HITRUST e1 vs i1 vs r2: Which One Do You Actually Need?
HITRUST publishes the control counts itself, so start there rather than with an assessor's brochure. Read on August 22, 2026, hitrustalliance.net describes e1 as "Foundational cybersecurity assurance with 43 core controls, valid for 1 year", i1 as "Threat-adaptive assurance with 182 control requirements, valid for 1 year", and r2 as "Tailored assurance with the highest level of control requirements, valid for 2 years". The same page describes CSF v11.8.0, which matters: control counts move between CSF versions, so a count without a version attached is a number with a shelf life. Cost is where it gets murkier, and we will show you two published sources that do not agree. The deciding question is not which tier is best. It is which one the contract in front of you names.
Below: what each assessment is, what the counts actually mean, what two sources say about money and time, who is allowed to certify you, and when the right answer is none of them yet.
Key takeaways
- HITRUST's own framework page, describing CSF v11.8.0 as read on August 22, 2026: e1 is 43 core controls valid one year, i1 is 182 control requirements valid one year, r2 is tailored with the highest requirement count and valid two years.
- Control counts are CSF-version-dependent. Pin the version whenever you quote one, including this one.
- Two published cost sources disagree materially, especially on r2. Neither is a survey, and both have a commercial interest.
- Only a HITRUST Authorized External Assessor can perform the validated assessment. A readiness consultancy, including this one, cannot certify you.
- The tier is a procurement question. If a customer named a tier in writing, that is the answer; if nobody has, buying the heaviest one first is the most common overspend we see in health tech.
What the three assessments are
The three tiers are not three difficulty settings on the same exam. They answer different questions.
e1 is the entry assessment: 43 core controls covering foundational cybersecurity hygiene, valid for one year. It exists because a large share of the vendors receiving HITRUST questions do not need, and cannot absorb, a full risk-tailored certification. It is a real, verifiable artifact at a scope a small company can actually finish.
i1 is the threat-adaptive middle tier: 182 control requirements, valid for one year. The design intent is that the requirement set tracks current threats rather than being purely risk-derived, which is why it carries a fixed count while r2 does not.
r2 is the risk-tailored certification: the requirement set is generated from your scoping factors, so two r2 assessments can differ substantially in size. HITRUST describes it as carrying the highest level of control requirements, and it is the only one of the three valid for two years. That validity period is a genuine economic difference, not a marketing point: a two-year certification amortizes across twice the sales cycles.
You will see an average control count quoted for r2 in vendor content. HITRUST does not publish one on the page above, and we are not going to repeat a figure we cannot trace to the source that would know it.
What the counts actually mean, and why they move
A count is not a workload. Two things break the intuition that 182 is roughly four times the work of 43.
First, requirements differ enormously in cost to satisfy. "Maintain an inventory of assets" and "implement and operate a formal secure development lifecycle" are one requirement each. Your effort is dominated by the handful you do not already have, not by the total.
Second, the counts are tied to a CSF version. The page we read describes CSF v11.8.0 and links comparison material between v11.7.1 and v11.8.0, which tells you plainly that these numbers get revised. Any article, including this one, that quotes a control count without naming a version and a read date is handing you a number that may already have moved. When you scope an engagement, re-read the source and pin the version in your own documentation.
The framework itself is broad by design. HITRUST states that it "maps controls to dozens of authoritative sources such as ISO/IEC 27001 and 27002, NIST 800-53 revision 5, HIPAA, PCI, GDPR, and others". That mapping is the practical argument for HITRUST over a pile of separate questionnaires, and it is the same argument we make about reusing evidence across frameworks: the control work is largely shared, the reporting is not.
Cost and timeline, from two sources that disagree
Here are both, with their interests stated, because the disagreement is more informative than either number alone.
soc2auditors.org, an independent directory for comparing audit firms and compliance software that is ad-supported and takes no percentage of audit fees, publishes all-in ranges of $20K to $70K over 3 to 4 months for e1, $60K to $200K over 6 to 12 months for i1, and $150K to $300K or more over 9 to 24 months for r2, describing those as covering the MyCSF platform, HITRUST QA and external assessor fees.
Integral Healthcare Solutions, a readiness consultancy that sells HITRUST preparation and therefore profits when you proceed, publishes roughly $35,000 to $50,000 all-in over 3 to 4 months for e1, $70,000 to $120,000 over 6 to 9 months for i1, and $100,000 to $500,000 or more over 12 to 15 months for r2.
Put them side by side and the pattern is worth a minute. They agree closely on e1 duration and broadly on i1 duration. They disagree on e1 cost by a factor of nearly two at the bottom, where the directory's $20K floor sits well under the consultancy's $35K. And they disagree wildly on r2: one caps at $300K or more, the other at $500K or more, and their timelines barely overlap, 9 to 24 months against 12 to 15.
That r2 spread is not sloppiness. It is the mechanical consequence of a risk-tailored requirement set. When the number of requirements is generated from your scoping factors, no one can quote a range that means anything until your scoping factors exist. Treat any confident r2 quote made before scoping as a sales artifact.
Neither source is a survey with a published method. Both are worth more than nothing and less than a bid. The number that matters is the one an authorized assessor gives you after seeing your scope.
Who is allowed to certify you, and who is not
This trips up more buyers than the tier choice does.
