HITRUST released CSF v11.9.0 on September 24, 2026, introducing updates to authoritative source mappings, AI security, technology-specific requirements, and the e1 and i1 assessment baselines. The release also establishes important deadlines for organizations still using earlier CSF versions.
For organizations pursuing or maintaining HITRUST e1, i1, or r2 assessments, the most important question is not simply what changed in v11.9.0. It is whether those changes affect your assessment strategy, current MyCSF assessment, evidence, controls, and certification timeline.
The good news is that v11.9.0 is an evolutionary update rather than a complete overhaul of the HITRUST CSF. However, organizations should pay close attention to the updated AI security mappings, e1 baseline changes, refreshed technology requirements, and the transition deadlines for older assessment versions.
What is HITRUST CSF v11.9.0?
HITRUST CSF v11.9.0 is the latest version of the HITRUST Common Security Framework, released on September 24, 2026.
The update includes:
- New, refreshed, and modified authoritative source mappings
- Updates to the e1 and i1 assessment baselines
- New AI security and agentic AI considerations
- Updates to AI Security Certification content
- Technology-specific requirement updates covering areas such as PKI, TLS, and passkeys
- Post-quantum cryptography considerations
- Library enhancements designed to address emerging technologies and risks
HITRUST made the new framework available through MyCSF and as a downloadable framework on September 24, 2026. For organizations already working toward certification, the practical impact depends on which assessment type and CSF version they are using.
What Changed in HITRUST CSF v11.9.0?
The v11.9.0 update can be grouped into four major areas:
- Authoritative source and compliance mappings
- AI and agentic AI security
- Technology and cybersecurity requirements
- e1 and i1 assessment baselines
Each has implications for organizations preparing for a new assessment or maintaining an existing HITRUST program.
1. HITRUST Added New and Refreshed Authoritative Source Mappings
One of the most significant changes in v11.9.0 is the update to HITRUST’s authoritative source mappings. HITRUST refreshed its mapping to NIST SP 800-53 Revision 5.2.0, helping maintain alignment with the current NIST control catalog. The release also adds a new mapping for the OWASP Top 10 for Agentic Applications 2026, including a selectable compliance factor.
This matters because organizations are increasingly deploying AI systems that can interact with applications, APIs, data, and other systems with varying degrees of autonomy. HITRUST has therefore added an explicit way to address emerging security considerations associated with agentic applications.
What does this mean for organizations?
If your organization develops, deploys, or assesses AI-enabled or agentic applications, your compliance program should not treat AI security as an isolated technology issue. You should evaluate how AI systems affect:
- Access control
- Identity and authentication
- Data protection
- Application security
- Third-party risk
- Monitoring and logging
- Vulnerability management
- Incident response
- Security testing
- Governance and accountability
The addition of the OWASP Top 10 for Agentic Applications 2026 mapping is particularly relevant for organizations building or deploying systems where AI can take actions through tools, applications, APIs, or other connected services.
2. HITRUST v11.9 Adds an Agentic AI factor
HITRUST has also added an “Agentic AI” selectable factor to its AI Security Certification. This is an important development for organizations building or operating AI systems that can act beyond simply generating content. HITRUST also updated its AI Security Certification content and incorporated updates responding to AI-enabled vulnerability research initiatives. For organizations developing AI products, platforms, or services, this means AI security assurance is becoming more closely connected to the specific risks created by increasingly autonomous AI applications.
What should AI organizations do?
Organizations should begin mapping their AI environment before an assessment rather than waiting for an assessor to identify gaps. Start by identifying:
- Which AI systems are in scope
- What data those systems access
- Which users and services can interact with them
- What actions AI systems can perform
- What external tools, APIs, or applications they can access
- How AI-related activity is monitored
- How AI security vulnerabilities are identified and remediated
- What third-party AI models, services, or components are being used
This is particularly important for organizations pursuing HITRUST alongside broader AI governance or security initiatives.
3. Technology-specific Requirements Have Been Refreshed
HITRUST v11.9.0 also includes updates to technology-specific requirements. The release specifically identifies areas including:
- Public key infrastructure (PKI)
- Transport Layer Security (TLS)
- Passkeys
HITRUST has also included post-quantum cryptography considerations in the updated CSF library. These changes reflect a broader shift in cybersecurity programs: organizations need to account not only for traditional security controls, but also for how emerging technologies affect authentication, encryption, and long-term data protection.
