DirectTrust identity and trust service accreditation is the set of DirectTrust programs for organizations that issue digital certificates, act as registration authorities, issue verified digital identities or run UDAP-trusted apps and servers in health data exchange, assessed in 2026 against tracks such as “Certificate Authority v2.2” and “Registration Authority v1.3”. It is for certificate authorities, registration authorities, identity providers and HISPs. Integral Healthcare Solutions (IHS) drafts the governance and procedure layer of your trust-service accreditation; your PKI and identity specialists own the technical controls.
Last reviewed: October 2026.
What is DirectTrust trust-service accreditation?
DirectTrust’s 2026 criteria release lists these trust-service tracks and versions: “Certificate Authority v2.2”, “Registration Authority v1.3”, “Registration Authority for Federal PKI v1.3”, “Identity Provider v1.1”, “UDAP Identity Provider Criteria v1.2”, “UDAP Server v1.2”, “UDAP Client App v1.2”, “UDAP Client App – Basic v1.2” and “Health Information Services Provider (HISP) v2.2” (source). None carries the asterisk that marks programs containing DirectTrust’s standard Privacy and Security criteria. DirectTrust’s programs “are governed by the organization’s Electronic Healthcare Network Accreditation Commission (EHNAC).” (source)
What DirectTrust says each main track covers:
- Certificate Authority (CAAP): “a comprehensive framework for entities involved in digital certificate issuance within the healthcare industry,” focused on “policies and structures, identification and authentication processes, certificate life-cycle management, and technical security controls.” (source)
- Registration Authority (RAAP): standards for “entities involved in the registration authority role within digital healthcare solutions,” covering “policy and structure, identification and authentication processes, certificate/credential life-cycle management, facility and operations control, and technical security.” (source)
- Identity Provider: a program that “targets organizations that issue digital credentials linked to verified real-world identities and adhere to high assurance levels (e.g. NIST SP 800-63 IAL2/IAL3 for identity proofing and AAL2/AAL3 for authenticators).” DirectTrust adds: “The Identity Provider Program is in its Beta phase.” (source)
- UDAP suite: programs “specifically developed to augment other DirectTrust accreditation programs (such as Health App) and verify that an application, identity service, or server (API) can execute the technical components to be trusted.” (source)
The criteria documents are released on request, not posted: “Criteria for each of our Accreditation Programs are available for request at the top of the Programs and Criteria page.” (source) This page relies on DirectTrust’s public pages, not the criteria text. A draft 2027 release is open for comment until November 17, 2026 (source).
Who needs it and what triggers it?
The buyer operates identity, certificate or registration services for health data exchange. Triggers named in the sources:
- Use of your certificates in Direct exchange. DirectTrust says accreditation “also means that its anchor certificates may be included in the DirectTrust Network, and for use by relying parties in Direct exchange.” (source)
- A CA application, which requires proof of HIPAA compliance: “providing proof of a valid DirectTrust Privacy and Security accreditation, HITRUST certification or WebTrust certification.” (source)
- Joining the Identity Provider Beta, which “is actively identifying organizations and identity and credential service providers to participate.” (source)
- Reaccreditation. “The accreditation cycle is for 2 years,” and the complete self-assessment is due “4 months prior to the expiration date.” (source)
How IHS helps
IHS works the organizational layer of the track you choose. The work runs in this order:
- Gap assessment of organizational controls against the criteria your organization obtains from DirectTrust.
- Questionnaires on identity proofing, partner obligations, access and incidents.
- Document and evidence mapping: each organizational criterion crosswalked to the policy or record that answers it.
- Drafting: governance, identity-proofing responsibility, access and incident procedures, and partner-obligation records, for your leaders to review and approve.
- Mock review of the organizational evidence.
- Readiness support: drafted responses to assessor findings, for your organization to submit.
What your organization supplies: the criteria, your certificate policy and certification practice documents, audit reports, and your PKI and identity specialists.
