Framework module · hitrust-csf-v11-7
HITRUST CSF
A certifiable, prescriptive control set healthcare organizations and their vendors adopt when a customer wants more than an attestation.
v11.8.0 · HITRUST Alliance · published 2026-05-07
Standing today
Acquisition required
01Standing
Acquisition required
Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.
HITRUST CSF cannot be onboarded yet: Acquisition required before authoritative verbatim inventory generation. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
HITRUST CSF cannot be onboarded yet: Acquisition required before authoritative verbatim inventory generation. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
02Registry record
checked 2026-08-06
- Registry status
- Roadmap · modelledWe model the regime — control families and at least one crosswalk map on disk — but no control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Information protection program · Access control · Endpoint protection · Risk management · Third-party assurance
- Applies to
- healthcare · technology · financial services · US · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-06
03Version ledger
2 editions
| v11.7.0 | Superseded | date not published |
| v11.8.0 | Current edition · supersedes v11.7.0 | 2026-05-07 |