Why does post-quantum cryptography matter?
Organizations may not need to immediately replace every cryptographic mechanism in their environment simply because post-quantum cryptography is emerging. However, security teams should understand where cryptography is being used, which assets depend on it, and whether long-lived sensitive information could be affected by future cryptographic advances.
For HITRUST preparation, this makes cryptographic asset visibility and documented risk decisions increasingly relevant.
4. The HITRUST e1 Baseline is Changing
One of the most tangible v11.9.0 changes affects the HITRUST e1 assessment baseline. Under v11.9.0, the e1 baseline contains 44 requirement statements. The i1 baseline remains at 182 requirement statements. HITRUST also confirms that all e1 requirements remain included within i1, and all i1 requirements remain included within r2.
This means organizations should review their assessment scope and control readiness rather than assuming that an existing e1 or i1 preparation effort will map perfectly to the new version.
Does HITRUST v11.9 change i1?
The i1 baseline remains at 182 requirement statements, although the release includes changes affecting the baseline and associated requirements. Organizations should therefore review the applicable v11.9 requirements in MyCSF rather than relying solely on documentation prepared against an earlier CSF version.
What happened to older HITRUST CSF versions?
This is one of the most important parts of the v11.9.0 release. HITRUST has established specific deadlines for organizations using older versions.
HITRUST e1 and i1 Transition Deadlines
Between September 24 and December 31, 2026, organizations can create e1 and i1 assessments using either CSF v11.8.0 or v11.9.0. Starting December 31, 2026, organizations will no longer be able to create new e1, i1, or rapid assessment objects using v11.8.0. From that point forward, new e1 and i1 assessments must use CSF v11.9.0.
There is another important date:
March 31, 2027 is the deadline for submitting e1 and i1 assessments using v11.8.0 or earlier. After that date, unsubmitted e1 and i1 assessments using v11.8.0 or earlier will need to be upgraded to v11.9.0 or later before they can be submitted for processing.
What About HITRUST r2?
HITRUST has also announced the decommissioning of CSF v11.0 through v11.3. Maintenance support for those versions has been discontinued, although existing assessments remain in MyCSF for now.
New r2 assessment objects using v11.0.0 through v11.3.2 will no longer be created after the applicable December 2026 cutoff, and submission of those older r2 assessments will be disabled after March 31, 2027. Organizations using older r2 versions should therefore review their assessment status and planned submission date rather than assuming they can continue indefinitely on their current version.
HITRUST CSF v11.9.0 Deadlines At a Glance
The most important transition dates are:
- September 24, 2026: HITRUST CSF v11.9.0 released.
- December 31, 2026: New e1 and i1 assessments can no longer be created using v11.8.0.
- March 31, 2027: e1 and i1 assessments using v11.8.0 or earlier can no longer be submitted.
Organizations using older r2 versions should also review HITRUST’s decommissioning requirements and transition their assessment strategy accordingly.
Do Existing HITRUST Assessments Need to Be Upgraded to v11.9?
Not necessarily.
The transition requirements depend on the assessment type, CSF version, and whether the assessment has already been created and submitted.
For e1 and i1 assessments, HITRUST has provided a transition period through the end of 2026 for creating assessments under either v11.8.0 or v11.9.0. However, assessments using v11.8.0 or earlier must meet the March 31, 2027 submission deadline or be upgraded to a supported version.
The practical takeaway is simple:
Do not automatically restart an assessment because v11.9.0 was released. First determine your current CSF version, assessment status, scope, evidence readiness, and planned submission date.
Should Organizations Starting a New HITRUST Assessment Use v11.9.0?
For organizations starting a new e1 or i1 assessment after the transition deadline, yes, v11.9.0 will be the required version. Organizations beginning their HITRUST journey now should therefore avoid building a new assessment strategy around an older version simply to delay the transition. Starting with the current framework can also reduce the risk of having to rework controls, evidence, mappings, and documentation later.
What Should Organizations Do Now?
The release creates a practical checklist for security, compliance, and GRC teams.
