Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HiTRUST » HITRUST Risk-based, 2-year (r2) Validated Assessment

HITRUST Risk-based, 2-year (r2) Validated Assessment

The HITRUST Risk-Based, 2-Year (r2) Validated Assessment is a comprehensive certification program that offers a set of assessments that are customized to offer an in-depth evaluation of an entity’s Information security and Risk management practices. 

The r2 is centered on the assessment of implemented security controls as well as their levels of maturity, which makes this framework appropriate to higher risk areas, which need additional and more profound approaches towards threats protection.

All of the security and privacy controls in the r2 assessment are divided according to numerous regulatory frameworks, including HIPAA, NIST, and ISO; this helps simplify the overall compliance process, as an organization can attain compliance in all these areas at once with a single assessment. 

While HITRUST i1 provides assessment against baseline controls, the assessment for r2 provides the extent to which an organization’s controls are designed specifically for the organization’s risk appetite.

The process of assessment starts with readiness assessment where an organization surveys the security deficiencies it has. An external expert performs the Validated Assessment to assess the strength and the complexity of the organization’s controls. This process involves consideration of control implementation, checking on the operations of the control and an evaluation of the risks by the existing controls.

When the assessment is done, the results are compiled and submitted to HITRUST. After completing the assessment, the organization gets this HITRUST r2 certification for two years. The organization must undertake an Interim Assessment, after one year in order to verify that controls are working as planned and that new risks are properly addressed.

Additional reading

NIST Risk Management Framework: The 7 Steps Explained 

TL,DR: The NIST RMF is a structured 7-step process: Prepare, Categorize systems, Select controls from NIST 800-53, Implement controls, Assess effectiveness, Authorize (leadership accepts residual risk), and Monitor security posture continuously The framework applies to any technology or system including IoT, control systems, and legacy systems across any sector. Risk assessment costs range from $10,000…

9 Common Compliance Issues and How to Overcome Them

According to PwC’s Global Risk Survey 2023, 40% of surveyed business and risk leaders reported improving their organization’s approach to risk in the last year to strengthen compliance with regulatory standards. Among the top-performing 5% of organizations, this figure skyrocketed to 81%. But what’s driving this significant leap? The solution resides in clearly recognizing and…

An Overview of AI Governance Trends Observed in 2026

AI adoption across U.S. organizations has moved faster than almost any previous technology shift. What began as experimentation has become operational dependency, often without the guardrails that security and compliance teams expect.  The AI Pulse Check Report, based on responses from 103 CISOs and security leaders, highlights key AI Governance trends and offers a timely…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.