The limit: PKI technical controls, assurance levels, UDAP and HL7 conformance testing, and technical validation are specialist work. IHS covers the organizational side only. Your organization submits its own application and self-assessment.
How the DirectTrust process runs
- Application: “An Accreditation Program Agreement must be signed by the applicant and submitted. A Financial Attestation to verify your organization’s revenue must also be submitted.” (source)
- Location review and report: “Location reviews are completed, and the Assessor completes the draft Accreditation Report.” (source)
- Decision: “The Commission reviews and votes on the Accreditation Report.” (source)
DirectTrust does not publish a typical timeline on the pages IHS reviewed, and Identity Provider Beta terms are not published there either.
What to have ready
Each item ties to DirectTrust’s published process or its public description of the 2026 track. The criteria text for your track governs; check each item against your copy.
- The criteria for your track and version, for example Certificate Authority v2.2 or Registration Authority v1.3, requested from DirectTrust (2026 versions).
- For CA accreditation, proof of a valid DirectTrust Privacy and Security accreditation, HITRUST certification or WebTrust certification (CA program).
- A signed Accreditation Program Agreement and a Financial Attestation of revenue (accreditation process).
- Your policy and structure documents (the CA program names “policies and structures”); for a CA this is typically the certificate policy and certification practice statement, which IHS expects the criteria text to call for.
- Written identification and authentication processes, which both the CA and RA programs name (CA); (RA).
- Certificate or credential life-cycle procedures (RA program).
- Facility and operations control records (RA program).
- For the Identity Provider track, documentation of the assurance levels you meet, such as NIST SP 800-63 IAL2/IAL3 and AAL2/AAL3 (Identity Provider program).
- For UDAP tracks, evidence of conformance with HL7’s Interoperable Digital Identity and Patient Matching Capabilities, which DirectTrust says UDAP programs require (UDAP programs).
- Evidence that documented practices are carried out; IHS’s expectation for the location review, which DirectTrust’s process page describes only as ‘Location reviews are completed’.
To walk through this list against your own operation, start with the introductory call.
How it compares
For a certificate authority, the comparison that matters first is the HIPAA compliance proof DirectTrust accepts. DirectTrust names three: “a valid DirectTrust Privacy and Security accreditation, HITRUST certification or WebTrust certification.” (source)
- DirectTrust Privacy and Security accreditation (v3.1): DirectTrust’s own route to that proof.
- HITRUST certification: accepted by DirectTrust for CA accreditation, per the quote above. See IHS’s HITRUST page.
- WebTrust certification: accepted by DirectTrust for CA accreditation, per the quote above.
- Registration Authority for Federal PKI v1.3: listed in DirectTrust’s 2026 criteria release as a separate track from Registration Authority v1.3. The pages IHS reviewed do not describe its scope or its federal PKI cross-certification requirements.
- DirectTrust’s own advisory help. DirectTrust program pages say: “Learn about our Consulting and Advisory Services which have been designed to provide additional guidance in completing these programs.” (source)
Related DirectTrust pages: DirectTrust HIE accreditation consulting; DirectTrust Outsourced Services accreditation consulting; DirectTrust MSO accreditation consulting. All IHS accreditation services are listed on the Accreditation Consulting page.
What does DirectTrust trust-service accreditation cost?
The cost has two parts: DirectTrust’s fees, set by program, location and revenue level, and the cost of preparing. DirectTrust says: “Accreditation fees are based on program(s), location(s), and revenue-level. Accredited organizations incur an Annual Fee. Every other year when an organization pursues accreditation (their On-Cycle year), they additionally incur Assessment, Location, and (if applicable) Multi-Program Discounted and Program-Specific Fees, as appropriate. On Off-Cycle years, organizations pay only the Annual Fee.” (source)
Three of the six revenue tiers on DirectTrust’s apply page (fetched October 2, 2026):
| Tier (as published) | Annual Fee | Assessment Fee | Additional Location Fee | Practices Statement Assessment Fee | Add-on Assessment Fee |
|---|---|---|---|---|---|
| 1 – Very Small – Under $3M | $3,100 | $5,500 | $3,500 | $4,000 | $1,000 |
| Small (includes federal, state and non-profit organizations) | $4,300 | $6,000 | $4,000 | $4,500 | $1,500 |
| 6 – Very Large – Greater than $75M | $27,500 | $15,000 | $6,000 | $8,000 | $3,500 |
- The page lists a “Practices Statement Assessment Fee” column but does not say which programs incur it.
