Crowe Quarterly Update on HITRUST – July 2026

Erika L. Del Giudice, Garret Pistiner
| 7/20/2026
Business professionals discuss HITRUST program updates and cybersecurity compliance strategies.

As we move into the second half of 2026, we highlight key updates in the HITRUST program and reflect on the most impactful developments from the last quarter. 

Recent HITRUST updates are giving organizations a few important planning items to keep in view.

Since our April HITRUST update, HITRUST has released the HITRUST CSF® version 11.8.0, confirmed how new e1 and i1 assessment objects should be created in MyCSF, and continued to prepare for changes to how certification reports are shared through the HITRUST Report Center.

These changes are not a major shift in how organizations are assessed. Instead, they are practical updates that can affect timing, scoping, customer communication, and how completed reports are distributed to relying parties.

In this edition of our quarterly newsletter, we highlight the key updates and what they might mean for organizations preparing for HITRUST assessments in 2026.

Assurance program updates

CSF v11.8.0: A practical framework update

On May 7, HITRUST issued HAA 2026-002 announcing that CSF v11.8.0 would be available in MyCSF and downloadable as of May 8. The release continues HITRUST’s ongoing effort to reduce overlap in the CSF while keeping the framework aligned to relevant standards and security expectations.

Key updates include:

  • Continued requirement statement consolidation to reduce overlap within the CSF
  • New authoritative source mappings, including NIST SP 800-137, ISO/IEC 29100:2024, and OWASP Top 10 for LLM Applications 2025
  • Refreshed mappings for areas such as PCI DSS v4.0.1, AICPA SOC 2 Trust Services Criteria, and the Texas Medical Records Privacy Act

For organizations, the main takeaway is straightforward: CSF v11.8.0 should be considered during upcoming assessment planning, especially when scoping factors, authoritative source mappings, or how e1 and i1 baseline requirements might affect the assessment approach.

New e1 and i1 assessments and CSF v11.8.0 

HITRUST also issued HAA 2026-003 to clarify the creation deadline for e1 and i1 assessments using CSF v11.7.0. Effective May 7, new e1, i1, and rapid assessment objects in MyCSF must be created using CSF v11.8.0.

This clarification does not mean every existing v11.7.0 assessment needs to restart. Existing e1 and i1 assessments already created under CSF v11.7.0 can continue to be submitted. HITRUST will announce future submission deadlines for those assessments at least 90 days in advance.

HITRUST Report Center: A simpler way to share certification information 

HITRUST is preparing changes for how organizations share certification information with customers, prospects, assessors, and other relying parties. Through the HITRUST Report Center, report sharing is expected to move from email and other manual distribution methods to a more controlled process managed directly in MyCSF.

This change is intended to give assessed entities more control over who can access their HITRUST reports and which report type can be shared. Recipients, including external assessors, are expected to request access through the HITRUST Report Center unless access already has been granted.

Based on current HITRUST planning, the HITRUST Report Center is expected to include the following changes.

  • HITRUST is expected to move toward two primary report types: the Certification Summary and the Certification Report.
  • Completion letters in MyCSF are expected to include a link and QR code to the assessment’s HITRUST Report Center dashboard.
  • Organizations will be able to control which reports are shared with relying parties.

Organizations should also understand what the HITRUST Report Center is not expected to change. HITRUST has indicated that this update is not intended to change assessment requirements, testing, scoring, quality assurance, or certification criteria.

The current target release is expected in Q3 2026. HITRUST will provide additional implementation details before the rollout, including an assessed entity webinar and related handbook updates after the advisory is published.

Crowe insights

New integration capabilities
Crowe has recently added integration capabilities with HITRUST’s MyCSF tool to support organizations that are pursuing HITRUST certification and simplifying the evidence upload and linking process. This capability reduces the administrative effort and complexity of a HITRUST assessment by streamlining how evidence is managed in the HITRUST MyCSF platform. In addition, this integration provides better visibility and tracking of evidence status throughout the HITRUST assessment life cycle.
Version planning: Earlier is better
The move to CSF v11.8.0 is manageable, but version selection can affect assessment setup and planning. In addition, with v11.8.0, there are modifications to two requirement statements in the current e1 and i1 baseline. Organizations planning on moving to v11.8.0 should review those modifications to verify they are still operating the control.
Report sharing and the certification life cycle

Historically, report sharing often was handled through email or other manual processes after certification. With the launch of the HITRUST Report Center, sharing will become more closely connected to MyCSF administration and access management.

Organizations should start thinking about who will own HITRUST Report Center access, how customer requests will be reviewed, and which report type should be shared in different business situations.

Refreshing customer communication

Clients that regularly share HITRUST reports with customers might need to update their communication process. Rather than attaching reports to emails, organizations might need to direct customers to the HITRUST Report Center and explain how access requests will work.

This change is also a good opportunity to review standard sales, procurement, and vendor risk responses to make sure they reflect the new sharing approach once HITRUST publishes final instructions.

Streamlining third-party risk management
In this joint blog post with HITRUST, we discuss the challenge many organizations have regarding third-party risk assessments that rely on labor-intensive manual reviews. Such reviews can take months to complete, delay procurement and business decisions, reduce agility, and potentially cause lost revenue or missed customer and compliance opportunities.
Cyber insurance

HITRUST and Trium Cyber conducted an article series on third-party risk. The series began with “The Missing Measure in Third-Party Information Risk,” which examines why organizations need a trusted, standardized way to convert fragmented third-party evidence into decision-ready risk insight.

The second article of the series, “The Hidden Weakness in Third-Party Cyber Risk Transfer,” highlights the limitations of relying on vendor cyber insurance and explores how shared policy limits, incomplete insurance disclosures, and inconsistent coverage terms can leave organizations exposed to residual risk when third-party cyber incidents impact multiple customers.

2026 assessment planning: Practical considerations

Organizations preparing for 2026 and 2027 HITRUST assessments should consider a few practical next steps:

  • Confirm the CSF version before creating new e1, i1, or rapid assessments in MyCSF
  • Review whether any new or refreshed authoritative source mappings affect scoping or reporting expectations
  • Identify who will manage HITRUST Report Center access once the functionality becomes available
  • Prepare customer-facing language explaining how customers can request or view HITRUST reports through the HITRUST Report Center
  • Watch for HITRUST’s Q3 rollout details, webinar, advisory, and handbook updates

Early coordination among security, compliance, sales, vendor risk, and assessor teams can reduce confusion and help organizations avoid rework during assessment planning and report distribution.

Looking ahead

The latest HITRUST updates are practical, but they point to a broader trend. HITRUST is continuing to refine the CSF and the supporting assessment process and making it easier for organizations to demonstrate certification status to customers and relying parties.

Organizations that treat HITRUST as an ongoing part of their risk and assurance program, rather than a one-time certification project, can be better positioned to manage version changes, reporting expectations, and customer requests as the program continues to evolve.

If you would like to discuss how these developments might affect your 2026 HITRUST road map, please contact the Crowe HITRUST team.

HITRUST assessment services
Our collaborative, customizable HITRUST assessment services remove the guesswork from the process.

Contact our authorized assessors


As a HITRUST Authorized External Assessor and a current HITRUST Authorized External Assessor Council member, we’re here to help keep you apprised of the most current changes. Our team also regularly provides insights and participates in discussions concerning the growth and evolution of HITRUST.

We look forward to hearing your questions and comments.

Erika Del Giudice
Erika L. Del Giudice
Principal, HITRUST Consulting Leader
Garret Pistiner
Garret Pistiner
Cyber Consulting