e1 covers 44 requirements and is the fastest path to a HITRUST certificate — ideal for organizations new to the framework or responding to a customer demand quickly.
i1 covers 182 requirements and is the most commonly accepted level by health-sector buyers — a meaningful signal of cybersecurity maturity.
r2 is the highest-assurance option with a tailored, risk-based requirement set — typically 200–800 requirements — and is the standard expected for high-value healthcare contracts.
HITRUST designed its three assessment types to serve different organizational risk profiles and stakeholder expectations. Not every organization needs the same level of assurance, and the cost and effort required to achieve each type varies significantly. The result is a tiered system: e1 for foundational cybersecurity hygiene, i1 for implemented leading practices, and r2 for a fully tailored, risk-based validated assessment. All three result in a HITRUST certificate; the difference is what that certificate demonstrates and who accepts it.
The e1 assessment covers 44 requirements focused on essential cybersecurity hygiene: endpoint protection, multi-factor authentication, patch management, access control, and incident response fundamentals. It is the fastest and least expensive of the three options, and it is valid for one year. The e1 is a self-assessment submitted through MyCSF without a requirement for an authorized External Assessor — though HITRUST validates the submission.
When is e1 right? When a customer or partner is asking for "some level of HITRUST" and you need to respond quickly, or when you are a smaller organization starting your HITRUST journey before scaling to i1. It is not accepted in place of i1 or r2 by most mature health-sector enterprise buyers, but it is a valid starting point and a signal of commitment.
The i1 assessment covers 182 requirements across all 14 HITRUST CSF control categories, focused on implemented leading security practices. Unlike r2, the i1 requirement set is fixed — every organization at this level is assessed against the same 182 requirements, which makes it straightforward to scope and budget. An authorized External Assessor validates the submission.
The i1 is the most commonly requested level in healthcare IT procurement. Most enterprise health systems, health plans, and government health agencies that require HITRUST will accept i1 as evidence of meaningful cybersecurity maturity. If you have one HITRUST assessment to budget for and your customers are asking for i1 or "HITRUST certified," this is your target.
The r2 is the highest-assurance HITRUST assessment. The requirement set is tailored to your organization based on a set of organizational, system, and regulatory factors — the number of employees, the geographic footprint, the regulatory environment, the type of data processed. A typical r2 requirement set ranges from 200 to 800+ requirements. The assessment is validated by an authorized External Assessor, and the certificate is valid for two years with a one-year interim review.
The r2 is expected for the largest, most sensitive healthcare contracts: major health system vendor agreements, federal health IT contracts, and partnerships where a business associate's breach would create significant regulatory and reputational exposure. It is the most credible signal in the healthcare compliance market. It is also the most significant investment — plan for 9–18 months of preparation for an organization that is not yet HITRUST-certified.