HITRUST certification comes from a validated assessment performed by a HITRUST Authorized External Assessor and then reviewed by HITRUST itself. A readiness or preparation firm is a different role. Integral Healthcare Solutions states the distinction plainly on its own page: it "prepares organizations for the Validated Assessment and manages the assessor relationship, but the formal assessment must be conducted by an independent authorized assessor."
That applies to us too, and we will say it in our own copy rather than leaving it in a footnote: Top Floor does HITRUST readiness. We do not perform validated assessments and we do not issue certifications. Any firm that offers to both close your gaps and certify the result has a conflict worth asking about directly, in the same way we tell people we do not issue SOC 2 opinions on environments we remediated.
The practical consequence for your budget: the assessor fee is a separate line from the readiness work, and the MyCSF subscription is a third. When you compare two "all-in" numbers, check first whether they are counting the same three things.
The contract decides the tier, not your maturity model
The most common way this decision goes wrong is treating tier selection as a self-assessment of how good your security program is.
Go and read the actual requirement. It is in a contract clause, a vendor security addendum, or a questionnaire, and it is almost always specific. When a health plan or a large provider organization writes HITRUST into an agreement, they usually name a tier or describe one, and an e1 will not close a gap that says i1 or r2. Conversely, if the requirement says only "HITRUST certification", ask the counterparty's vendor risk team which tier satisfies them before you scope anything, exactly as you would ask a buyer which SOC 2 report type they accept.
Three patterns we see:
- Nobody has asked. Then the honest answer is that you are shopping for a certification you have no buyer for.
- A single large customer asked, and named a tier. Scope to that tier. Not the one above it, on the theory that you will need it eventually.
- Several customers ask inconsistently. This is the case where the two-year validity of r2 starts to earn its cost, because you are re-answering the same question repeatedly and the heavier artifact ends the conversation.
When the answer is none of them, yet
Against our own interest, because readiness work is what we sell.
If no customer has named HITRUST, do not buy it. We have made this argument before in our piece on whether HIPAA certification exists, and it holds here with the numbers attached: the cheapest published e1 figure above is $20,000 and the higher source says $35,000, which is real money spent on an artifact nobody has requested. For most health tech companies the first attestation that removes sales friction is a SOC 2 Type II with HIPAA mapping, and we work through that comparison in HITRUST or SOC 2 for healthcare.
If a customer has named it but your controls are genuinely immature, buying the assessment first is also wrong. The assessment measures. It does not fix. Money spent on an authorized assessor while your access reviews are aspirational buys you a documented failure.
And if you are being pushed toward r2 before anyone has scoped you, slow down. The requirement set is generated from scoping factors. Until those exist, nobody, including us, can tell you what r2 costs in your environment.
Where Top Floor fits
We do HITRUST readiness under our HITRUST practice: scoping, gap assessment, remediation planning, evidence preparation and assessor coordination. The underlying Security Rule work usually sits alongside it under our HIPAA practice, and the continuing program version under Compliance as a Service.
We are not a HITRUST Authorized External Assessor and we do not issue certifications. If someone tells you they can do both halves, that is the question to ask them.
How to decide this week
Find the sentence. Not the summary of the requirement, the actual clause in the actual contract or questionnaire, and check whether it names a tier. That single lookup resolves most of this decision, and you can do it today.
If it names a tier, get two scoping conversations booked with authorized assessors and treat the published ranges above as sanity checks rather than budgets. If it does not name a tier, email the counterparty's vendor risk contact and ask. Ten minutes of somebody else's time is cheaper than a $20,000 artifact aimed at the wrong target.
If nobody has named HITRUST at all, close this tab and go read your last risk analysis instead. That obligation is real today, and it is the one an investigator will ask about.
Frequently asked questions
How many controls are in HITRUST e1, i1, and r2?
HITRUST's framework page, read on August 22, 2026 and describing CSF v11.8.0, states that e1 covers 43 core controls and i1 covers 182 control requirements. It does not publish a fixed count for r2, because r2 is risk-tailored: the requirement set is generated from your scoping factors, so two r2 assessments can differ substantially in size. HITRUST describes r2 as carrying the highest level of control requirements. Counts change between CSF versions, so quote a version and a read date whenever you use one.
How long is each HITRUST certification valid?
HITRUST states that e1 is valid for one year, i1 is valid for one year, and r2 is valid for two years. The two-year validity is one of the more material economic differences between the tiers, because it halves the frequency of the assessment cycle for the heaviest assessment. If you are comparing total cost across a three-year horizon rather than a single engagement, the recertification cadence usually moves the answer more than the sticker price of any one assessment.
How much does HITRUST certification cost?
Published figures differ by source and none of them is a survey. The directory soc2auditors.org publishes all-in ranges of $20K to $70K for e1, $60K to $200K for i1, and $150K to $300K or more for r2. Integral Healthcare Solutions, a readiness consultancy, publishes roughly $35,000 to $50,000 for e1, $70,000 to $120,000 for i1, and $100,000 to $500,000 or more for r2. Both have a commercial interest in the answer. Expect the r2 range in particular to be meaningless until your scoping factors are set, since the requirement set itself is generated from them.
Can a consulting firm certify us against HITRUST?
No. A HITRUST validated assessment must be performed by a HITRUST Authorized External Assessor and is then reviewed by HITRUST. Readiness firms, including Top Floor, prepare you for that assessment, manage scoping and evidence, and coordinate with the assessor, but they cannot issue the certification. Treat an offer to both remediate your gaps and certify the outcome as a conflict of interest worth questioning directly.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.