Scrutineer.ai

Scrutineer · By framework

HITRUST compliance software for HITRUST CSF certification readiness

A HITRUST assessment is won or lost on evidence. Every requirement statement is scored on policy, process and implementation, so proving a control is where the budget goes.

Scrutineer maps your controls to the HITRUST CSF, shows what is covered at each maturity level, and keeps evidence current so your assessor validates facts instead of chasing screenshots.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with HITRUST

CSF requirements mapped

Scrutineer maps the controls you already run to HITRUST CSF requirement statements, so you can see the e1, i1 and r2 baselines side by side and pick the assessment you can actually pass.

Scored the way HITRUST scores

HITRUST grades each requirement on maturity, not on a yes or no. Scrutineer tracks policy, procedure and implementation separately, which is where most first-time submissions lose points.

Evidence kept current, not rebuilt

Read-only connections to your cloud, identity and ticketing systems refresh evidence continuously, so an interim assessment or a recertification is not a second full project.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps your controls to HITRUST CSF requirement statements
  • Scopes e1, i1 and r2 against what you can evidence today
  • Tracks policy, procedure and implementation maturity separately
  • Flags gaps before an external assessor validates them
  • Reuses HIPAA, SOC 2 and ISO 27001 evidence across frameworks
  • Keeps documentation current for interim and recertification work
HITRUST readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Assessment reference

HITRUST e1, i1 and r2, compared

HITRUST publishes three assessment types on one framework. The difference is how many requirement statements are in scope, how long the result lasts, and how much assurance a customer reads into it.

Assessment Requirement statements Valid for Who it fits
e1, Essentials, 1-year Roughly 44 in the current CSF version, covering foundational cybersecurity practices only. One year from issuance. Early-stage companies and lower-risk vendors that need a credible, externally validated certificate quickly.
i1, Implemented, 1-year 182 in CSF v11.7 and v11.8. A fixed best-practice set that HITRUST re-baselines against current threats. One year from issuance. Moderate-risk vendors. This is the level a growing number of healthcare buyers now accept instead of insisting on an r2.
r2, Risk-based, 2-year Tailored by risk factors, commonly 300 to 400 or more, with roughly 250 as the practical floor. Two years, with a required interim assessment at the one-year mark. Organizations holding large volumes of regulated data, or anyone whose customer contract names r2 specifically.
Readiness work before any of them Whichever baseline you intend to submit, scored internally against real evidence. Not a certification and never presented as one. Every team, before engaging an assessor. This is where Scrutineer sits.

Requirement counts move with the CSF version. HITRUST CSF v11.8.0 became mandatory for new e1, i1 and rapid assessments created after May 7, 2026. Validated assessments are performed by a HITRUST Authorized External Assessor, which submits working papers to HITRUST; HITRUST performs its own quality assurance review and issues the certification. Scrutineer prepares and maintains the evidence behind that submission and does not perform or issue a HITRUST assessment.

Good questions

Questions about HITRUST

HITRUST certification is a third-party validated attestation that an organization meets the requirement statements of the HITRUST CSF, a control framework that harmonizes HIPAA, ISO 27001, NIST and other authoritative sources into one assessable set. A HITRUST Authorized External Assessor performs the validated assessment and submits it; HITRUST runs its own quality assurance review and issues the certification.
There are three: e1, i1 and r2. The e1 covers foundational cybersecurity practices and is valid for one year. The i1 uses a fixed set of 182 requirement statements aimed at moderate risk and is also valid for one year. The r2 is tailored by risk factors, commonly runs 300 to 400 or more requirement statements, and is valid for two years with a required interim assessment at the one-year mark.
Reported all-in ranges are roughly $20,000 to $70,000 for an e1, $60,000 to $200,000 for an i1, and $150,000 to $300,000 or more for an r2, covering the external assessor, the MyCSF subscription and HITRUST report credits. Those are third-party reported figures, so confirm current pricing with HITRUST and your chosen assessor. Internal remediation labor is usually the larger line item and is not included in any of them.
SOC 2 is an attestation by a licensed CPA firm against the Trust Services Criteria, and the auditor decides what testing is adequate. HITRUST is a prescriptive framework with scored requirement statements, and HITRUST itself reviews and issues the result. SOC 2 is more flexible and cheaper; HITRUST is more prescriptive and carries more weight with healthcare buyers.
You scope the assessment in MyCSF, answer every requirement statement in the selected baseline, and score each one on policy, procedure and implementation maturity. An Authorized External Assessor validates your answers and evidence, then submits the working papers to HITRUST. Certification requires meeting the scoring threshold across the scored maturity levels, with any shortfalls carried as corrective action plans.
Reported timelines run roughly three to four months for an e1, six to twelve months for an i1, and nine to twenty-four months for an r2. The variable is almost never the assessment itself. It is the remediation and evidence work in front of it, which is why teams that already run mapped, evidenced controls finish near the low end of each range.
CSF stands for Common Security Framework. It is a control framework that maps dozens of authoritative sources, including HIPAA, ISO 27001, NIST SP 800-53 and PCI DSS, into a single set of requirement statements you can be assessed against once. The current version is v11.8.0, which added mappings for continuous monitoring, privacy and large language model risk.
No. Only HITRUST issues a HITRUST certification, after an Authorized External Assessor validates your assessment. Scrutineer is readiness and decision-support: it maps your controls to CSF requirement statements, shows where the evidence is thin, and keeps documentation current so the validated assessment is faster and cheaper.

Keep reading

Guides that go deeper on HITRUST and the frameworks around it

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification