Skip to content
    August 25, 2026| Top Floor Team| 13 min read

    How Long Does HITRUST Take?

    HITRUST answers this question itself for two of its three assessments and declines to for the third. Read on August 25, 2026, HITRUST's e1 page says certification can take "as little as a few weeks, with the average time for most organizations being around 30 days", and its i1 page says most companies complete the i1 certification process within 6 to 12 months. Its r2 page publishes a two-year validity and an interim assessment after one year, and no duration at all; the only r2 estimate on this site is our own, from our HITRUST service page, at 9 to 15 months from readiness through certification. The contrarian part is that the calendar is not mostly the assessor's. HITRUST's Assessment Handbook fixes a set of clocks that apply to every tier and cannot be compressed by hiring more help: a 90-day maximum fieldwork window, a 90-day incubation period before a new control can be tested, a 60-day one for policies and procedures, and a QA block you reserve in advance. Everything else on the calendar is your readiness.

    This article takes the tiers in turn: what HITRUST publishes about each, the clocks the handbook writes down, a worked calendar for each tier, what happens after the certificate issues, and the five things that actually move the date. Which tier you need is a different question, answered in HITRUST e1 vs i1 vs r2; whether you need HITRUST at all rather than another framework is answered in HITRUST or SOC 2 for healthcare. What it costs is in what HITRUST certification costs, and no dollar figure appears here.

    Key takeaways

    • HITRUST's own pages, read August 25, 2026: e1 averages around 30 days and can take as few as 4 to 6 weeks depending on readiness; i1 takes most companies 6 to 12 months; r2 has no published duration, only a two-year validity with an interim assessment after one year.
    • The Assessment Handbook caps validated assessment fieldwork at 90 days for all three tiers, and requires controls to have operated for 90 days, and policies and procedures for 60 days, before they can be tested.
    • QA is scheduled, not queued: you reserve a one-week QA block up to a year in advance, need a report credit to do so, and should expect to hear from HITRUST within seven to ten business days after the block ends. For e1, HITRUST commits to a post-submission service level of not more than 30 business days.
    • The certificate is not the end of the calendar. e1 and i1 are reassessed every year, i1 has a rapid recertification path built on a 120-day window, and r2 requires an interim assessment in the 90-day window before its first anniversary.
    • Remediation resets the incubation clock. The single largest cause of a slipped HITRUST date in our experience is a control fixed during fieldwork that then has to wait 90 days to be testable.

    What HITRUST itself publishes about duration

    The table is built only from HITRUST's own pages, so that the empty cell is visible rather than filled in.

    AssessmentHITRUST's published durationValidityWhat HITRUST says about renewal
    e1As few as 4 to 6 weeks depending on readiness; "the average time for most organizations being around 30 days"1 yearAnnual reassessment
    i1Most companies complete the i1 certification process within 6 to 12 months1 yearAnnual reassessment, with a rapid recertification option in year two that focuses "on approximately 60 core controls rather than the full 182-control set"
    r2None published on the r2 page or the framework page2 years"Organizations must complete an interim assessment after one year to confirm continued compliance"

    Two things about that table. The e1 figure is HITRUST's marketing for the entry tier, and "depending on readiness" is doing real work in the sentence: the 30-day average describes organisations that arrive with the controls already operating. And the r2 gap is not an oversight. The r2 requirement set is generated from your scoping factors, and HITRUST's own r2 data sheet gives the count as "2000+ based on Tailoring (360 average)". A duration for an assessment whose size varies by an order of magnitude would be a number HITRUST could not stand behind, so it does not publish one. Neither do we, beyond the 9 to 15 month estimate on our service page, which is drawn from our own readiness engagements and is labelled as ours. The two third-party ranges in our tier comparison disagree with each other, which is the same point made twice.

    The clocks written into the Assessment Handbook

    The HITRUST Assessment Handbook, version 1.2, is the document that turns the tiers into a calendar, and it applies the same clocks to all three. These are the ones that decide dates.

    The fieldwork window is 90 days, maximum, for every tier. The handbook's assessment comparison table lists the "Assessor's validated assessment fieldwork window (maximum)" as 90 days for e1, i1 and r2 alike, and criterion 11.2.5 states that "all testing performed by the External Assessor in support of the validated assessment must be conducted in a 90-day period concluding with the Assessed Entity signing the Management Representation Letter." Planning, scoping and document request lists may happen before fieldwork starts; testing may not.

    Controls must have operated for 90 days before they can be tested. Criterion 11.2.8: "all controls established by the Assessed Entity in support of each of the HITRUST requirement statements must be implemented for a minimum of 90 days prior to testing (i.e., 90-day incubation period). This includes either a newly implemented control or a control remediated due to deficiencies." This is the clock that readiness work exists to start early.

    Policies and procedures get a 60-day incubation, and there is a narrow remediation window inside fieldwork. Criterion 11.2.10 requires policies and procedures to be implemented for a minimum of 60 days before the assessor considers them, and then notes the one gap: "as the maximum fieldwork length is 90 days, it is possible for the Assessed Entity to remediate any policy and/or procedure deficiencies identified by the External Assessor within the first 30 days of fieldwork." A policy fixed in week five of fieldwork does not make it; a control fixed in week five does not make it either, and has to wait its 90 days.

    QA is reserved, not queued. Chapter 13.1 describes a reservation system in MyCSF where "QA Blocks are one-week periods where HITRUST will begin QA procedures on the assessment", reservations "may be made up to one year in advance of the current date", and "a validated assessment report credit is required to make a reservation." Miss the submission date you entered and the reservation is cancelled with a change fee. After the block, "Assessed Entities should typically expect to hear from HITRUST within seven to ten business days after the end of the QA Block."

    The e1 has a published QA service level. HITRUST's advisory HAA 2023-004, dated January 17, 2023, sets "the established e1 post-submission service level agreement (SLA)" at "not greater than 30 business days with HITRUST", measured from the earlier of the day QA begins or the last day of the reserved block, and counting weekdays in HITRUST-owned phases before the draft report is posted. Submissions "entering escalated QA due to quality concerns are exempted from this SLA."

    Draft review is 30 days, and silence approves. For every tier the handbook gives the Assessed Entity up to 30 days to review draft reports, and "if the Assessed Entity does not approve the draft reports or request revisions within 30 days, the draft reports are automatically approved by MyCSF."

    A worked calendar for each tier

    No dates, because yours will differ, but the sequence and the fixed lengths are the same for everyone.

    e1. Scoping and the pre-assessment webforms; a readiness pass against the 43 core controls, the count HITRUST's framework page gives for the e1 alongside its one-year validity; fieldwork inside a window of up to 90 days that in practice for an e1 is far shorter; submission into a reserved QA block; the 30-business-day SLA; the 30-day draft review. HITRUST's 30-day average is consistent with an organisation whose 43 controls are already operating and whose QA block is reserved before fieldwork starts. An organisation that discovers gaps during fieldwork is looking at the 90-day incubation on each one, which is how "around 30 days" becomes a quarter.

    i1. The same sequence against 182 control requirements, which is where HITRUST's "6 to 12 months" comes from: the readiness and remediation phase dominates, and every remediated control needs its 90 days before the 90-day fieldwork window can close over it. The fieldwork window itself is the same 90-day maximum. Our practical rule is that the i1 calendar is set by the last control you fix, plus 90 days, plus the QA block you were able to reserve.

    r2. Scoping generates the requirement set from your factors, so the calendar cannot be estimated until scoping is done, which is why we refuse to quote r2 dates before it. After that the same clocks apply: incubation, a 90-day fieldwork cap, a reserved QA block, a 30-day draft review. The 9 to 15 months on our service page is our own end-to-end estimate from readiness through certification, and the long pole in it is almost never HITRUST; it is the remediation programme that precedes fieldwork.

    What happens after the certificate

    The calendar does not stop at issuance, and the after-issuance clocks are the ones buyers most often forget to budget time for.

    e1 and i1 are annual. Both are valid for one year, and the Assessment Handbook marks its interim and bridge workflow as "only applicable for r2 validated assessments", so an expiring e1 or i1 is renewed by reassessment rather than bridged. The reassessment is a full assessment, with one exception.

    i1 rapid recertification runs on a 120-day window. HITRUST's advisory HAA 2024-001, dated February 8, 2024, describes the eligibility questionnaire arriving "180 days prior to the expiration of the active i1 Certification", the rapid recertification assessment object being generated "120 days prior to the expiration", and states that "the 120-day period allows for a 30-day planning period and a maximum 90-day fieldwork period." The sample is 60 requirement statements from the full assessment, including every one that required a corrective action plan, and eligibility requires that "the control environment has not materially degraded since the full i1 Assessment was performed" and a full MyCSF subscription. Handbook chapter 15.5 adds that e1 core requirement statements are never eligible for the rapid sampling approach.

    r2 requires an interim assessment in a 90-day window. Handbook chapter 15.4: "for an entity to maintain its r2 certification, an interim assessment must be completed and submitted to HITRUST in the 90-day window leading up to the one-year anniversary of the certification issuance date." The interim "will consist of one randomly selected requirement statement from each of the assessment domains plus all requirement statements that resulted in required CAPs", and HITRUST checks for no significant scope changes, no security events in the certified environment, no lowering of maturity scores in the sampled statements, and sufficient progress on the CAPs. For annual MyCSF subscribers the interim object is generated automatically 90 days before it is due; non-subscribers get a notice and 60 days of access once they ask.

