Skip to main content
—
Framework library
Framework module · hitrust-csf-v11-7

HITRUST CSF

A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.

v11.8.0 · HITRUST Alliance · published 2026-05-08

Standing today
Acquisition required

00Answer

from the registry record
What is HITRUST CSF?
A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
Who does HITRUST CSF apply to?
HITRUST CSF applies to healthcare, technology, financial services, US, global, per HITRUST Alliance.
What is the current version of HITRUST CSF?
The current edition is v11.8.0, issued by HITRUST Alliance and published 2026-05-08. Source: https://hitrustalliance.net/hitrust-csf/.
What does an assessment under HITRUST CSF require?
No control catalog has been ingested for HITRUST CSF yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Acquisition required

Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.

HITRUST CSF cannot be onboarded yet: Acquisition required before authoritative verbatim inventory generation. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.

HITRUST CSF cannot be onboarded yet: Acquisition required before authoritative verbatim inventory generation. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.

02Registry record

checked 2026-09-06
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Information protection program · Access control · Endpoint protection · Risk management · Third-party assurance
Applies to
healthcare · technology · financial services · US · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06
Pending change
New e1, i1, and rapid assessment objects can no longer be created on CSF v11.7.0 as of 2026-05-07 — all new assessments must be created on v11.8.0. Assessment objects already created on v11.7.0 may still be submitted; this is a wind-down, not a hard cutoff, and HITRUST has committed to announcing the v11.7.0 submission deadline at least 90 days in advance.Expected: Submission deadline not yet announced (≥90 days' notice promised)

03Version ledger

2 editions
v11.7.0Supersededdate not published
v11.8.0Current edition · supersedes v11.7.02026-05-08

03aCoexisting versions

1 other version in force
  1. v11.7.0 (submission-only wind-down)

    Applies to: e1, i1, and rapid assessment objects created before 2026-05-07 that have not yet been submitted

    No scheduled end date — HITRUST has not yet announced the v11.7.0 submission deadline; it has committed to giving at least 90 days' notice before setting one.

    Source (opens in a new tab)

04Authority intelligence

reviewed 2026-08-30

Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.

  1. Standards release

    HITRUST CSF v11.8 refreshes authoritative-source mappings.

    Version 11.8 continues requirement-statement consolidation and refreshes mappings including PCI DSS v4.0.1 and the AICPA SOC 2 Trust Services Criteria.

    Operating move

    Pin the assessment object to its licensed CSF version, preserve the prior mapping basis, and re-evaluate affected evidence candidates before carrying them forward.

05Change history

06Related frameworks

scored from registry facts
  1. Shared Assessments SIG2026 annual release

    Also applies to financial services · The licensed Standardized Information Gathering questionnaire used for risk-based third-party due diligence across security, privacy, resilience, and operational domains. SIG responses are assessment inputs—not a certification, attestation, or independent assurance opinion.

  2. HIPAA Security Rule45 CFR Part 164 Subparts A and C

    Also applies to healthcare · The federal safeguards standard for electronic protected health information, binding on covered entities and their business associates.

  3. SOC 22017 TSC (revised points of focus, 2022)

    Also applies to technology · Independent assurance over how a service organization handles customer data. Type 1 and Type 2 are two report options over the same criteria, not two standards.

  4. Digital Operational Resilience ActRegulation (EU) 2022/2554

    Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.

HITRUST CSF | ControlFrame