r2 · Risk-Based, 2-Year

Enterprise Security Accelerator for HITRUST (r2)

$2,499.99

The most comprehensive governance package, built for organizations pursuing the HITRUST r2 Risk-Based, 2-Year assessment.

Buy Now — Secure Checkout

Who it's for

Established healthcare organizations and enterprise vendors whose partners require the most rigorous HITRUST tier — often a condition of large BAAs, health-plan contracts, or enterprise procurement.

What it does

The r2 Enterprise Security Accelerator covers all 19 HITRUST CSF domains and 172 controls, written in formal r2 "shall" voice — the seven governance domains, 11 technical domains, and Domain 16 (Business Continuity) — plus a five-part Enterprise Artifacts suite covering enterprise risk, privacy program, executive governance, assessment management, and internal audit program, for organizations that need to demonstrate board-level oversight of a full-scope program.

Deliverables (103 files)

  • START_HERE Guide (PDF)
  • Implementation Guide (PDF)
  • 19 domain policies (Domains 01–19) + supporting procedures, standards & checklists (.docx)
  • Control documentation tagged with [BUID Reference] markers — 172 controls
  • Readiness Assessment Workbook
  • Gap Assessment Tool
  • Evidence Tracker
  • Internal Audit Workbook
  • Executive Dashboard & Governance Readiness Scorecard
  • Enterprise Risk: Enterprise Risk Register, Risk Acceptance Register, Risk Treatment Plan, Third-Party Risk Register
  • Privacy Program: Data Inventory Workbook, Data Retention Schedule, Privacy Impact Assessment, Privacy Incident Tracker
  • Executive Governance: Board Reporting Package, KPI Dashboard, Management Review Workbook, Risk Committee Package, Security Metrics Program
  • Assessment Management: Assessment Readiness Workbook, Assessor Request Tracker, Control Testing Workbook, Evidence Collection Matrix, Remediation Tracker
  • Internal Audit Program: Audit Charter, Audit Plan, Audit Procedures, Audit Reporting Templates
  • RACI Matrix
  • Framework Crosswalk (HITRUST ↔ HIPAA ↔ NIST ↔ ISO 27001)
  • License Agreement (PDF)

Frequently Asked Questions

Why would we choose r2 over i1?

r2 is risk-based rather than a fixed control set — it tailors requirements to your organization's specific risk factors and covers a two-year certification cycle. Many enterprise healthcare partners and health plans require r2 specifically.

What's different about the toolkit at this tier?

r2 is the only tier covering all 19 domains and 172 controls, and it's the only tier with the Enterprise Artifacts suite — five additional workbook and document sets for enterprise risk, privacy program management, executive/board governance, assessment management, and an internal audit program — on top of the same readiness, gap, evidence, audit, and dashboard tools included at every tier.

Does this replace an external assessor?

No — a HITRUST-authorized external assessor is still required for certification. This toolkit dramatically reduces the prep work before that engagement.

What's covered by the license?

Each purchase includes a signed License Agreement (PDF) granting your organization a non-exclusive, non-transferable license to use, customize, and distribute the toolkit across your enterprise, including subsidiaries and affiliated business units, and to share relevant materials with your Board of Directors or Risk Committee. See the full License Agreement for details.

Ready to accelerate your r2 readiness?

$2,499.99

Checkout is handled securely through Lemon Squeezy — instant digital download after purchase.

Buy Now — Secure Checkout

Questions first? Contact us or try the free resources.