HITRUST is issuing this request for comment to gather feedback on a proposed set of updates to select certification requirements in response to the rapidly evolving vulnerability identification and exploitation landscape made possible through frontier AI models. As the time between vulnerability disclosure, weaponization, and active exploitation continues to compress, HITRUST may clarify and strengthen certain HITRUST CSF requirements to better reflect current operational realities and risk expectations. These updates are also intended to help organizations address the “Defend” and “Thwart” focus areas reflected in the NIST Cyber AI Profile.

The proposed updates affect five requirements applicable to the e1 assessment type, fifteen requirements applicable to the i1 and r2 assessment types, and seven requirements applicable to only r2 assessment types. These changes span the following domains: Endpoint Protection, Configuration Management, Vulnerability Management, Audit Logging & Monitoring, Third Party Assurance, Incident Management, and Risk Management.