HITRUST AI Security Certification provides third-party validated assurance that an organization’s deployed AI systems have controls in place to mitigate AI-specific cybersecurity threats. The certification is part of the HITRUST AI Assurance Program and is designed primarily for AI application providers and AI platform providers.
Unlike traditional cybersecurity certifications, HITRUST AI Security Certification looks beyond the underlying IT environment to address risks associated with AI models, AI platforms, specialized AI infrastructure, datasets, agents, plugins, and other AI-specific components.
If you’re evaluating HITRUST AI Security Certification in 2026, this guide explains what the certification covers, its requirements, assessment process, cost considerations, timeline, eligibility, and how to prepare.
What Is HITRUST AI Security Certification?
HITRUST AI Security Certification is a security-focused certification for organizations that provide AI systems. It helps demonstrate that an organization’s AI system has been assessed against AI-specific cybersecurity threats and that appropriate controls have been implemented to mitigate those risks. The certification can apply to:
- Generative AI systems
- Predictive AI and machine learning systems
- Rule-based AI systems
- AI applications
- AI platforms
- Supporting AI compute infrastructure
HITRUST evaluates the AI-specific components of the environment alongside the broader IT platform that supports the AI system.
Who can obtain HITRUST AI Security Certification?
HITRUST identifies AI Application Providers and AI Platform Providers as the primary organizations eligible for this certification. An organization that simply uses a third-party AI system does not obtain certification for that external provider’s AI system. Instead, responsibility may be divided across the AI application provider, AI platform provider, model provider, infrastructure provider, and other parties. This makes HITRUST AI Security Certification particularly relevant for organizations that:
- Build AI products
- Provide AI-powered applications to customers
- Operate AI platforms
- Deploy AI systems for external customers
- Need to demonstrate AI security during enterprise procurement
- Serve highly regulated industries
- Need independent validation of AI security controls
What Are the HITRUST AI Security Certification Requirements?
HITRUST AI Security Certification includes up to 44 AI-specific HITRUST CSF requirement statements, depending on how the assessment is tailored. The important part is that these 44 requirements are not assessed by themselves. They are added to an underlying HITRUST e1, i1, or r2 assessment. Therefore, the total number of requirements assessed will be higher than 44. The requirements address areas such as:
AI Security Threat Management
Organizations need to identify the cybersecurity threats relevant to their AI systems and determine how those threats are being mitigated. HITRUST’s AI threat register includes 13 threats, including:
- Prompt injection
- Data poisoning
- Model poisoning
- Model inversion
- Model extraction and theft
- Evasion
- Denial of AI service
- Excessive agency
- Confabulation
- Sensitive information disclosure in outputs
- Harmful code generation
- Compromised third-party models or code
- Compromised third-party training datasets
The focus is not simply on identifying these threats. Organizations must demonstrate that they have appropriate countermeasures and risk treatment processes.
AI Threat Modeling
HITRUST requires organizations to perform threat modeling for their AI systems. The assessment considers whether organizations:
- Evaluate exposure to identified AI security threats
- Identify existing countermeasures
- Identify additional countermeasures where needed
- Update threat modeling when new AI security threats are identified
- Perform threat modeling before deploying new models
- Revisit threat modeling regularly
HITRUST’s current requirement calls for threat modeling at least semi-annually, in addition to triggers such as new threats and deployment of new models.
AI Security Testing and Red Teaming
AI security cannot be validated through documentation alone. HITRUST requires security assessments that consider AI-specific threats. These can include:
- AI red teaming
- Penetration testing
- Security assessments
- Testing for AI-specific attack scenarios
HITRUST’s requirement calls for testing before deployment of new models, before deployment of new or significantly modified supporting infrastructure, and at least annually thereafter.
