Scrutineer.ai

Scrutineer · By framework

HITRUST i1 certification software and i1 assessment

A health system's vendor risk team wants a HITRUST i1, and your team has to turn that into a plan. The i1 is HITRUST's one-year, moderate-assurance certification: 182 requirement statements in CSF v11.9, scored on implementation only, tested by an Authorized External Assessor, with an average of 83 or more needed in every domain.

Scrutineer runs the controls the i1 tests on one library already mapped to HIPAA and SOC 2, shows coverage per domain before the assessor does, and keeps the evidence current through year two. Compliance software for readiness, not a certification.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with HITRUST i1

The i1 is scored on implementation, and every domain has to reach 83

HITRUST scores i1 requirement statements on the implemented maturity level only, so a written policy earns little on its own and the assessor looks at whether the control actually runs across your scope. The core statements in each domain have to average at least 83. One weak domain produces a validated report without a certificate, however strong the others are. Scrutineer tracks coverage per control and per system, which is the number the assessor computes.

Controls have to run for 90 days before the assessor tests them

HITRUST's assessment handbook sets an incubation period for the i1: a control must have operated for 90 days before it is tested, and policies and procedures for 60 days. A control you deploy the month before fieldwork does not count yet. HITRUST says most companies complete the i1 process in 6 to 12 months, and the incubation clock is usually what sets the date.

Year two is decided by what you leave open in year one

An i1 lasts 12 months, and the cheaper second year runs through rapid recertification. HITRUST then tests every statement added in the newer CSF version, a sample of 60 previously scored statements, every statement that needed a corrective action plan and every statement marked not applicable. Closing CAPs and keeping N/A honest in year one shrinks year two.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Runs the controls the i1 tests (access control, MFA, endpoint protection, vulnerability and patch management, logging, encryption, third-party assurance, incident response, backup and recovery) on one library already mapped to HIPAA and SOC 2
  • Shows implementation coverage per control and per system, so a domain heading below 83 is visible before the External Assessor scores it
  • Timestamps when each control started producing evidence, so you can see which ones have cleared the 90-day incubation period
  • Keeps the evidence an assessor samples current through read-only connections to your cloud, identity and device tools, which is what a 60-statement rapid recertification sample draws on
  • Lists every service provider in scope with the evidence you rely on, because third-party assurance is its own i1 domain
  • Answers health system security questionnaires from the same record while the i1 is in progress
  • Loads the i1 baseline as its own framework mapped onto your controls on the Enterprise plan, and carries the same controls forward if a customer later asks for an r2
HITRUST i1 readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Why year one sets the cost of year two

HITRUST i1 rapid recertification, statement by statement

Most guides describe the i1 as a one-year certificate. In practice it is a two-year plan, because the year-two rapid recertification does not resample everything at random. Some statements are always retested, and you decide which ones in year one.

Statement in your i1 Year one full assessment Year two rapid recertification What to do in year one
Scored fully compliant, no CAP Tested by the External Assessor Rolls forward unless it is drawn into the sample of 60 Keep the evidence current, since any of these can be sampled
Needed a corrective action plan Tested, CAP recorded in the report Always retested, outside the sample Close the CAP with evidence before the year-two representation letter
Logged as a gap (control reference averaged 80 or more) Tested, gap recorded, no CAP required Eligible for the sample of 60 Fix it anyway while it is cheap, before it is drawn
Marked not applicable Justified to the assessor Always retested Mark N/A only what is truly outside scope
New in the newer CSF version Not part of your year-one baseline Always tested Watch the CSF release advisories and add the new statements early
Scope change or significant change Not applicable Rapid recertification not available, a full assessment again Hold the assessed scope stable through the year
Readiness in Scrutineer Your controls scored against real evidence before you engage an assessor Evidence kept current between assessments Not a certification and never presented as one

Sources: HITRUST advisory HAA 2026-005 (CSF v11.9.0 released September 24, 2026; i1 baseline remains 182 requirement statements; every e1 statement is in the i1 and every i1 statement is in the r2), the HITRUST Assessment Handbook v1.1 (83 per domain, implemented level scored, 90-day control and 60-day policy incubation, 90-day fieldwork, rapid recertification sample of 60 plus CAP, N/A and new statements, same scope required) and the HITRUST i1 data sheet. Scrutineer prepares and maintains evidence and does not perform or issue a HITRUST assessment.

Good questions

Questions about HITRUST i1

HITRUST i1 (Implemented, 1-year) is a validated assessment and certification of leading cybersecurity practices. An Authorized External Assessor tests a fixed set of 182 HITRUST CSF requirement statements in v11.9, HITRUST runs a quality review, and HITRUST issues a certificate valid for 12 months. It sits between the smaller e1 and the risk-based r2.
The i1 has 182 requirement statements in HITRUST CSF v11.9.0, released September 24, 2026, the same count as v11.8. All 44 e1 statements are inside it, and every i1 statement is inside the r2. Older guides still quote 219, which was the count under CSF v9 and no longer applies.
The i1 is a fixed 182-statement baseline scored on implementation, valid for one year, aimed at moderate assurance. The r2 is tailored to your risk factors, usually several hundred statements, scored on policy, procedure and implementation, and valid for two years with an interim assessment. Pick the r2 only when a contract names it, because it is the heavier program.
Ask the customer first. The e1 covers 44 foundational statements for lower-risk vendors, while the i1 covers 182 statements and a broader set of active threats for moderate-risk relationships. A vendor handling large volumes of PHI for a health system is usually asked for the i1. Every e1 statement is reused if you start with the e1 and move up.
HITRUST says most companies complete the i1 process within 6 to 12 months. The floor comes from incubation: controls must have operated for 90 days and policies for 60 days before testing, and fieldwork can run up to 90 days. A team whose controls already produce evidence across every in-scope system lands near six months.
HITRUST does not publish i1 prices. The cost has four parts it names itself: a MyCSF subscription, a validated assessment report credit, the External Assessor fee, and your own remediation work. Third-party estimates disagree widely, so get two assessor quotes on the same scope. The assessor fee and the remediation you still have to do move the total most.
The core requirement statements in each assessment domain must average at least 83. It is a per-domain test, not an overall average, so one weak domain blocks certification and you receive a validated report instead. A statement below fully compliant also needs a corrective action plan when its control reference averages below 80.
Rapid recertification is the shorter year-two path for an i1 earned through a full assessment on CSF v11 or later. The assessor tests every new statement from the newer CSF version, a sample of 60 previously scored statements, every statement that needed a CAP and every statement marked N/A. Scope must stay the same and no significant change can have occurred.
Yes, but they are not what gets scored. The i1 scores the implemented level, so a policy without a working control earns little. HITRUST still expects policies and procedures to have been in place for 60 days before testing, and the assessor will read them to understand how each control is meant to operate.
No. Only HITRUST issues the certification, after an Authorized External Assessor validates your assessment. Scrutineer is the readiness and evidence layer: it runs your controls on one library mapped to HIPAA and SOC 2, shows coverage per domain, and keeps evidence current into year two. Most i1 work fits on Growth at $1,200 a month; loading the i1 baseline as its own framework needs Enterprise.

Keep reading

Guides for the HIPAA and SOC 2 work around a HITRUST i1

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification