Scrutineer · By framework
HITRUST r2 certification software and r2 vs i1 readiness
A health plan or hospital contract names HITRUST r2, and your team has to decide what that means in work. The r2 is HITRUST's risk-based, two-year certification: a requirement list tailored to your risk factors, scored on policy, procedure and implementation, with every domain needing an average of 71 and a certificate that lasts two years if the interim assessment passes.
Scrutineer runs the controls the r2 tests on one library already mapped to HIPAA and SOC 2, scores each domain before the assessor does, and keeps CAPs and evidence current through the interim year. Compliance software for readiness, not a certification.
Control-mapped findings · linked evidence · you decide what to remediate
Interactive walkthrough on a sample company, not a scan of your systems.
›
Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with HITRUST r2
The r2 passes at 71 per domain, which is lower than the e1 and i1, and it is still the hardest
HITRUST certifies an r2 when every assessment domain averages at least 71, and a domain as low as 62 is accepted if corrective action plans are already underway. The e1 and i1 need 83. The r2 number is lower because it scores a different thing: policy, procedure and implementation each carry weight, so a control that runs everywhere but is not written down still loses points. Scrutineer tracks all three for every control.
Your scope decides the requirement list, not a fixed baseline
The e1 and i1 test fixed sets of requirement statements. The r2 is tailored: you answer a questionnaire on geographic, organizational, systematic and regulatory risk factors (record volume, internet exposure, third-party access, which regulations apply) and MyCSF builds the requirement list from the answers. Two vendors can hold an r2 with very different workloads, so scope deliberately before you collect evidence.
Two years only holds if the second year is clean
An r2 is valid for two years on four conditions: annual progress on your CAPs, no breach reportable to a federal or state agency, no significant change to the controls in scope, and a timely interim assessment at the one-year mark. A program that only works in assessment season tends to fail the interim. Scrutineer keeps the evidence and CAP status current all year.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps one control library to the HITRUST CSF and to HIPAA and SOC 2, so r2 evidence also answers the frameworks your customers already ask about
- Scores each control on whether it is written in a policy, backed by a procedure and implemented across your scope, the three levels most r2 assessments test
- Shows every domain heading toward the 71 line before the External Assessor computes it, with the weakest requirements listed first
- Tracks corrective action plans with owners and due dates, because the certificate depends on annual progress on them
- Keeps evidence current through read-only connections to cloud, identity and device tools, so the interim assessment is a refresh and not a rebuild
- Lists each service provider in scope and the assessment you rely on, since inheritance and reliance on others still have to be documented
- Loads the r2 requirement list from your MyCSF tailoring as a custom framework on the Enterprise plan
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Choosing between the three HITRUST certifications
HITRUST r2 compared with the e1 and i1
Most comparisons call the r2 the hardest and stop there. The scoring is the real difference: the r2 grades whether a control is written, proceduralized and implemented, so its pass mark is lower and the work is different.
| Question | HITRUST e1 | HITRUST i1 | HITRUST r2 |
|---|---|---|---|
| How the requirement list is built | Fixed baseline, 44 statements in CSF v11.9 | Fixed baseline, 182 statements | Tailored from your answers on risk factors, usually far larger |
| What each requirement is scored on | Implementation | Implementation | Policy, procedure and implementation (measured and managed can be added) |
| Score needed in every domain | 83 | 83 | 71, or 62 with corrective action plans underway |
| How long the certificate lasts | One year | One year | Two years, with an interim assessment at year one |
| What fails people most often | One weak domain dragging below 83 | Coverage gaps across systems | Undocumented controls and an interim year with stale evidence |
| Who it suits | Lower-risk vendors and a first step | Moderate-risk vendors | High-risk relationships and contracts that name r2 |
| Scrutineer readiness | Controls and evidence per domain | Same library, wider coverage | Same library, plus policy and procedure tracking and CAPs |
Sources: HITRUST's r2 assessment page (two-year validity, interim assessment, tailoring, inheritance), HITRUST's sample r2 certification report (71 per domain, 62 with CAPs underway, CAP criteria, validity conditions, 75 as the top score when measured and managed are excluded), HITRUST advisory HAA 2026-006 (e1 baseline of 44 in CSF v11.9) and HITRUST's i1 page (182 statements). Scrutineer prepares and maintains evidence and does not perform or issue a HITRUST assessment.
Good questions
Questions about HITRUST r2
Keep reading
Guides for the HIPAA and SOC 2 work around a HITRUST r2
HITRUST vs SOC 2
What each one proves, who issues it, and which one your customers are actually asking for.
Read the guideHIPAA compliance checklist
The Security Rule duties that sit alongside an r2 certificate.
Read the guideBest HIPAA risk assessment software
The risk analysis HIPAA still requires after you hold an r2.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification