Anybody who has gone through the process of achieving HITRUST Certification before will confirm that the last step in the process is rather manual. After you have done the assessment and gotten your report, you will be spending weeks writing emails to your customers, auditors, and business associates requesting copies of the document. There is no way to know who has the document, whether it is current or whether it was even supposed to be sent to them. HITRUST Report Center is designed to address this issue.
The article sets out precisely what is changing, the reasons why HITRUST developed it, who the changes affect and in what way, and also provides a practical checklist for make you understand what this whole change is all about.
What Report Center actually is
Report Center is a new secure platform that has been incorporated into the HITRUST MyCSF portal for sharing assessment status and reports. Rather than assessed organisations sending the report files directly by email to those who request them, each HITRUST assessment will have its own Report Center dashboard, which will act as a single, central location where authorised recipients can see the assessment status and ask for access to the reports they need.
If you’re new to HITRUST: MyCSF is the SaaS platform that organisations use to carry out their HITRUST assessment from beginning to end – covering scoping, evidence collection, scoring, and now the distribution of reports. It acts as the official record-keeping system for the whole assessment process and is used by the organisations being assessed, their external assessors, and HITRUST’s own quality assurance reviewers. Report Center is the latest module to be added to that platform, and it will go live on September 10, 2026.
Why HITRUST built this
The problem Report Center solves is one every assessed entity has quietly lived with: report sharing has historically been a manual, email-based process. That created a handful of recurring headaches. There was no reliable way to know how many copies of a report existed or who had them. There was no way to revoke access once a report had already been sent; a partnership ends, or a point of contact moves on, but their old email still has your full certification report sitting in it indefinitely. And there was no built-in way for a recipient to confirm that the PDF they received was genuine, current, and unaltered, rather than a forwarded copy of uncertain vintage. Report Center is HITRUST’s answer to all three problems at once: centralized control, revocable access, and verifiable authenticity.
What’s actually changing
The old way: HITRUST report sharing relied onassessed entities exported a report file and emailed it to whoever needed it; a customer’s vendor risk team, a cyber insurer, an auditor, a prospective partner. There was no built-in way to know who had a copy, whether they still needed it, or whether an old copy was floating around after access should have been revoked.
The new way: assessed entities manage report access centrally inside MyCSF, through a new Report Center Access Administration page. From there, an organization’s MyCSF admin users can:
- Ask recipients to visit their report dashboard at the Reporting Center.
- Grant or deny access to customers or partners or others.
- Select exactly which types of reports your recipient is able to view: the complete Certification (or Validation) Report, the shortened Certification (or Validation) Summary, or specific Insights Reports.
- Change or delete access at any time, regardless of the number of copies that have been distributed by email.
The two report types Report Center manages
It is important to be clear on the report types, as Report Center considers them separate from one another, meaning that it is not necessary to provide all recipients with the same amount of detail.
- Certification (or Validation) Report: This is the complete report for those who actually need it: scope of the assessment, results, and underlying detail. Consider an internal vendor risk team performing a detailed review, or a regulator performing a compliance review.
- Certification (or Validation) Summary: This is a short report for those who only require confirmation of the results, without the underlying detail. Consider a procurement team performing a trust review prior to signing a contract.
- Insights Reports (where applicable): These translate HITRUST results into other frameworks; HIPAA, HICP, NIST SP 800-171, GovRAMP; and can be authorized to specific recipients separately from the main report.
Who this affects, and how
Assessed entities
If your organization has or is trying to get a HITRUST certification, you have greater control than ever before. You control who has access to what reports, and for how long. Reports downloaded contain information about who downloaded them, including the name of the organization, the e-mail of the downloader, and the date that it was downloaded. So, if a report is found in a place it should not be, you know exactly who downloaded it. The removal of access prevents any future downloads but does not affect past copies. Reports downloaded through Report Center are intended strictly for the internal business use of the authorized recipient’s organization; they aren’t meant to be republished, redistributed, or disclosed further.
Report recipients
If you’re on the receiving end; if you’re a vendor risk analyst, a cyber-insurance underwriter, a customer doing their due diligence; you have one reliable place from which you can find out about the status of the assessments, request and receive exactly the right reports. Plus, you get extra assurance that the document you are working with is an official HITRUST report, not just a PDF circulated via email three times already.
External assessors
The assessors themselves are not responsible for managing the access to the Report Center; this is left to be taken care of by the admin users of the assessed entity’s MyCSF. Nonetheless, the assessors must expect questions from their clients regarding the new process, especially in relation to the transition period and prior reports.
Public vs. private dashboards
The report center dashboard, by default, is private because an individual who has been provided with the link or QR code needs to be authorized for viewing the dashboard first. The assessed entities can decide to make the dashboard public; in such a scenario, anyone who has the link is able to view the status of the assessment without prior authorization. However, making the dashboard public does not automatically authorize the download of the reports.
Dashboard access is typically reached through a link or QR code embedded in the HITRUST Completion Letter or shared directly by the assessed entity; for example, on a trust center page or in a sales deck.
The timeline, in plain terms
| Key dates to plan around Draft reports issued on or before September 10, 2026; no change. You can keep using the existing email-based process, though a Report Center dashboard will also be available if you want to start using it early. Draft reports issued after September 10, 2026; mandatory. All report sharing for these assessments must go through Report Center. There’s no opt-out. |
The trigger point is not the date of your certification or the date your assessment was submitted; it is the date the draft report is issued. If your assessment will come close to September 10th to the draft-report phase, it might make sense to check with your assessor or HITRUST as to which side of the line you fall on.
What to do before the switchover

- Identify your MyCSF admin users now. They’re the ones who will manage Report Center access, so make sure the right people in your organization (compliance, security, or vendor management leads) actually have MyCSF admin rights and aren’t locked out because the account is tied to someone who has since left.
- Build your recipient list ahead of time. Think through who currently receives your HITRUST report; customers, cyber insurers, auditors, investors; so, you’re ready to invite them to your dashboard rather than scrambling after the fact.
- Make a choice between public or private visibility. When using your HITRUST certification as a selling point or trust center, a public dashboard will be less friction for the prospect who needs to evaluate your posture before closing the deal because he or she doesn’t have to get approved first to view it.
- Update your sales and trust-center materials. If your website or trust center currently links to a static report file, plan to swap that for a Report Center dashboard link once your next report is issued under the new process.
- Brief your customer-facing teams. Sales, customer success, and vendor management staff who currently field “can you send us your HITRUST report” requests should know the process is changing, so they can set expectations with counterparts.
Why this matters beyond the mechanics
On the surface, Report Center is a workflow change. Underneath it, it’s part of a broader shift in how third-party assurance is expected to work: less “trust me, here’s a PDF,” more centrally managed, traceable, and revocable access to verified information. That mirrors a trend playing out across the assurance industry more broadly, from SOC 2 report repositories to trust-center platforms; buyers increasingly want a live, authoritative source of truth rather than a static document of unknown age.
For organizations which are already considering their HITRUST certification as an advantage while selling and doing evaluations of vendors, the Report Center will help them tell their story well; one URL instead of a report attached to an email of unknown provenance. For report recipients, this translates into not having to wonder if a report is current or not.
Frequently asked questions
No. Assessments with draft reports issued on or before that date can continue using the existing email-based process. A Report Center dashboard will still be available for those assessments if you want to start using it voluntarily.
Can I still email a report directly if a recipient prefers that?
For assessments with draft reports issued after September 10, 2026, no; all report sharing must go through Report Center. For assessments issued before that date, the existing process remains available.
What happens if I revoke someone’s access after they’ve already downloaded a report?
Revocation prevents future access and downloading through Report Center, but it does not delete or recall the copies that have been previously downloaded.
Is there a cost to using Report Center?
Report Center is one of the modules included in the MyCSF platform which is offered by HITRUST to their assessed organizations. Report Center is not sold as a separate module. Please verify details through your HITRUST representative if you have any concerns regarding your organization’s contract.
Does a public dashboard let anyone download my report?
No. Making the dashboard public just means that anyone who gets the URL can access the assessment progress on the dashboard. However, downloading any report requires special permission from the assessment subject.


