HITRUST Certification: Cost, Timeline & Readiness Checklist
There’s no official HIPAA certification — HITRUST CSF is the framework enterprise healthcare buyers actually ask for instead. What e1, i1, and r2 cost, how long each takes, and what to fix before an assessor shows up.
A security questionnaire or enterprise contract names “HITRUST certified” as a requirement, and the first instinct for a lot of healthcare vendors is to check whether they’re already HIPAA compliant and assume that covers it. It doesn’t, and the confusion is understandable: HIPAA sets the legal requirements, but it was never built with an audit-and-certify mechanism attached to it.
Most guides on this either bury the actual cost and timeline numbers under generic reassurance, or treat HITRUST like one fixed process when it’s really three different assessment levels with different scopes, different price tags, and different buyers behind them. Here’s what each one actually requires, in the order the work happens.
Why HITRUST Exists (and Why HIPAA Alone Doesn’t Answer the Question)
HIPAA is a federal law, not a certifiable standard. There’s no government body that issues a “HIPAA certified” seal, and any vendor claiming one is worth a closer look, not automatic trust. HITRUST CSF was built specifically to close that gap: a private, certifiable framework that maps its controls to HIPAA, along with SOC 2, NIST CSF, ISO 27001, and a handful of other standards, so a healthcare buyer gets one assessment that answers several compliance questions at once.
That’s also why “are you HITRUST certified?” has become the practical stand-in question enterprise healthcare buyers actually ask, instead of “are you HIPAA compliant?” The second one can’t be independently verified the same way the first one can.
The Three Assessment Levels
All three sit under the same HITRUST CSF framework, but they’re not stages of one process — they’re different assessments built for different buyers and different stages of a security program.
e1 — Essentials
44 foundational controls. Valid one year. Built for smaller or earlier-stage vendors establishing a baseline — passing e1 also gives a head start toward i1 later.
i1 — Implemented
Roughly 182 controls, including everything in e1. Valid one year. Signals a more mature, operating security program rather than a starting point.
r2 — Risk-based
Control selection is tailored to your risk profile from a library of 2,000+ possible controls, typically landing around 300–400 in scope. Valid two years, with a required interim check at year one.
If an RFP or contract just says “HITRUST” without naming a level, that’s worth clarifying before scoping anything — the difference between e1 and r2 changes both the cost and the timeline by multiples, not by a small margin.
What It Actually Costs
Assessor fees are priced separately from HITRUST’s own platform and QA fees, and both scale with the assessment level. e1 assessor fees typically run around $10,000. i1 typically runs around $25,000. r2 is priced differently again: commonly up to roughly $25,000 for the first 250 controls in scope, with additional controls priced per control beyond that, which is part of why r2 costs vary so much between organizations.
On top of assessor fees, budget for MyCSF platform access (commonly cited around $15,000 a year), the internal time or consulting support to close control gaps before the assessment, and, for r2, the interim assessment at the one-year mark. Added together, a full r2 program commonly lands somewhere between $70,000 and $160,000 all-in; e1 and i1 programs run meaningfully lower, largely in proportion to their smaller control sets.
Which level actually matches what your buyers are asking for is usually the first thing worth nailing down — it’s the single biggest lever on both the cost and timeline below.
Book a free gap assessmentRealistic Timeline
e1 moves fastest: organizations with reasonably mature security controls already in place can complete readiness and assessment in six to eight weeks. Starting from a lower baseline, building access controls, logging, or incident response processes from scratch, stretches that closer to three or four months.
i1 typically takes three to six months, largely because evidence collection across roughly four times as many controls takes real operational time, not just documentation time. r2 is the longest at six to nine months from kickoff to certification, driven by the size of the tailored control set and however much remediation the readiness assessment turns up.
None of that clock starts until the assessment level is actually chosen. Teams that begin gathering evidence before confirming whether a buyer needs e1, i1, or r2 routinely end up redoing work once the real requirement surfaces.
Readiness Checklist
The sequence holds regardless of which level you’re targeting; only the scope of steps two through five changes.
- 01Confirm the assessment levelGet the specific level a buyer or contract requires in writing before scoping anything. Don’t assume “HITRUST” automatically means r2.
- 02Run a readiness assessment in MyCSFScore current controls against the target requirement set to find real gaps before an external assessor does.
- 03Remediate the gapsClose what the readiness assessment flagged: access management, encryption, logging, incident response, vendor risk, whatever came back weak or missing.
- 04Engage a HITRUST-Authorized External AssessorOnly an authorized firm’s assessment can result in certification. Internal self-assessment alone doesn’t qualify, no matter how thorough.
- 05Collect and submit evidenceThe assessor validates evidence against every control in scope, not a policy document alone.
- 06HITRUST Quality Assurance reviewHITRUST’s own QA team reviews the assessor’s work before a score is issued.
- 07Certification is issuede1 and i1 last one year. r2 lasts two, with an interim assessment required at the one-year mark.
- 08Plan the next cycle earlyStart readiness work for recertification well before the current certificate expires, so there’s no lapse in status.
Find out which level you actually need before the audit clock starts.
Accredify Global runs HITRUST-authorized assessments across e1, i1, and r2, from readiness through certification, so healthcare vendors aren’t guessing which level a buyer actually requires or handed off between a consultant and an assessor partway through.
Book your free readiness assessment →Frequently Asked Questions
Is there an official HIPAA certification?
No. HIPAA doesn’t have an official, government-issued certification; the law itself doesn’t create one. That gap is exactly why HITRUST CSF exists: a certifiable framework built to map to HIPAA, along with SOC 2, NIST CSF, and other standards, so healthcare vendors have something concrete to show a buyer instead of a self-attestation.
What’s the difference between HITRUST e1, i1, and r2?
e1 (Essentials) covers 44 foundational controls and is valid one year, built for smaller or earlier-stage vendors establishing basic trust. i1 (Implemented) covers roughly 182 controls, also valid one year, and demonstrates a more mature security program. r2 (Risk-based) is the most comprehensive: control selection is tailored to your specific risk profile from a library of 2,000+ possible controls, typically landing around 300–400 in scope, and certification is valid two years with a required interim check at year one.
How much does HITRUST certification cost?
Assessor fees alone typically run around $10,000 for e1, roughly $25,000 for i1, and from about $25,000 up, plus roughly $50 per additional control beyond the first 250, for r2. Add HITRUST’s MyCSF platform access, commonly cited around $15,000 a year, plus internal remediation time and any consulting support, and the realistic all-in range for a full r2 program often lands between $70,000 and $160,000.
How long does HITRUST certification take?
For e1, teams with reasonably mature controls can move through readiness and assessment in six to eight weeks; starting from a lower baseline stretches that to three or four months. i1 usually takes three to six months. r2 is the longest, typically six to nine months from kickoff to certification, driven by the size of the control set and how much remediation is needed.
Do we need a consultant to get HITRUST certified?
Not by requirement, but most organizations bring in outside help for the readiness assessment and remediation planning, since MyCSF’s control language and evidence requirements have a real learning curve. The certification itself can only be performed by a HITRUST-Authorized External Assessor; that part isn’t optional.
Which assessment level should we start with?
If a buyer or RFP just says “HITRUST” without specifying a level, clarify which one they actually require before scoping the engagement; it changes the cost and timeline by multiples. Early-stage vendors typically start at e1 to establish a track record, since passing it gives a head start toward i1 later. Enterprises handling large volumes of protected health information, or selling into buyers who specifically require it, usually go straight to r2.