| HITRUST i1 ("Implemented") | HITRUST r2 ("Risk-based") | |
|---|---|---|
| Control set | Fixed, ~182 controls, threat-adaptive (HITRUST updates it against current threat data) | Tailored by risk factors · commonly 250-500+, can exceed 1,000 in broad scopes |
| Scoring | Implementation only | Maturity model: policy, procedure, implementation (measured/managed optional) |
| Certification term | 1 year (rapid recert available year 2) | 2 years, with an interim assessment at the 1-year mark |
| Typical timeline | 3-6 months | 9-18 months first cycle |
| Typical all-in cost band | ~$30K-$60K | ~$100K-$250K+ per cycle |
| Assessor required | HITRUST Authorized External Assessor | HITRUST Authorized External Assessor |
| Who accepts it | Growing fast · moderate-risk vendor due diligence, many payer vendor programs | The default read of "HITRUST certified" at payers and large health systems |
| Best fit | Health-tech vendors proving real security without the r2 budget; step up from e1 | Organizations whose contracts, payers, or regulators explicitly demand it |
Cost bands are typical 2026 market ranges (assessor + HITRUST fees + internal effort), not quotes. There is also e1 · 44 essential controls, the on-ramp below i1 · worth knowing before you buy anything.
Read the contract first. If it names r2 (or your customer's security team confirms only r2 counts), that's the answer and nothing cheaper survives procurement. If it just says "HITRUST" · ask. A growing share of vendor-risk programs accept i1 for moderate-risk vendors, and answering that one question before engaging an assessor is the difference between a $40K year and a $200K cycle.
Half of "we need HITRUST" requests aren't HITRUST problems. If the buyer is a mid-market SaaS customer rather than a payer, what they usually need is SOC 2 · see the SOC 2 platform ranking. If ISO is on the table instead, start with the time-to-ISO-27001 comparison. Framework-by-city help lives at the compliance hub and the San Diego County consulting page.