Service

DirectTrust identity and trust service accreditation is the set of DirectTrust programs for organizations that issue digital certificates, act as registration authorities, issue verified digital identities or run UDAP-trusted apps and servers in health data exchange, assessed in 2026 against tracks such as “Certificate Authority v2.2” and “Registration Authority v1.3”. It is for certificate authorities, registration authorities, identity providers and HISPs. Integral Healthcare Solutions (IHS) drafts the governance and procedure layer of your trust-service accreditation; your PKI and identity specialists own the technical controls.

Last reviewed: October 2026.

What is DirectTrust trust-service accreditation?

DirectTrust’s 2026 criteria release lists these trust-service tracks and versions: “Certificate Authority v2.2”, “Registration Authority v1.3”, “Registration Authority for Federal PKI v1.3”, “Identity Provider v1.1”, “UDAP Identity Provider Criteria v1.2”, “UDAP Server v1.2”, “UDAP Client App v1.2”, “UDAP Client App – Basic v1.2” and “Health Information Services Provider (HISP) v2.2” (source). None carries the asterisk that marks programs containing DirectTrust’s standard Privacy and Security criteria. DirectTrust’s programs “are governed by the organization’s Electronic Healthcare Network Accreditation Commission (EHNAC).” (source)

What DirectTrust says each main track covers:

The criteria documents are released on request, not posted: “Criteria for each of our Accreditation Programs are available for request at the top of the Programs and Criteria page.” (source) This page relies on DirectTrust’s public pages, not the criteria text. A draft 2027 release is open for comment until November 17, 2026 (source).

Who needs it and what triggers it?

The buyer operates identity, certificate or registration services for health data exchange. Triggers named in the sources:

How IHS helps

IHS works the organizational layer of the track you choose. The work runs in this order:

  1. Gap assessment of organizational controls against the criteria your organization obtains from DirectTrust.
  2. Questionnaires on identity proofing, partner obligations, access and incidents.
  3. Document and evidence mapping: each organizational criterion crosswalked to the policy or record that answers it.
  4. Drafting: governance, identity-proofing responsibility, access and incident procedures, and partner-obligation records, for your leaders to review and approve.
  5. Mock review of the organizational evidence.
  6. Readiness support: drafted responses to assessor findings, for your organization to submit.

What your organization supplies: the criteria, your certificate policy and certification practice documents, audit reports, and your PKI and identity specialists.

The limit: PKI technical controls, assurance levels, UDAP and HL7 conformance testing, and technical validation are specialist work. IHS covers the organizational side only. Your organization submits its own application and self-assessment.

How the DirectTrust process runs

DirectTrust does not publish a typical timeline on the pages IHS reviewed, and Identity Provider Beta terms are not published there either.

What to have ready

Each item ties to DirectTrust’s published process or its public description of the 2026 track. The criteria text for your track governs; check each item against your copy.

  1. The criteria for your track and version, for example Certificate Authority v2.2 or Registration Authority v1.3, requested from DirectTrust (2026 versions).
  2. For CA accreditation, proof of a valid DirectTrust Privacy and Security accreditation, HITRUST certification or WebTrust certification (CA program).
  3. A signed Accreditation Program Agreement and a Financial Attestation of revenue (accreditation process).
  4. Your policy and structure documents (the CA program names “policies and structures”); for a CA this is typically the certificate policy and certification practice statement, which IHS expects the criteria text to call for.
  5. Written identification and authentication processes, which both the CA and RA programs name (CA); (RA).
  6. Certificate or credential life-cycle procedures (RA program).
  7. Facility and operations control records (RA program).
  8. For the Identity Provider track, documentation of the assurance levels you meet, such as NIST SP 800-63 IAL2/IAL3 and AAL2/AAL3 (Identity Provider program).
  9. For UDAP tracks, evidence of conformance with HL7’s Interoperable Digital Identity and Patient Matching Capabilities, which DirectTrust says UDAP programs require (UDAP programs).
  10. Evidence that documented practices are carried out; IHS’s expectation for the location review, which DirectTrust’s process page describes only as ‘Location reviews are completed’.

To walk through this list against your own operation, start with the introductory call.

How it compares

For a certificate authority, the comparison that matters first is the HIPAA compliance proof DirectTrust accepts. DirectTrust names three: “a valid DirectTrust Privacy and Security accreditation, HITRUST certification or WebTrust certification.” (source)

Related DirectTrust pages: DirectTrust HIE accreditation consulting; DirectTrust Outsourced Services accreditation consulting; DirectTrust MSO accreditation consulting. All IHS accreditation services are listed on the Accreditation Consulting page.

