Scrutineer.ai

Scrutineer · By framework

HITRUST r2 certification software and r2 vs i1 readiness

A health plan or hospital contract names HITRUST r2, and your team has to decide what that means in work. The r2 is HITRUST's risk-based, two-year certification: a requirement list tailored to your risk factors, scored on policy, procedure and implementation, with every domain needing an average of 71 and a certificate that lasts two years if the interim assessment passes.

Scrutineer runs the controls the r2 tests on one library already mapped to HIPAA and SOC 2, scores each domain before the assessor does, and keeps CAPs and evidence current through the interim year. Compliance software for readiness, not a certification.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Interactive walkthrough on a sample company, not a scan of your systems.

Worked example with sample findings, not a scrutiny of your environment. Not an audit attestation.

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with HITRUST r2

The r2 passes at 71 per domain, which is lower than the e1 and i1, and it is still the hardest

HITRUST certifies an r2 when every assessment domain averages at least 71, and a domain as low as 62 is accepted if corrective action plans are already underway. The e1 and i1 need 83. The r2 number is lower because it scores a different thing: policy, procedure and implementation each carry weight, so a control that runs everywhere but is not written down still loses points. Scrutineer tracks all three for every control.

Your scope decides the requirement list, not a fixed baseline

The e1 and i1 test fixed sets of requirement statements. The r2 is tailored: you answer a questionnaire on geographic, organizational, systematic and regulatory risk factors (record volume, internet exposure, third-party access, which regulations apply) and MyCSF builds the requirement list from the answers. Two vendors can hold an r2 with very different workloads, so scope deliberately before you collect evidence.

Two years only holds if the second year is clean

An r2 is valid for two years on four conditions: annual progress on your CAPs, no breach reportable to a federal or state agency, no significant change to the controls in scope, and a timely interim assessment at the one-year mark. A program that only works in assessment season tends to fail the interim. Scrutineer keeps the evidence and CAP status current all year.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps one control library to the HITRUST CSF and to HIPAA and SOC 2, so r2 evidence also answers the frameworks your customers already ask about
  • Scores each control on whether it is written in a policy, backed by a procedure and implemented across your scope, the three levels most r2 assessments test
  • Shows every domain heading toward the 71 line before the External Assessor computes it, with the weakest requirements listed first
  • Tracks corrective action plans with owners and due dates, because the certificate depends on annual progress on them
  • Keeps evidence current through read-only connections to cloud, identity and device tools, so the interim assessment is a refresh and not a rebuild
  • Lists each service provider in scope and the assessment you rely on, since inheritance and reliance on others still have to be documented
  • Loads the r2 requirement list from your MyCSF tailoring as a custom framework on the Enterprise plan
HITRUST r2 readiness_report
Readiness 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Every finding links to the evidence behind it

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Choosing between the three HITRUST certifications

HITRUST r2 compared with the e1 and i1

Most comparisons call the r2 the hardest and stop there. The scoring is the real difference: the r2 grades whether a control is written, proceduralized and implemented, so its pass mark is lower and the work is different.

Question HITRUST e1 HITRUST i1 HITRUST r2
How the requirement list is built Fixed baseline, 44 statements in CSF v11.9 Fixed baseline, 182 statements Tailored from your answers on risk factors, usually far larger
What each requirement is scored on Implementation Implementation Policy, procedure and implementation (measured and managed can be added)
Score needed in every domain 83 83 71, or 62 with corrective action plans underway
How long the certificate lasts One year One year Two years, with an interim assessment at year one
What fails people most often One weak domain dragging below 83 Coverage gaps across systems Undocumented controls and an interim year with stale evidence
Who it suits Lower-risk vendors and a first step Moderate-risk vendors High-risk relationships and contracts that name r2
Scrutineer readiness Controls and evidence per domain Same library, wider coverage Same library, plus policy and procedure tracking and CAPs

Sources: HITRUST's r2 assessment page (two-year validity, interim assessment, tailoring, inheritance), HITRUST's sample r2 certification report (71 per domain, 62 with CAPs underway, CAP criteria, validity conditions, 75 as the top score when measured and managed are excluded), HITRUST advisory HAA 2026-006 (e1 baseline of 44 in CSF v11.9) and HITRUST's i1 page (182 statements). Scrutineer prepares and maintains evidence and does not perform or issue a HITRUST assessment.

Good questions

Questions about HITRUST r2

HITRUST r2 (Risk-based, 2-year) is HITRUST's most rigorous certification. An Authorized External Assessor tests a requirement list tailored to your risk factors, scoring policy, procedure and implementation, HITRUST runs a quality assurance review, and HITRUST issues a certificate valid for two years, provided an interim assessment is completed at the one-year mark.
The i1 tests a fixed set of 182 requirement statements on implementation only and lasts one year. The r2 tests a list tailored to your risk profile, scores policy and procedure as well as implementation, and lasts two years with an interim assessment. Choose the one your customer contract names; when it names neither, the i1 is usually the faster first certification.
Every assessment domain needs a straight average of at least 71. HITRUST accepts a domain averaging as low as 62 if the organization already has corrective action plans underway. It is a per-domain test, so a strong overall score does not rescue one weak domain.
HITRUST requires a CAP for a requirement when four things are true: its overall score is under 71, its implemented level is below fully compliant, its control reference is required for r2 certification, and that control reference averages under 71. The certificate then depends on annual progress against those CAPs.
HITRUST does not publish an r2 price, and the published estimates disagree widely, so treat any single figure with caution. The cost has four parts: MyCSF subscription, the External Assessor fee, HITRUST's own fees, and your remediation labor. Scope drives all four, because the tailoring questionnaire sets how many requirements the assessor has to test, and the interim assessment adds a second-year cost.
Plan on months, not weeks. The validated assessment follows a readiness period whose length depends on how many requirements your tailoring produces and how much policy, procedure and evidence already exists. HITRUST then runs quality assurance before it issues the certificate. Teams that already run mapped, evidenced controls for SOC 2 or HIPAA spend most of the time on documentation gaps.
It is a check at the one-year mark that the controls certified in year one are still operating. Completing it on time is one of the conditions for the certificate staying valid for its full two years, together with progress on CAPs, no reportable breach and no significant change in the scoped environment.
Yes, within HITRUST's rules. An External Assessor may inherit results from, or rely on, another validated HITRUST assessment, rely on third-party audits, or rely on testing by your internal assessors, and every such use is subject to HITRUST quality assurance and listed in your report. Inheritance reduces testing, it does not remove the requirement from scope.
No certification proves HIPAA compliance, and HHS does not endorse any. An r2 can include HIPAA as a regulatory factor in tailoring, so it covers more of the Security Rule than an e1 or i1, but you still owe a HIPAA risk analysis and the administrative duties the rule places on you.
No. Only HITRUST issues the certification, after an Authorized External Assessor validates your assessment. Scrutineer is the readiness and evidence layer: it shows each domain against the 71 line, tracks CAPs and keeps evidence current for the assessor and the interim year.

Keep reading

Guides for the HIPAA and SOC 2 work around a HITRUST r2

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification