HITRUST CSF v11.8.0 Adds AI and Compliance Mappings and Consolidates Requirement Statements
HITRUST announced CSF version 11.8.0 on May 7, 2026, with the framework available in MyCSF and as a download from May 8, 2026. The release continues the consolidation of requirement statements to reduce overlap within the CSF, adjusts the e1 and i1 baselines, and adds authoritative source mappings including the OWASP Top 10 for Large Language Model Applications 2025 and the Commonwealth of Virginia IT Resource Management Standard SEC530. New e1, i1 and rapid assessment objects created in MyCSF must use v11.8.0, while assessments already created under v11.7.0 may still be submitted.
Key Analytics
Impact Analysis
The AI mapping is the part worth planning around. By pulling the OWASP Top 10 for LLM Applications into the authoritative sources, HITRUST gives organizations deploying generative AI a route to assess those systems inside an assurance program they already run, rather than standing up a separate AI review. Teams mid-cycle should check which CSF version their assessment object was created under before assuming their requirement set is unchanged, because the baseline adjustments and statement consolidation mean a v11.8.0 assessment is not a like-for-like continuation of a v11.7.0 one. Organizations that treat a HITRUST certification as a fixed annual target tend to discover version drift late, when the requirement count in MyCSF no longer matches the evidence they collected against.
Recommended Actions
- Confirm which CSF version your current assessment objects were created under, since v11.7.0 assessments may still be submitted but new e1, i1 and rapid objects require v11.8.0
- Re-baseline your evidence inventory against the consolidated requirement statements rather than assuming a one-to-one carryover from v11.7.0
- Map any generative AI systems in scope against the newly added OWASP Top 10 for LLM Applications 2025 authoritative source
- Review the e1 and i1 baseline changes before committing to an assessment tier for the coming cycle
- Check the HITRUST advisories feed for the creation deadlines that retire each prior CSF version, which are published separately from the release advisory
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Gap assessment against current controls
- ›Delta analysis of changed requirements
- ›Policy and control updates
- ›Re-certification planning
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 60 to 155 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.