1. Identify your current HITRUST version
Start by determining:
- Which CSF version your assessment uses
- Whether you are pursuing e1, i1, or r2
- Whether the assessment has been created
- Whether evidence collection has started
- Whether the assessment has been submitted
- Your planned submission date
This determines how the v11.9 transition affects you.
2. Review the v11.9 requirement changes
Do not rely exclusively on your previous control matrix. Review the applicable v11.9 requirements and identify:
- New requirements
- Modified requirements
- Updated authoritative mappings
- AI-related requirements
- Technology-specific changes
- Evidence implications
This is especially important for organizations using e1 or i1.
3. Review your AI environment
If your organization develops or deploys AI, determine whether AI-related systems, applications, services, or infrastructure fall within your HITRUST scope. Then evaluate:
- AI security controls
- Agentic AI use cases
- AI application access
- Data exposure
- Model and application security
- AI-related vulnerabilities
- Monitoring
- Third-party AI dependencies
The addition of the OWASP Top 10 for Agentic Applications 2026 mapping and the Agentic AI factor makes this an increasingly important consideration.
4. Review authentication and cryptography
Because v11.9 includes updates involving PKI, TLS, passkeys, and post-quantum cryptography considerations, organizations should review their current authentication and cryptographic controls.
Ask:
- Where is encryption used?
- Which cryptographic mechanisms protect sensitive data?
- How are certificates managed?
- How are cryptographic assets tracked?
- Where are passkeys being used or considered?
- Are cryptographic risks periodically reassessed?
5. Reassess your evidence strategy
A framework update can expose a common compliance problem: having a control documented does not necessarily mean having the right evidence to demonstrate that the control operates effectively. Before the assessment, verify that evidence is:
- Current
- Complete
- Traceable to the applicable requirement
- Owned by the right team
- Consistent across systems
- Available for the assessment period
This is particularly important when organizations manage HITRUST alongside SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, or other frameworks.
6. Review your assessment timeline
If you are currently using v11.8.0 or an older version, compare your planned submission date against HITRUST’s transition deadlines. Do not wait until the end of the transition period to determine whether your assessment needs to be upgraded. A late version change can create unnecessary rework across:
- Control mapping
- Evidence
- Policies
- Procedures
- Testing
- Remediation
- Assessment documentation
How Can Organizations Prepare For HITRUST CSF v11.9.0?
A practical v11.9 readiness process should include five steps:
Scope → Gap Assessment → Remediation → Evidence Readiness → Validated Assessment
Step 1: Define the assessment scope
Determine which systems, applications, infrastructure, processes, locations, and third parties are included. Scope errors can create problems later, particularly when organizations have complex cloud, SaaS, healthcare, or multi-environment architectures.
Step 2: Perform a v11.9 gap assessment
Assess the environment against the applicable v11.9 requirements. The objective is to identify what has changed and where the organization is not yet ready.
Step 3: Prioritize remediation
Not every gap has the same operational impact. Prioritize issues based on:
- Security risk
- Assessment requirements
- Evidence availability
- Implementation effort
- Dependencies
- Business impact
Step 4: Build assessment-ready evidence
Make sure controls are not only implemented but supported by evidence that can withstand independent review.
Step 5: Work with an Authorized External Assessor
Organizations pursuing a HITRUST validated assessment need the appropriate HITRUST Authorized External Assessor. Accorian provides HITRUST assessment services across e1, i1, and r2, including readiness, remediation support, validated assessment, and ongoing compliance.
How GORICO Can Help with HITRUST v11.9 Readiness
HITRUST version changes can create significant operational work when organizations manage controls, evidence, remediation, and assessment activities across spreadsheets, email, shared folders, and disconnected systems.
GORICO, Accorian’s AI-enabled GRC platform, is designed to centralize compliance workflows and has a direct integration with HITRUST MyCSF.
Organizations can use GORICO to help manage:
- Controls
- Evidence
- Assessments
- Remediation
- Compliance workflows
- Cross-framework requirements
- HITRUST readiness
The direct MyCSF integration helps connect broader compliance activities with the HITRUST assessment workflow and can reduce duplicate effort across the assessment lifecycle. This becomes particularly valuable for organizations managing HITRUST alongside frameworks such as SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, and AI governance requirements.
