Skip to content
    Back to Regulatory Radar
    ImportantFramework UpdateMay 8, 2026

    HITRUST CSF v11.8.0 Adds AI and Compliance Mappings and Consolidates Requirement Statements

    HITRUST announced CSF version 11.8.0 on May 7, 2026, with the framework available in MyCSF and as a download from May 8, 2026. The release continues the consolidation of requirement statements to reduce overlap within the CSF, adjusts the e1 and i1 baselines, and adds authoritative source mappings including the OWASP Top 10 for Large Language Model Applications 2025 and the Commonwealth of Virginia IT Resource Management Standard SEC530. New e1, i1 and rapid assessment objects created in MyCSF must use v11.8.0, while assessments already created under v11.7.0 may still be submitted.

    HITRUSTNIST AI RMFISO 42001HealthcareSaaS

    Key Analytics

    May 8, 2026
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    3
    Frameworks Affected

    Impact Analysis

    The AI mapping is the part worth planning around. By pulling the OWASP Top 10 for LLM Applications into the authoritative sources, HITRUST gives organizations deploying generative AI a route to assess those systems inside an assurance program they already run, rather than standing up a separate AI review. Teams mid-cycle should check which CSF version their assessment object was created under before assuming their requirement set is unchanged, because the baseline adjustments and statement consolidation mean a v11.8.0 assessment is not a like-for-like continuation of a v11.7.0 one. Organizations that treat a HITRUST certification as a fixed annual target tend to discover version drift late, when the requirement count in MyCSF no longer matches the evidence they collected against.

    Recommended Actions

    • Confirm which CSF version your current assessment objects were created under, since v11.7.0 assessments may still be submitted but new e1, i1 and rapid objects require v11.8.0
    • Re-baseline your evidence inventory against the consolidated requirement statements rather than assuming a one-to-one carryover from v11.7.0
    • Map any generative AI systems in scope against the newly added OWASP Top 10 for LLM Applications 2025 authoritative source
    • Review the e1 and i1 baseline changes before committing to an assessment tier for the coming cycle
    • Check the HITRUST advisories feed for the creation deadlines that retire each prior CSF version, which are published separately from the release advisory

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Modeled estimate
    Moderate45-115 hours
    Key Workstreams
    • Gap assessment against current controls
    • Delta analysis of changed requirements
    • Policy and control updates
    • Re-certification planning

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 45-115 hours
    Start cold under pressureSignificant · 105-270 hours

    Roughly 60 to 155 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events