AI Governance and Oversight
Organizations must establish clear responsibility for AI security. This includes formally defining roles and responsibilities for:
- AI governance
- AI security
- AI risk management
AI-related policies should also address the specific characteristics of the organization’s AI environment. HITRUST specifically calls for AI considerations to be incorporated into relevant policies, including security administration, data governance, software development, risk management, incident management, business continuity, and disaster recovery.
AI Model and Asset Management
AI systems require visibility into the assets that make them work. Depending on the environment, this can include:
- AI models
- AI datasets
- AI-relevant code
- AI configurations
- Agents
- Plugins
- Supporting infrastructure
HITRUST requirements include tracking and versioning AI models and maintaining appropriate documentation around the overall AI system.
AI Supply Chain Security
Third-party AI components create another layer of risk. Organizations may rely on external providers for:
- AI models
- Datasets
- Software packages
- AI platforms
- Computing infrastructure
- Agents and plugins
HITRUST requires organizations to evaluate the security posture of relevant external AI component providers. It also includes requirements around reviewing model cards for externally sourced AI models and communicating AI security requirements to external providers.
Access Controls for AI Systems
AI models and supporting systems must be protected against unauthorized access and modification. HITRUST includes requirements around restricting access to deployed AI models according to least-privilege principles. This helps address threats such as:
- Model extraction
- Model poisoning
- Data poisoning
- Unauthorized model modification
AI Data and Asset Protection
AI systems often process sensitive training, operational, and customer data. Security requirements can extend to:
- AI datasets
- Models
- AI-related code
- AI configurations
- Data moving to and from AI models
- AI artifacts stored at rest
The exact requirements depend on the AI architecture and assessment tailoring.
How Many Requirements Are in HITRUST AI Security Certification?
There are up to 44 AI-specific HITRUST CSF requirements. However, this does not mean an organization completes only 44 requirements to obtain certification. The AI requirements are added to an underlying HITRUST assessment.
For example, HITRUST states that an i1 assessment contains 182 requirement statements before the additional AI security requirements are considered. An AI security assessment can then add up to 44 AI-specific requirements, depending on tailoring.
So, the actual assessment scope depends on:
- The underlying e1, i1, or r2 assessment
- AI system architecture
- AI model type
- Assessment tailoring
- Data and technology in scope
- Third-party AI dependencies
- Applicable AI security requirements
Is HITRUST AI Security Certification a Standalone Certification?
No.
This is one of the most important points to understand before budgeting or planning an assessment. HITRUST AI Security Certification requirements are added to a qualifying HITRUST e1, i1, or r2 assessment. They cannot be assessed independently of the underlying HITRUST assessment. The AI certification therefore extends an organization’s broader HITRUST cybersecurity assurance rather than replacing it.
In practical terms:
HITRUST e1/i1/r2 + AI Security requirements = AI Security Certification path
This approach allows organizations to evaluate both the underlying IT environment and the AI-specific components operating within it.
What Is the HITRUST AI Security Certification Process?
The HITRUST AI Security Certification process can be broken down into six practical stages:
Scope → Tailor → Prepare → Assess → Validate → Certify
Step 1: Define the AI system scope
Start by identifying exactly what AI system will be assessed. This can include:
- AI applications
- AI models
- Training and operational datasets
- AI platforms
- APIs
- Agents
- Plugins
- RAG components
- Supporting infrastructure
- Third-party AI services
A clearly defined scope helps determine which AI security requirements apply.
Step 2: Select the underlying HITRUST assessment
The AI Security Certification is built on an underlying HITRUST assessment. Depending on the organization’s needs, this can involve:
The appropriate assessment depends on the organization’s security requirements, scope, risk profile, and assurance objectives.
Step 3: Complete Assessment Tailoring
Not every organization will have the same AI environment. HITRUST therefore uses tailoring to determine the applicable AI security requirements. For example, certain requirements may depend on whether the organization uses:
- Generative AI
- Predictive machine learning
- Agents
- Plugins
- External models
- External datasets
- Third-party AI platforms
This is why the phrase “44 HITRUST AI requirements” should not be interpreted as a fixed checklist that applies identically to every organization.