- Program-specific: “UDAP Client App – Basic $1,500” annual fee (source).
Verify current fees with DirectTrust before budgeting. IHS scopes each engagement after a free introductory call.
What this is not
- IHS is not an accrediting body and does not grant, predict or influence DirectTrust’s decision.
- IHS does not submit anything to DirectTrust. IHS drafts; your organization submits.
- IHS does not design, test or validate PKI controls, assurance levels or UDAP and HL7 conformance. This page is not legal advice.
Frequently asked questions
What does DirectTrust Certificate Authority accreditation require?
DirectTrust says its Certificate Authority Accreditation Program focuses on policies and structures, identification and authentication processes, certificate life-cycle management, and technical security controls. The 2026 version is Certificate Authority v2.2. Applicants must also show HIPAA compliance proof.
Do we need HITRUST or WebTrust before applying for DirectTrust CA accreditation?
DirectTrust says CA applicants must provide proof of one of three: a valid DirectTrust Privacy and Security accreditation, HITRUST certification or WebTrust certification.
What is the difference between DirectTrust Certificate Authority and Registration Authority accreditation?
The CA program covers entities that issue digital certificates. The RA program covers entities in the registration authority role and adds facility and operations control to the areas it reviews. Both cover identification and authentication processes, life-cycle management and technical security.
What is the DirectTrust Identity Provider program and is it still in Beta?
It targets organizations that issue digital credentials linked to verified real-world identities at high assurance levels. As of DirectTrust's program page read on October 2, 2026, the program is in its Beta phase and is identifying organizations to participate. The 2026 criteria version is Identity Provider v1.1.
What NIST 800-63 assurance levels does the DirectTrust Identity Provider program expect?
DirectTrust gives NIST SP 800-63 IAL2 or IAL3 for identity proofing and AAL2 or AAL3 for authenticators as examples of the high assurance levels it targets. The criteria text sets the requirement.
What is UDAP accreditation and which UDAP track fits an identity provider versus a FHIR server?
The UDAP suite augments other DirectTrust programs and verifies that an application, identity service or server (API) can execute the technical components to be trusted. The 2026 tracks include UDAP Identity Provider Criteria v1.2, UDAP Server v1.2, UDAP Client App v1.2 and UDAP Client App - Basic v1.2. UDAP programs require conformance with HL7's Interoperable Digital Identity and Patient Matching Capabilities.
How long does DirectTrust accreditation take and how often must it be renewed?
DirectTrust does not publish a typical timeline on the pages IHS reviewed. The accreditation cycle is 2 years, and renewing organizations submit a complete self-assessment 4 months before expiration.
How much does DirectTrust CA or RA accreditation cost?
DirectTrust publishes revenue-tiered fees, for example a $3,100 Annual Fee and $5,500 Assessment Fee for organizations under $3M in revenue. A Practices Statement Assessment Fee column ($4,000 in that tier) appears, but the page does not say which programs incur it. Verify current fees with DirectTrust; IHS scopes its own engagement after a free introductory call.
What organizational policies do assessors look for in a trust-service accreditation?
DirectTrust's program pages name policies and structures, identification and authentication processes, life-cycle management and, for registration authorities, facility and operations control. The criteria text for your track sets the detail. IHS drafts the governance, identity-proofing, access, incident and partner-obligation documents that answer those areas.
Does DirectTrust accreditation let our anchor certificates into the DirectTrust Network?
DirectTrust says accreditation means an organization's anchor certificates may be included in the DirectTrust Network for use by relying parties in Direct exchange. The decision on accreditation is the Commission's.
