HITRUST CSF
A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
v11.8.0 · HITRUST Alliance · published 2026-05-08
00Answer
01Standing
Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.
HITRUST CSF cannot be onboarded yet: Acquisition required before authoritative verbatim inventory generation. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
HITRUST CSF cannot be onboarded yet: Acquisition required before authoritative verbatim inventory generation. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Information protection program · Access control · Endpoint protection · Risk management · Third-party assurance
- Applies to
- healthcare · technology · financial services · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
- Pending change
- New e1, i1, and rapid assessment objects can no longer be created on CSF v11.7.0 as of 2026-05-07 — all new assessments must be created on v11.8.0. Assessment objects already created on v11.7.0 may still be submitted; this is a wind-down, not a hard cutoff, and HITRUST has committed to announcing the v11.7.0 submission deadline at least 90 days in advance.Expected: Submission deadline not yet announced (≥90 days' notice promised)
03Version ledger
| v11.7.0 | Superseded | date not published |
| v11.8.0 | Current edition · supersedes v11.7.0 | 2026-05-08 |
03aCoexisting versions
- v11.7.0 (submission-only wind-down)
Applies to: e1, i1, and rapid assessment objects created before 2026-05-07 that have not yet been submitted
No scheduled end date — HITRUST has not yet announced the v11.7.0 submission deadline; it has committed to giving at least 90 days' notice before setting one.
Source (opens in a new tab)
04Authority intelligence
Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.
- Standards release
HITRUST CSF v11.8 refreshes authoritative-source mappings.
Version 11.8 continues requirement-statement consolidation and refreshes mappings including PCI DSS v4.0.1 and the AICPA SOC 2 Trust Services Criteria.
Operating movePin the assessment object to its licensed CSF version, preserve the prior mapping basis, and re-evaluate affected evidence candidates before carrying them forward.
05Change history
06Related frameworks
- Shared Assessments SIG2026 annual release
Also applies to financial services · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.
- HIPAA Security Rule45 CFR Part 164 Subparts A and C
Also applies to healthcare · The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.
- SOC 22017 TSC (revised points of focus, 2022)
Also applies to technology · Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.
- Digital Operational Resilience ActRegulation (EU) 2022/2554
Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.