If you're managing a HITRUST certification, version 11.8.0 introduced changes you need to account for in your next assessment cycle. This checklist guides you through the decision points, control updates, and evidence requirements that determine whether and how you adopt the new version.
What This Checklist Covers
This checklist applies to organizations planning or maintaining HITRUST CSF certifications across r2, e1, and i1 assessment types. It addresses the version decision, updated baseline statements in Domain 3 and Domain 14, and the authoritative source changes that affect control mapping. Use it during assessment planning, not during active fieldwork.
Prerequisites
Before working through this checklist, confirm:
- Your current HITRUST CSF version and assessment type (r2, e1, or i1)
- Whether you've created a MyCSF object for your next assessment
- Your assessment timeline relative to May 7, 2026
- Which third parties have access to scoped systems or information
- Your portable media handling procedures (both digital and physical)
Checklist Items
1. Determine Your Version Requirement
Action: Identify which CSF version you're required to use based on assessment type and timeline.
- If you're planning an r2 assessment: You can use any CSF version 11.x
- If you're planning an e1 or i1 assessment AND created your MyCSF object before May 7, 2026: You can continue with version 11.7.0
- If you're planning an e1 or i1 assessment AND have not created your MyCSF object: You must use version 11.8.0
What good looks like: You've documented your version decision with a clear rationale tied to HITRUST rules, and your assessment timeline reflects the version you'll be using. Your internal control documentation references the correct CSF version number.
2. Review Domain 3 Portable Media Security Changes
Action: Update your portable media controls to reflect the restructured baseline statement.
- Separate your control documentation into digital portable media requirements and non-digital (paper) requirements
- Confirm encryption is applied to all transported digital portable media
- Establish accountability mechanisms for digital portable media (tracking, logging, or chain-of-custody records)
- Establish accountability mechanisms for non-digital media (sign-out logs, transport receipts, or disposal certificates)
- Update your portable media security policy to reflect the digital/non-digital distinction
What good looks like: Your policy explicitly states encryption requirements for digital media and accountability requirements for both types. Your evidence repository contains separate folders or tags for digital media encryption proofs and physical media tracking records. An auditor can immediately identify which controls apply to which media type.
3. Assess Domain 14 Third Party Assurance Obligations
Action: Align your third-party verification process with the updated baseline statement requiring annual independent verification of contract compliance.
- Inventory all third parties with access to scoped systems or information
- Review contracts with those third parties to identify specific information security provisions
- Establish an independent verification process (internal audit, external assessment, or questionnaire validation)
- Schedule annual verification activities for each third party
- Document how you verify compliance with contractual provisions, not just general security posture
What good looks like: You maintain a third-party register that lists each vendor, their contract security provisions, the verification method, the verification date, and the outcome. Your verification evidence directly ties back to contract language. If a third party doesn't have a SOC 2 or ISO/IEC 27001 certificate, you have an alternative verification method that independently confirms contract compliance.
4. Map Updated Authoritative Sources to Your Control Environment
Action: Review how the new and updated authoritative sources affect your existing control mappings.
- Identify which of your controls map to NIST SP 800-137, ISO/IEC 29100:2024, or OWASP LLM v2025
- Review updated mappings for Texas Medical Records Privacy Act, PCI DSS v4.0.1, and AICPA SOC 2 Trust Services Criteria
- Determine if these updates reduce duplication across your other compliance obligations
- Update your control matrix to reflect the new authoritative source references
What good looks like: Your control matrix shows which HITRUST controls satisfy requirements in other frameworks you maintain. You can demonstrate to leadership how a single control implementation addresses HITRUST, PCI DSS, and SOC 2 simultaneously, reducing evidence collection burden.
5. Plan Evidence Collection for Modified Controls
Action: Adjust your evidence collection procedures to match the new control language.
- For Domain 3: Collect encryption configuration screenshots, key management documentation, and media transport logs
- For Domain 14: Collect third-party verification reports, contract excerpts, and verification schedules
- Update evidence request templates to reflect the new control elements
- Brief your evidence collection team on what changed and why
What good looks like: Your evidence collection calendar includes specific deadlines for third-party verification reports. Your portable media evidence folder contains clear labels distinguishing digital encryption proofs from physical media accountability records. When an auditor requests Domain 3 or Domain 14 evidence, your team knows exactly which files to provide.
Common Mistakes
Treating "independent verification" as optional for third parties without audit reports. The Domain 14 update explicitly added independent verifications alongside independent assessments. If a vendor doesn't have a SOC 2 or ISO/IEC 27001 certificate, you still need to independently verify their contract compliance annually. A vendor self-attestation questionnaire isn't independent verification unless someone outside the vendor's control validates the responses.
Applying encryption requirements to all portable media. The Domain 3 restructure clarifies that encryption applies to digital portable media only. Physical documents require accountability, not encryption. Applying encryption requirements to paper creates an impossible control.
Upgrading to 11.8.0 for an r2 assessment when your team has already built evidence against 11.7.0. You have version flexibility in r2 assessments. If switching versions mid-cycle means re-mapping controls and re-collecting evidence, you're introducing risk without a compliance benefit.
Assuming authoritative source updates automatically change your control requirements. Updated mappings to PCI DSS v4.0.1 or SOC 2 don't change what HITRUST requires from you. They change how HITRUST demonstrates alignment with those frameworks, which matters for de-duplication strategy but doesn't alter your control implementation.
Next Steps
After completing this checklist, schedule a planning session with your assessment team to confirm version selection, evidence timelines, and any control design changes. If you're adopting 11.8.0, update your ISMS documentation to reference the new version and communicate the Domain 3 and Domain 14 changes to control owners. If you're maintaining 11.7.0 for this cycle, document when you'll evaluate 11.8.0 for future assessments.
For r2 assessments, consider whether the authoritative source updates create opportunities to consolidate other compliance activities. The updated mappings don't eliminate separate audits, but they can reduce the evidence burden if you structure your control environment to serve multiple frameworks simultaneously.



