Advisories

HAA 2026-005 CSF Version 11.9.0 Release

Written by HITRUST | Sep 25, 2026, 2:15:14 PM
Overview

The HITRUST CSF v11.9.0 framework (v11.9.0) is available within MyCSF and downloadable here as of September 24, 2026.  

The changes included in v11.9.0 consist of: 

  • New, refreshed and modified Authoritative Sources
  • Library enhancements
  • Updates to the e1 and i1 assessment baselines

New, Refreshed, and Removed Authoritative Sources 

v11.9.0 includes the following new, refreshed, and modified Authoritative Source mapping changes:

  • Refreshed National Institute of Standards and Technology Special Publication 800-53 Revision 5.2.0 (NIST SP 800-53 Rev. 5.2.0) mapping. This refresh helps maintain alignment between the HITRUST CSF and the current NIST control catalog content.
  • Added Open Worldwide Application Security Project Top 10 for Agentic Applications 2026 (OWASP Top 10 for Agentic Applications 2026) mapping and selectable Compliance factor, "OWASP Top 10 for Agentic Applications 2026". This new mapping supports emerging AI security considerations associated with agentic applications.
  • Made targeted modifications to the HIPAA Privacy Rule and HIPAA Security Rule mappings based on continued entity-type applicability analysis.
  • Added “Agentic AI” selectable factor to the AI Security Certification

The following Authoritative Sources have been removed in v11.9.0: 

  • APEC Cross-Border Privacy Rules (CBPR)
  • Data Governance Framework
  • HITRUST De-ID Framework
  • ISO/IEC 27799:2016
  • ISO/IEC 29100:2011
  • NIST SP 800-53 r4
  • The Joint Commission
CSF Library Enhancements

With the release of v11.9.0, HITRUST is making several updates to the CSF library. These updates are intended to improve clarity and address emerging technologies and risks.

The library enhancements included in v11.9.0 consist of:

  • Updates to AI Security Certification content to support continued refinement of HITRUST’s AI-related assurance offerings.
  • Updates in response to AI-enabled vulnerability research initiatives
  • Refresh of technology-specific requirements, including areas such as public key infrastructure (PKI), Transport Layer Security (TLS), and passkeys.
  • Inclusion of post-quantum cryptography consideration

e1 and i1 Assessment Baseline Impacts

With the release of v11.9, HITRUST is making changes to the e1 and i1 baselines. These adjustments are the result of multiple analysis focused on optimizing the e1 and i1 assessments. More information on why these changes are being made can be found in our v11.9 Baseline Change FAQ.

As a result of these changes, the size of the e1 baseline for v11.9 is 44 requirement statements. The size of the i1 baseline remains 182 requirement statements. In v11.9, it is still true that all requirement statements in the e1 baseline are included in the i1 baseline and all requirement statements in the i1 baseline are included in the r2 baseline.

 

Additional Resources 

See HAA 2026-006 which sets the creation deadline for e1 and i1 assessments using CSF v11.8.0.

For more information, see the HITRUST CSF v11.9.0 Summary of Changes. For additional questions please contact our Support team or a HITRUST Customer Success Manager (CSM).