Step 4: Perform Readiness and Remediation
Before the formal assessment, organizations should identify gaps between their current AI security program and applicable HITRUST requirements. This is where organizations typically address:
- Missing policies
- Incomplete AI inventories
- Threat modeling gaps
- Insufficient security testing
- Evidence gaps
- Third-party AI risk
- Model governance
- Access control issues
- Logging and monitoring gaps
Step 5: Undergo the External Assessment
HITRUST AI Security Certification involves independent validation. The assessor evaluates the organization’s implementation of the applicable HITRUST requirements and reviews evidence supporting the controls. Organizations should therefore prepare for more than a policy review. Evidence needs to demonstrate that controls are actually operating.
Step 6: HITRUST Review and Certification
After the external assessment and applicable quality review processes are completed, organizations that satisfy certification requirements receive the applicable HITRUST certification.
How Long Does HITRUST AI Security Certification Take?
There is no universal HITRUST AI Security Certification timeline.
The duration depends on the organization’s existing security maturity, assessment scope, AI architecture, evidence readiness, remediation requirements, and assessor availability.
A practical project typically involves:
- Planning and scoping: Define the AI environment, assessment boundary, applicable systems, and underlying HITRUST assessment.
- Readiness assessment: Identify control and evidence gaps.
- Remediation: Implement missing controls and address documentation or operational deficiencies.
- External assessment: Provide evidence and undergo testing with the external assessor.
- HITRUST review and certification: Complete the applicable validation and certification process.
What determines the timeline?
The biggest factors include:
- Whether the organization already has HITRUST certification
- Whether the AI system is already operational
- Number of AI systems in scope
- Complexity of the AI architecture
- Number of third-party AI providers
- Existing AI governance
- Existing threat modeling
- AI red-team readiness
- Evidence maturity
- Remediation requirements
Organizations starting from an established HITRUST program may have a very different preparation timeline from organizations building their security and AI governance program from scratch.
The most useful way to estimate the timeline is therefore to perform a readiness and gap assessment before setting a certification target date.
How Much Does HITRUST AI Security Certification Cost?
There is no single fixed price for HITRUST AI Security Certification. The total cost depends on the organization’s assessment configuration, scope, AI environment, assessor engagement, and preparation requirements. Major cost factors include:
- e1, i1, or r2 assessment
- AI Security Certification scope
- Number of systems in scope
- AI architecture complexity
- Number of environments
- Existing HITRUST certification
- External assessor fees
- Readiness assessment
- Remediation work
- Evidence management
- Security testing and AI red teaming
Does an existing HITRUST Certification reduce cost?
It can reduce the amount of preparation and assessment effort where existing controls and evidence can be leveraged or inherited. However, organizations should not assume that an existing HITRUST certification automatically satisfies the AI-specific requirements. AI introduces additional risks around models, datasets, agents, plugins, prompts, and AI-specific attack techniques that need to be addressed within the applicable scope.
How should you budget for HITRUST AI Security Certification?
Instead of using a generic online cost estimate, organizations should request a scope-specific quote from a HITRUST assessor. The quote should account for:
- Existing HITRUST certification status
- Underlying assessment type
- AI systems in scope
- AI-specific requirements
- Assessment complexity
- Readiness and remediation effort
- External assessment fees
This produces a much more realistic certification budget.
What Does HITRUST AI Security Certification Cover?
HITRUST’s AI Security Certification addresses cybersecurity risks associated with AI systems. The current AI threat register includes 13 threats, including prompt injection, data poisoning, model extraction, model inversion, excessive agency, sensitive information disclosure, and harmful code generation. The certification can therefore address security across multiple layers of an AI environment:
AI model → AI platform → AI compute infrastructure → supporting IT environment
That broader view matters because an AI model cannot be secured independently from the infrastructure, data, applications, identities, APIs, and third-party services around it.
