Certification Threshold
In the HITRUST context, a certification threshold is the minimum score an organization must generally achieve on its assessed controls to earn a HITRUST certification. It sets the bar that separates an assessment that passes from one that does not. The specific numeric thresholds vary by assessment type and by the HITRUST CSF version, so readers should confirm current values against HITRUST's official documentation.
A certification threshold in the HITRUST CSF program refers to the minimum control maturity or scoring level an organization must meet, generally at the domain or control level, to qualify for a given HITRUST certification (such as the i1 or r2 assessments). Scoring is typically evaluated across maturity levels, and an organization must reach or exceed the applicable threshold for the relevant scope to be certified. It is important to note that the evidence packet provided does not contain reliable HITRUST source material defining the current numeric thresholds; any specific values (for example, per-domain minimum scores by assessment type) must be verified against the current HITRUST CSF version and HITRUST's official assessment and certification methodology, as these figures are adjusted over time. This term has no equivalent regulatory meaning under HIPAA. HITRUST is a private organization and HITRUST certification is not itself a legal requirement; meeting a HITRUST certification threshold does not by itself establish HIPAA compliance, which is enforced by HHS OCR under the HIPAA Privacy, Security, Breach Notification, and Enforcement Rules.
Why it matters
The certification threshold is the decisive line between a HITRUST assessment that results in certification and one that does not. For organizations that invest significant time and resources into a HITRUST engagement, understanding where that line sits, and how it is applied across control domains, is essential to planning, budgeting, and setting internal expectations. Falling short of the applicable threshold in even a single scored domain can prevent certification, so teams need a clear picture of the bar they are working toward before committing to a formal assessment.
The threshold also matters because it shapes how organizations prioritize remediation. Because HITRUST scoring is generally evaluated across maturity levels and at the domain or control level, the threshold effectively tells an organization how mature its controls must be to pass. This drives decisions about where to focus improvement efforts, what evidence to prepare, and how to sequence work ahead of an assessment. The specific numeric values differ by assessment type and by HITRUST CSF version and are adjusted over time, so readers should confirm current thresholds against HITRUST's official assessment and certification methodology rather than relying on figures that may be outdated.
Who it's relevant to
Inside Certification Threshold
Common questions
Answers to the questions practitioners most commonly ask about Certification Threshold.