What does DirectTrust trust-service accreditation cost?

The cost has two parts: DirectTrust’s fees, set by program, location and revenue level, and the cost of preparing. DirectTrust says: “Accreditation fees are based on program(s), location(s), and revenue-level. Accredited organizations incur an Annual Fee. Every other year when an organization pursues accreditation (their On-Cycle year), they additionally incur Assessment, Location, and (if applicable) Multi-Program Discounted and Program-Specific Fees, as appropriate. On Off-Cycle years, organizations pay only the Annual Fee.” (source)

Three of the six revenue tiers on DirectTrust’s apply page (fetched October 2, 2026):

Tier (as published)Annual FeeAssessment FeeAdditional Location FeePractices Statement Assessment FeeAdd-on Assessment Fee
1 – Very Small – Under $3M$3,100$5,500$3,500$4,000$1,000
Small (includes federal, state and non-profit organizations)$4,300$6,000$4,000$4,500$1,500
6 – Very Large – Greater than $75M$27,500$15,000$6,000$8,000$3,500

Verify current fees with DirectTrust before budgeting. IHS scopes each engagement after a free introductory call.

What this is not

Frequently asked questions

What does DirectTrust Certificate Authority accreditation require?

DirectTrust says its Certificate Authority Accreditation Program focuses on policies and structures, identification and authentication processes, certificate life-cycle management, and technical security controls. The 2026 version is Certificate Authority v2.2. Applicants must also show HIPAA compliance proof.

Do we need HITRUST or WebTrust before applying for DirectTrust CA accreditation?

DirectTrust says CA applicants must provide proof of one of three: a valid DirectTrust Privacy and Security accreditation, HITRUST certification or WebTrust certification.

What is the difference between DirectTrust Certificate Authority and Registration Authority accreditation?

The CA program covers entities that issue digital certificates. The RA program covers entities in the registration authority role and adds facility and operations control to the areas it reviews. Both cover identification and authentication processes, life-cycle management and technical security.

What is the DirectTrust Identity Provider program and is it still in Beta?

It targets organizations that issue digital credentials linked to verified real-world identities at high assurance levels. As of DirectTrust's program page read on October 2, 2026, the program is in its Beta phase and is identifying organizations to participate. The 2026 criteria version is Identity Provider v1.1.

What NIST 800-63 assurance levels does the DirectTrust Identity Provider program expect?

DirectTrust gives NIST SP 800-63 IAL2 or IAL3 for identity proofing and AAL2 or AAL3 for authenticators as examples of the high assurance levels it targets. The criteria text sets the requirement.

What is UDAP accreditation and which UDAP track fits an identity provider versus a FHIR server?

The UDAP suite augments other DirectTrust programs and verifies that an application, identity service or server (API) can execute the technical components to be trusted. The 2026 tracks include UDAP Identity Provider Criteria v1.2, UDAP Server v1.2, UDAP Client App v1.2 and UDAP Client App - Basic v1.2. UDAP programs require conformance with HL7's Interoperable Digital Identity and Patient Matching Capabilities.

How long does DirectTrust accreditation take and how often must it be renewed?

DirectTrust does not publish a typical timeline on the pages IHS reviewed. The accreditation cycle is 2 years, and renewing organizations submit a complete self-assessment 4 months before expiration.

How much does DirectTrust CA or RA accreditation cost?

DirectTrust publishes revenue-tiered fees, for example a $3,100 Annual Fee and $5,500 Assessment Fee for organizations under $3M in revenue. A Practices Statement Assessment Fee column ($4,000 in that tier) appears, but the page does not say which programs incur it. Verify current fees with DirectTrust; IHS scopes its own engagement after a free introductory call.

What organizational policies do assessors look for in a trust-service accreditation?

DirectTrust's program pages name policies and structures, identification and authentication processes, life-cycle management and, for registration authorities, facility and operations control. The criteria text for your track sets the detail. IHS drafts the governance, identity-proofing, access, incident and partner-obligation documents that answer those areas.

Does DirectTrust accreditation let our anchor certificates into the DirectTrust Network?

DirectTrust says accreditation means an organization's anchor certificates may be included in the DirectTrust Network for use by relying parties in Direct exchange. The decision on accreditation is the Commission's.

Talk with IHS's CEO

A 30-minute introductory meeting with Thomas G. Goddard, JD, PhD, to scope what your organization needs.

Schedule a Free Discovery Session