What Evidence Is Needed for HITRUST AI Security Certification?
The exact evidence depends on the tailored requirements, but organizations should expect to demonstrate that AI security controls are both documented and operational. Evidence may include:
AI governance
- AI security policies
- Roles and responsibilities
- AI governance documentation
- AI security training
AI inventory
- AI system inventory
- Model inventory
- Model versions
- Architecture documentation
- AI asset records
Threat management
- AI threat assessments
- Threat models
- Risk assessments
- AI security testing
- Red-team reports
- Penetration-testing reports
Model security
- Model access controls
- Model versioning
- Model change management
- Model documentation
- Model cards
Data security
- Dataset inventories
- Data classification
- Data protection controls
- Training data controls
- RAG data controls where applicable
Third-party AI security
- Vendor due diligence
- AI provider assessments
- Third-party contracts
- Shared responsibility documentation
- Security requirements communicated to AI providers
Monitoring and response
- AI security monitoring
- Logging
- Incident response
- Security event records
- Evidence of recurring assessments
The key is not simply collecting documents. The evidence needs to demonstrate that controls operate as required.
How Often Is HITRUST AI Security Certification Renewed?
The validity period follows the underlying HITRUST CSF assessment:
However, organizations should not treat the certification cycle as the only time they need to evaluate AI security. HITRUST’s requirements include recurring activities.
For example, AI threat modeling is required at least semiannually, while AI security assessments such as red teaming or penetration testing are required at least annually and when significant changes occur. That makes continuous AI security monitoring and evidence management increasingly important.
HITRUST AI Security Certification vs. AI Risk Management Assessment
HITRUST offers more than one approach to AI assurance.
The key distinction is:
HITRUST AI Security Certification focuses on cybersecurity threats affecting AI systems.
HITRUST AI Risk Management Assessment addresses broader AI risks across the AI lifecycle.
The second approach is useful when an organization wants to evaluate AI risk management beyond cybersecurity, including broader governance and risk considerations.
Organizations may therefore use AI Security Certification when they need validated security assurance, while broader AI risk management activities can address risks that fall outside cybersecurity.
HITRUST AI Security Certification vs. ISO 42001
HITRUST AI Security Certification and ISO/IEC 42001 address different dimensions of AI assurance.
HITRUST AI Security Certification
Focuses on:
- AI cybersecurity
- AI-specific threats
- Security controls
- Threat modeling
- AI security testing
- Third-party validation
ISO/IEC 42001
Focuses on:
- AI management systems
- AI governance
- Organizational processes
- Risk management
- Accountability
- Continual improvement
For organizations building a mature AI governance program, the two can complement each other. HITRUST provides a security-focused assurance layer, while ISO 42001 addresses the broader AI management system.
How to Prepare for HITRUST AI Security Certification
If certification is on your roadmap, start with the AI environment rather than the checklist.
- Build an AI inventory: Know what AI exists across your organization. Include Models, Applications, APIs, Agents, Plugins, Datasets, RAG systems, and Third-party AI services.
- Map your AI supply chain: Identify every external component supporting your AI system. HITRUST specifically addresses due diligence for external AI providers, including providers of models, datasets, software, platforms, infrastructure, agents, and plugins.
- Perform AI threat modeling: Map threats to the architecture and document the countermeasures already in place. Do not limit the exercise to traditional vulnerabilities. Consider AI-specific threats such as:
- Prompt injection
- Data poisoning
- Model extraction
- Model inversion
- Excessive agency
- Sensitive information disclosure
- Test the AI system: Conduct AI-specific security testing before certification. Consider:
- AI red teaming
- Prompt injection testing
- Model security testing
- Application penetration testing
- API security testing
- Data security testing
- Centralize evidence: AI security evidence can quickly become fragmented across engineering, security, compliance, data science, and vendor-management teams. A centralized evidence strategy can make it easier to demonstrate control operation and maintain readiness as the AI environment changes.
