Recent HITRUST updates are giving organizations a few important planning items to keep in view.
Since our April HITRUST update, HITRUST has released the HITRUST CSF® version 11.8.0, confirmed how new e1 and i1 assessment objects should be created in MyCSF, and continued to prepare for changes to how certification reports are shared through the HITRUST Report Center.
These changes are not a major shift in how organizations are assessed. Instead, they are practical updates that can affect timing, scoping, customer communication, and how completed reports are distributed to relying parties.
In this edition of our quarterly newsletter, we highlight the key updates and what they might mean for organizations preparing for HITRUST assessments in 2026.
On May 7, HITRUST issued HAA 2026-002 announcing that CSF v11.8.0 would be available in MyCSF and downloadable as of May 8. The release continues HITRUST’s ongoing effort to reduce overlap in the CSF while keeping the framework aligned to relevant standards and security expectations.
Key updates include:
For organizations, the main takeaway is straightforward: CSF v11.8.0 should be considered during upcoming assessment planning, especially when scoping factors, authoritative source mappings, or how e1 and i1 baseline requirements might affect the assessment approach.
HITRUST also issued HAA 2026-003 to clarify the creation deadline for e1 and i1 assessments using CSF v11.7.0. Effective May 7, new e1, i1, and rapid assessment objects in MyCSF must be created using CSF v11.8.0.
This clarification does not mean every existing v11.7.0 assessment needs to restart. Existing e1 and i1 assessments already created under CSF v11.7.0 can continue to be submitted. HITRUST will announce future submission deadlines for those assessments at least 90 days in advance.
HITRUST is preparing changes for how organizations share certification information with customers, prospects, assessors, and other relying parties. Through the HITRUST Report Center, report sharing is expected to move from email and other manual distribution methods to a more controlled process managed directly in MyCSF.
This change is intended to give assessed entities more control over who can access their HITRUST reports and which report type can be shared. Recipients, including external assessors, are expected to request access through the HITRUST Report Center unless access already has been granted.
Based on current HITRUST planning, the HITRUST Report Center is expected to include the following changes.
Organizations should also understand what the HITRUST Report Center is not expected to change. HITRUST has indicated that this update is not intended to change assessment requirements, testing, scoring, quality assurance, or certification criteria.
The current target release is expected in Q3 2026. HITRUST will provide additional implementation details before the rollout, including an assessed entity webinar and related handbook updates after the advisory is published.
Historically, report sharing often was handled through email or other manual processes after certification. With the launch of the HITRUST Report Center, sharing will become more closely connected to MyCSF administration and access management.
Organizations should start thinking about who will own HITRUST Report Center access, how customer requests will be reviewed, and which report type should be shared in different business situations.
Clients that regularly share HITRUST reports with customers might need to update their communication process. Rather than attaching reports to emails, organizations might need to direct customers to the HITRUST Report Center and explain how access requests will work.
This change is also a good opportunity to review standard sales, procurement, and vendor risk responses to make sure they reflect the new sharing approach once HITRUST publishes final instructions.
HITRUST and Trium Cyber conducted an article series on third-party risk. The series began with “The Missing Measure in Third-Party Information Risk,” which examines why organizations need a trusted, standardized way to convert fragmented third-party evidence into decision-ready risk insight.
The second article of the series, “The Hidden Weakness in Third-Party Cyber Risk Transfer,” highlights the limitations of relying on vendor cyber insurance and explores how shared policy limits, incomplete insurance disclosures, and inconsistent coverage terms can leave organizations exposed to residual risk when third-party cyber incidents impact multiple customers.
Organizations preparing for 2026 and 2027 HITRUST assessments should consider a few practical next steps:
Early coordination among security, compliance, sales, vendor risk, and assessor teams can reduce confusion and help organizations avoid rework during assessment planning and report distribution.
The latest HITRUST updates are practical, but they point to a broader trend. HITRUST is continuing to refine the CSF and the supporting assessment process and making it easier for organizations to demonstrate certification status to customers and relying parties.
Organizations that treat HITRUST as an ongoing part of their risk and assurance program, rather than a one-time certification project, can be better positioned to manage version changes, reporting expectations, and customer requests as the program continues to evolve.
If you would like to discuss how these developments might affect your 2026 HITRUST road map, please contact the Crowe HITRUST team.
As a HITRUST Authorized External Assessor and a current HITRUST Authorized External Assessor Council member, we’re here to help keep you apprised of the most current changes. Our team also regularly provides insights and participates in discussions concerning the growth and evolution of HITRUST.
We look forward to hearing your questions and comments.