How Accorian Can Help with HITRUST CSF v11.9.0
A framework update is easier to manage when the organization has both assessment expertise and cybersecurity depth behind the preparation process. Accorian is a HITRUST Authorized External Assessor and supports organizations across HITRUST e1, i1, and r2 assessments. Its services include readiness assessments, gap identification, remediation support, evidence readiness, validated assessments, and ongoing compliance.
Accorian combines:
HITRUST assessment expertise + cybersecurity expertise + GORICO
That combination allows organizations to address not only whether a control meets a HITRUST requirement, but also the underlying security environment supporting that control. For organizations preparing for v11.9.0, Accorian can help with:
- HITRUST scope definition
- 9 readiness and gap assessments
- e1, i1, and r2 assessment preparation
- Control and evidence readiness
- Remediation planning
- Cybersecurity testing
- AI security considerations
- Third-party risk
- Continuous compliance
- HITRUST validated assessments
- GORICO-enabled evidence and compliance management
HITRUST CSF v11.9.0: Frequently Asked Questions
1. What is the latest version of HITRUST CSF?
HITRUST CSF v11.9.0 is the latest version as of September 2026. HITRUST released it on September 24, 2026.
2. What changed in HITRUST CSF v11.9.0?
The release includes updated authoritative source mappings, AI and agentic AI updates, refreshed technology-specific requirements, post-quantum cryptography considerations, and changes to the e1 and i1 assessment baselines.
3. How many requirements are in HITRUST e1 v11.9?
The HITRUST e1 baseline in v11.9 contains 44 requirement statements.
4. How many requirements are in HITRUST i1 v11.9?
The HITRUST i1 baseline remains at 182 requirement statements in v11.9.
5. Does HITRUST v11.9 include AI security requirements?
Yes. v11.9 includes updates to AI Security Certification content, adds an Agentic AI selectable factor, and adds an OWASP Top 10 for Agentic Applications 2026 mapping.
6. When do new e1 and i1 assessments have to use HITRUST v11.9?
After December 31, 2026, new e1, i1, and rapid assessments must be created using v11.9.0 or later.
7. When is the deadline for submitting a HITRUST v11.8 e1 or i1 assessment?
HITRUST has set March 31, 2027 as the deadline for submitting e1 and i1 assessments using v11.8.0 or earlier.
8. Do organizations need to restart their HITRUST assessment because of v11.9?
Not automatically. The impact depends on the assessment type, CSF version, assessment status, and planned submission date. Organizations should review their current assessment against HITRUST’s transition requirements before deciding whether an upgrade is necessary.
9. How should organizations prepare for HITRUST v11.9?
Start by confirming your current CSF version and assessment status, reviewing applicable v11.9 changes, assessing AI and technology-specific requirements, validating evidence readiness, addressing gaps, and confirming your assessment timeline.
The Bottom Line
HITRUST CSF v11.9.0 is not simply another framework version update. It reflects where cybersecurity assurance is heading: AI-enabled environments, agentic applications, evolving authentication technologies, stronger cryptographic considerations, and continuously changing threat conditions.
For organizations, the immediate priority is to understand which v11.9 changes apply to their environment and how the transition deadlines affect their assessment.
If you are starting a new e1 or i1 assessment, plan around v11.9. If you have an existing v11.8 assessment, review its status and submission timeline against the December 31, 2026 and March 31, 2027 deadlines. If you are operating older r2 versions, review HITRUST’s decommissioning schedule as well.
The organizations that handle the transition early can focus on what matters most: building controls that work, maintaining defensible evidence, and staying ready for independent validation.
Prepare for HITRUST CSF v11.9.0 with Accorian
Whether you are starting a new HITRUST assessment, transitioning from an earlier CSF version, or strengthening an existing compliance program, Accorian can help you navigate readiness, remediation, assessment, and continuous compliance.
With HITRUST Authorized External Assessor expertise, cybersecurity capabilities, and GORICO’s direct HITRUST MyCSF integration, Accorian helps organizations move from fragmented preparation to a more connected approach to HITRUST readiness.
Talk to Accorian about your HITRUST CSF v11.9.0 readiness.