How Accorian Helps with HITRUST AI Security Certification
HITRUST AI Security Certification requires more than compliance documentation. Organizations need to connect AI security, cybersecurity controls, threat management, testing, governance, and evidence. Accorian has been a HITRUST CSF Assessor since 2019, supporting organizations with HITRUST assessments and cybersecurity assurance. Accorian can help organizations prepare for and address AI security requirements through capabilities including:
- HITRUST AI Security readiness
- HITRUST CSF assessments
- AI security assessments
- AI threat modeling
- AI penetration testing
- AI red teaming
- AI governance
- ISO 42001 readiness
- Multi-framework compliance
For organizations managing multiple frameworks, GORICO, Accorian’s AI-enabled GRC platform, can also support evidence management, control mapping, policy and procedure reviews, posture assessments, and continuous compliance workflows. The platform is designed to help organizations move away from fragmented spreadsheets, screenshots, emails, and manual evidence collection toward a more connected compliance process.
HITRUST AI Security Certification: FAQs
1. What is HITRUST AI Security Certification?
HITRUST AI Security Certification is a validated certification for AI systems that demonstrates the implementation of controls designed to mitigate AI-specific cybersecurity threats. It is part of the HITRUST AI Assurance Program.
2. How many HITRUST AI Security requirements are there?
There are up to 44 AI-specific HITRUST CSF requirements, depending on assessment tailoring. These requirements are added to an underlying e1, i1, or r2 assessment.
3. Is HITRUST AI Security Certification standalone?
No. The AI security requirements must be assessed alongside a HITRUST e1, i1, or r2 assessment.
4. Who can obtain HITRUST AI Security Certification?
AI Application Providers and AI Platform Providers are the primary organizations eligible for the certification. Organizations simply using another company’s AI system do not obtain certification for that external system.
5. How much does HITRUST AI Security Certification cost?
There is no single fixed cost. Pricing depends on the underlying HITRUST assessment, scope, AI architecture, assessment complexity, assessor fees, and remediation requirements.
6. How long does HITRUST AI Security Certification take?
There is no standard timeline. The duration depends on the organization’s existing HITRUST maturity, AI system scope, evidence readiness, remediation requirements, assessment complexity, and assessor availability.
7. How long is HITRUST AI Security Certification valid?
The certification follows the underlying assessment’s validity period: one year for e1 or i1 and two years for r2.
8. What AI threats does HITRUST certification address?
HITRUST’s AI threat register includes 13 threats, including prompt injection, data poisoning, model poisoning, model inversion, model extraction and theft, excessive agency, sensitive information disclosure, and harmful code generation.
9. Does HITRUST AI Security Certification cover responsible AI?
Not entirely. HITRUST AI Security Certification focuses on cybersecurity of AI systems. HITRUST notes that organizations still need to address other responsible AI areas, including privacy, ethics, and transparency.
10. Is HITRUST AI Security Certification the same as ISO 42001?
No. HITRUST AI Security Certification focuses on AI cybersecurity assurance, while ISO 42001 focuses on an AI management system and broader organizational governance.
Final Takeaway
HITRUST AI Security Certification gives AI application and platform providers a structured way to demonstrate that their AI systems are protected against AI-specific cybersecurity threats.
The certification can include up to 44 AI-specific HITRUST CSF requirements, covering areas such as threat modeling, AI security testing, governance, model management, supply chain security, access control, and protection of AI assets.
But the 44 requirements are only one part of the assessment. They are added to an underlying HITRUST e1, i1, or r2 assessment, making scope definition and readiness assessment critical to understanding the actual cost, effort, and timeline.
For organizations building AI products or deploying AI at scale, the most effective starting point is to map the AI environment, identify applicable HITRUST requirements, assess current gaps, and build an evidence strategy before entering the formal assessment.
AI security is evolving quickly. Your certification strategy should be built to evolve with it.