    A bridge buys 90 days, not a renewal. The handbook describes a bridge assessment as allowing an organisation "to maintain a form of HITRUST r2 certification status for an additional 90 days even if its r2 validated assessment recertification date has passed." It is a stopgap for a recertification that ran late, and it exists only for r2.

    What actually moves the date

    Five things, in the order we see them slip a schedule.

    Remediation during fieldwork. A control fixed in fieldwork restarts its own 90-day incubation and can push testing past the 90-day window, which means a new fieldwork period and, often, a new QA reservation. Readiness work exists to find those controls before the window opens.

    The QA reservation. Because QA blocks are reserved and can be booked a year ahead, the constraint is availability of the block you want, not HITRUST's speed once it starts. Reserve when you have a credible submission date, and treat the submission date as a hard commitment, because missing it cancels the reservation and bills a change fee.

    Scoping, for r2. The requirement set is generated from your factors. Until they are entered, there is no calendar to estimate, and a vendor quoting an r2 date before scoping is quoting a guess.

    Inheritance. Handbook criterion 11.2.9 says an Assessed Entity relying on a service provider's control "does not need to wait the 90-day incubation period if it is able to demonstrate the service provider's control has been implemented at least 90 days", and that a provider with a HITRUST certification can be inherited from immediately. That is a calendar effect as much as a cost one, and HITRUST inheritance explained covers what does and does not move.

    Escalated QA. Submissions with quality concerns are routed to escalated QA, are exempt from the e1 service level, and take longer than the normal path. The handbook's whole quality-assurance chapter exists because the fastest QA is the one with no tasks to address, and that is decided by the quality of the submission, which is decided by the readiness work.

    Where Top Floor fits

    Our HITRUST readiness practice is scoped around the clocks above: finding the controls that need their 90 days before fieldwork opens rather than during it, sequencing policy changes ahead of the 60-day incubation, and getting the QA reservation booked against a submission date we believe. The underlying Security Rule work usually sits alongside it under our HIPAA practice, and the continuing programme runs under Compliance as a Service.

    We are not a HITRUST Authorized External Assessor and we do not issue certifications. Fieldwork and QA are performed by the assessor and by HITRUST, and nothing a readiness firm does shortens either. What it shortens is everything before them.

    How to decide this week

    Write down which tier you are being asked for and whether scoping has been done. If the answer is r2 and scoping has not been done, no date anyone gives you this week is real, including ours.

    Then list every control you know is not yet operating and add 90 days to the date you expect to fix it. The latest date on that list, plus the fieldwork window, plus a QA block you can actually reserve, is your earliest certification date. If that lands after the contract deadline that started this, the conversation to have is with the customer about the tier, not with the assessor about speed.

    Frequently asked questions

    How long does HITRUST e1 certification take?

    HITRUST's e1 page, read August 25, 2026, says certification can take as few as 4 to 6 weeks depending on readiness, with the average for most organisations around 30 days. That average describes organisations whose 43 core controls are already operating when fieldwork starts. Any control found wanting during fieldwork needs a 90-day incubation period before it can be tested under the Assessment Handbook, and HITRUST's published post-submission service level for e1 is not more than 30 business days, so an e1 with remediation in it is a quarter rather than a month.

    How long does HITRUST i1 certification take?

    HITRUST's i1 page says most companies complete the i1 certification process within 6 to 12 months. The spread is readiness: 182 control requirements, each remediated one needing 90 days of operation before testing, inside a fieldwork window capped at 90 days, followed by a reserved QA block and a 30-day draft review. In year two an eligible organisation can use rapid recertification, which HITRUST describes as focusing on approximately 60 core controls and which runs on a 120-day window of 30 days planning and up to 90 days fieldwork.

    How long does HITRUST r2 certification take?

    HITRUST publishes no duration for r2 on the pages we fetched, and the reason is structural: the requirement set is generated from your scoping factors, with HITRUST's own data sheet giving the count as 2000 or more based on tailoring and 360 on average, so no single duration would be honest. Our own service page estimates 9 to 15 months from readiness through certification, and that is a Top Floor estimate from our engagements rather than a HITRUST figure. Whatever the total, the fixed parts are the same as the other tiers: 90-day control incubation, a 90-day maximum fieldwork window, a reserved QA block and a 30-day draft review, plus an interim assessment due in the 90-day window before the first anniversary.

    How long is a HITRUST certification valid?

    HITRUST's framework page states that e1 and i1 are valid for one year and r2 for two years. The two-year r2 comes with an interim assessment that must be submitted in the 90-day window leading up to the one-year anniversary of issuance, sampling one requirement statement per assessment domain plus every statement that carried a corrective action plan. A bridge assessment can extend a form of r2 status for a further 90 days if recertification runs late, but it exists only for r2 and it is a stopgap rather than a renewal.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.