SideGuy
HITRUST · Assessment Router · 2026

HITRUST i1 vs r2: which certification do you actually need?

The short answer: i1 is the fixed-menu certification · ~182 threat-adaptive controls, implementation-only scoring, renewed every year, done in 3-6 months. r2 is the tailored one · your risk factors decide the control count (often 250-500+), scored on policy + procedure + implementation maturity, certified on a two-year cycle, and it's what most payers and large health systems still mean when a contract just says "HITRUST certified." r2 typically costs 3-5x more and takes 9-18 months.
HITRUST i1 ("Implemented")HITRUST r2 ("Risk-based")
Control setFixed, ~182 controls, threat-adaptive (HITRUST updates it against current threat data)Tailored by risk factors · commonly 250-500+, can exceed 1,000 in broad scopes
ScoringImplementation onlyMaturity model: policy, procedure, implementation (measured/managed optional)
Certification term1 year (rapid recert available year 2)2 years, with an interim assessment at the 1-year mark
Typical timeline3-6 months9-18 months first cycle
Typical all-in cost band~$30K-$60K~$100K-$250K+ per cycle
Assessor requiredHITRUST Authorized External AssessorHITRUST Authorized External Assessor
Who accepts itGrowing fast · moderate-risk vendor due diligence, many payer vendor programsThe default read of "HITRUST certified" at payers and large health systems
Best fitHealth-tech vendors proving real security without the r2 budget; step up from e1Organizations whose contracts, payers, or regulators explicitly demand it

Cost bands are typical 2026 market ranges (assessor + HITRUST fees + internal effort), not quotes. There is also e1 · 44 essential controls, the on-ramp below i1 · worth knowing before you buy anything.

The honest router

Read the contract first. If it names r2 (or your customer's security team confirms only r2 counts), that's the answer and nothing cheaper survives procurement. If it just says "HITRUST" · ask. A growing share of vendor-risk programs accept i1 for moderate-risk vendors, and answering that one question before engaging an assessor is the difference between a $40K year and a $200K cycle.

Half of "we need HITRUST" requests aren't HITRUST problems. If the buyer is a mid-market SaaS customer rather than a payer, what they usually need is SOC 2 · see the SOC 2 platform ranking. If ISO is on the table instead, start with the time-to-ISO-27001 comparison. Framework-by-city help lives at the compliance hub and the San Diego County consulting page.

One scoping hour beats a wrong six-figure assessment. Operator-honest routing · which assessment your buyers actually accept, which assessor shortlist fits, what to do in-house first. $100/hr, no retainer. Text PJ: 858-461-8054 or start with the SideGuy Hour.