controls, policies, and procedures.
Who Participates in Validated Assessment Interviews?
Assign the people who own and operate each control rather than representatives who cannot speak directly to implementation. Plan their remote or in-person availability within the prescribed fieldwork window.
Can an r2 Interim Assessment Add New Products?
Treat the original certified scope as fixed when planning an r2 interim assessment. Products or services added later should be evaluated for the next full assessment rather than the midpoint review.