Scrutineer · By framework
HITRUST compliance software for HITRUST CSF certification readiness
A HITRUST assessment is won or lost on evidence. Every requirement statement is scored on policy, process and implementation, so proving a control is where the budget goes.
Scrutineer maps your controls to the HITRUST CSF, shows what is covered at each maturity level, and keeps evidence current so your assessor validates facts instead of chasing screenshots.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with HITRUST
CSF requirements mapped
Scrutineer maps the controls you already run to HITRUST CSF requirement statements, so you can see the e1, i1 and r2 baselines side by side and pick the assessment you can actually pass.
Scored the way HITRUST scores
HITRUST grades each requirement on maturity, not on a yes or no. Scrutineer tracks policy, procedure and implementation separately, which is where most first-time submissions lose points.
Evidence kept current, not rebuilt
Read-only connections to your cloud, identity and ticketing systems refresh evidence continuously, so an interim assessment or a recertification is not a second full project.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps your controls to HITRUST CSF requirement statements
- Scopes e1, i1 and r2 against what you can evidence today
- Tracks policy, procedure and implementation maturity separately
- Flags gaps before an external assessor validates them
- Reuses HIPAA, SOC 2 and ISO 27001 evidence across frameworks
- Keeps documentation current for interim and recertification work
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Assessment reference
HITRUST e1, i1 and r2, compared
HITRUST publishes three assessment types on one framework. The difference is how many requirement statements are in scope, how long the result lasts, and how much assurance a customer reads into it.
| Assessment | Requirement statements | Valid for | Who it fits |
|---|---|---|---|
| e1, Essentials, 1-year | Roughly 44 in the current CSF version, covering foundational cybersecurity practices only. | One year from issuance. | Early-stage companies and lower-risk vendors that need a credible, externally validated certificate quickly. |
| i1, Implemented, 1-year | 182 in CSF v11.7 and v11.8. A fixed best-practice set that HITRUST re-baselines against current threats. | One year from issuance. | Moderate-risk vendors. This is the level a growing number of healthcare buyers now accept instead of insisting on an r2. |
| r2, Risk-based, 2-year | Tailored by risk factors, commonly 300 to 400 or more, with roughly 250 as the practical floor. | Two years, with a required interim assessment at the one-year mark. | Organizations holding large volumes of regulated data, or anyone whose customer contract names r2 specifically. |
| Readiness work before any of them | Whichever baseline you intend to submit, scored internally against real evidence. | Not a certification and never presented as one. | Every team, before engaging an assessor. This is where Scrutineer sits. |
Requirement counts move with the CSF version. HITRUST CSF v11.8.0 became mandatory for new e1, i1 and rapid assessments created after May 7, 2026. Validated assessments are performed by a HITRUST Authorized External Assessor, which submits working papers to HITRUST; HITRUST performs its own quality assurance review and issues the certification. Scrutineer prepares and maintains the evidence behind that submission and does not perform or issue a HITRUST assessment.
Good questions
Questions about HITRUST
Keep reading
Guides that go deeper on HITRUST and the frameworks around it
HITRUST vs SOC 2
What each one proves, who issues it, what the two cost, and which one your customers are actually asking for.
Read the guideThe HIPAA compliance checklist
The Security Rule safeguards behind a large share of the HITRUST CSF requirement statements, and the evidence for each.
Read the guideAll 93 ISO 27001 Annex A controls
Another authoritative source the CSF maps, and the control set most teams have already evidenced before they start HITRUST.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification