HITRUST Authorized External Assessor

Powered by ValueMentor

Readiness, validated assessment and HITRUST certification support — in one engagement.

Build a strong cybersecurity foundation and demonstrate it through independent validation. ValueMentor is a HITRUST Authorized External Assessor and can support your organization from HITRUST e1 readiness through the validated assessment and submission to HITRUST. e1 focuses on 43 foundational cybersecurity controls — a practical, lower-complexity entry point into HITRUST assurance.
Starting from $14,500.

Guided planFrom $14,500
Complete plan$19,500
DeliveryRemote, delivered globally
Delivered byValueMentor — HITRUST Authorized External Assessor

The definition

What is HITRUST e1 certification?

HITRUST Essentials, 1-Year — commonly called HITRUST e1 — is a validated cybersecurity assessment and certification focused on foundational cybersecurity practices. It uses a defined set of 43 HITRUST CSF requirements focused on essential security controls and control implementation. Unlike a self-assessment or security questionnaire, an e1 Validated Assessment is independently tested by a HITRUST Authorized External Assessor and submitted to HITRUST for quality assurance and a certification decision. A successful assessment results in a HITRUST e1 Certification valid for one year.
  • Guided plan

    From $14,500

  • Complete plan

    $19,500

  • Delivery

    Remote, delivered globally

  • Delivered by

    ValueMentor — HITRUST Authorized External Assessor

Is HITRUST e1 right for you?

HITRUST e1 can be a good fit if you:

  • Are a startup, SaaS provider, healthcare technology company or growing business that needs independent cybersecurity assurance.
  • Have been asked by a customer or business partner for HITRUST assurance.
  • Want to demonstrate foundational cybersecurity controls without immediately pursuing the more extensive i1 or r2 assessment.
  • Need stronger assurance than a security questionnaire or self-assessment.
  • Want to establish a foundation that can later support progression toward HITRUST i1 or r2.
  • Have a relatively straightforward technology environment and lower-risk assessment scope.

If customers require broader threat-based assurance, regulatory coverage or a more comprehensive HITRUST assessment, HITRUST i1 or r2 may be more appropriate.

Not sure which HITRUST assessment you need?

Talk to us

Choose your HITRUST e1 plan

Every plan includes HITRUST e1 scoping, a readiness/gap assessment, gap remediation guidance, evidence requirements guidance, the validated assessment, submission to HITRUST and QA support.

Guided

Organizations with an established security program

$14,500one-time

Package scope
  • Pre-assessment evidence reviewUp to 2 reviews
  • HITRUST readiness workshopsUp to 6
  • Remediated evidence follow-up1 review
  • Support periodUp to 8 weeks

Timeline depends on your readiness, scope complexity and team availability.

Enterprise

Complex or multi-environment organizations

Custom pricing

Everything in Complete, plus
  • HITRUST policy & procedure templatesIncluded
  • Pre-assessment evidence reviewCustom
  • HITRUST readiness workshopsCustom
  • Dedicated project managerIncluded
  • Remediated evidence follow-upCustom
  • Support periodCustom

Timeline depends on your readiness, scope complexity and team availability.

Compare plans

FeatureGuidedCompleteEnterprise
Best forOrganizations with an established security programOrganizations that want structured end-to-end supportComplex or multi-environment organizations
HITRUST policy & procedure templates—
Pre-assessment evidence reviewUp to 2 reviewsUp to 4 reviewsCustom
HITRUST readiness workshopsUp to 6Weekly during readiness periodCustom
Dedicated project manager—
Remediated evidence follow-up1 reviewUp to 2 reviewsCustom
Support periodUp to 8 weeksUp to 12 weeksCustom

HITRUST/MyCSF licensing, report, assessment processing or other fees charged by HITRUST are not included in the ValueMentor service fee and will be identified separately.

What's included

Every plan covers the full journey from scoping through HITRUST submission and QA support.

  • 1. HITRUST e1 Scoping

    We work with your team to define exactly what will be covered by the assessment. The standard Guided and Complete packages are designed around one legal entity and one defined HITRUST assessment scope — typically one SaaS platform, product, service or defined technology environment. Complex multi-product, multi-entity or materially distributed environments may require Enterprise scoping.

  • 2. HITRUST Readiness Assessment

    Before validation begins, we evaluate your current environment against the applicable HITRUST e1 requirements — identifying controls already implemented, missing or insufficient controls, documentation and evidence gaps, potential inheritance opportunities, and areas requiring remediation. You receive a prioritized readiness action plan showing what should be addressed before the validated assessment.

  • 3. Remediation Guidance

    Our team explains what is missing, why it matters, what needs to be implemented, and what evidence will be required. Your organization remains responsible for implementing and operating its security controls. The Complete plan adds workshops, templates and evidence preparation support to reduce the administrative burden on your team.

  • 4. Evidence Preparation

    HITRUST certification requires more than having policies — controls must be implemented and supported by appropriate evidence. We help your team understand what evidence is expected and review documentation before the validated assessment begins. Typical evidence includes configuration records, screenshots, system reports, logs, policies, procedures, tickets and approvals.

  • 5. HITRUST Validated Assessment

    Once your organization is ready, ValueMentor performs the official HITRUST e1 Validated Assessment as a HITRUST Authorized External Assessor — testing the applicable controls, reviewing supporting evidence, validating control implementation and completing the applicable assessment scoring. The validated assessment is then prepared for submission to HITRUST.

  • 6. HITRUST Submission & QA

    ValueMentor manages the assessment submission and works through the HITRUST quality assurance process. If HITRUST raises questions or requests clarification relating to the validated assessment, our assessment team coordinates the required responses. The final certification decision remains with HITRUST.

  • 7. HITRUST e1 Certification

    Organizations that successfully meet HITRUST's certification requirements receive a HITRUST e1 Certification Report, valid for one year. Organizations must undergo reassessment to maintain their HITRUST e1 certified status after the certification period.

How it works

How the process works

  1. Step 1

    Purchase & kickoff

    Choose your service plan, complete onboarding and meet your HITRUST team.

  2. Step 2

    Define scope

    We confirm the system, application, infrastructure and organizational boundaries covered by your assessment.

  3. Step 3

    Readiness assessment

    We evaluate your existing implementation against HITRUST e1 requirements.

  4. Step 4

    Close readiness gaps

    Your team implements the required actions with guidance from ValueMentor.

  5. Step 5

    Prepare evidence

    Evidence is collected and reviewed for assessment readiness.

  6. Step 6

    Validated assessment

    ValueMentor's assessment team independently tests the applicable controls and validates the assessment.

  7. Step 7

    HITRUST submission & QA

    The validated assessment is submitted through the HITRUST process for quality assurance.

  8. Step 8

    Certification

    If the certification requirements are satisfied, HITRUST issues your e1 certification and report.

How long does HITRUST e1 take?

A well-prepared organization can move through HITRUST e1 significantly faster than an i1 or r2 assessment. HITRUST states that an e1 assessment can potentially be completed in as few as 4–6 weeks, depending on organizational readiness.

  • Guided

    Up to 8 weeks

    Readiness and assessment support included in the Guided plan.

  • Complete

    Up to 12 weeks

    Readiness and assessment support included in the Complete plan.

The actual certification timeline depends on your starting level of readiness, remediation requirements, evidence availability and the HITRUST quality assurance process. We do not guarantee certification within a specific number of days.

Included

What you get

At the end of the engagement, depending on the assessment outcome, you will receive:

Your engagement includes

  • HITRUST e1 scope definition
  • Readiness assessment results
  • Gap and remediation action plan
  • Evidence requirements guidance
  • Validated HITRUST e1 assessment
  • HITRUST assessment submission
  • Support through HITRUST QA
  • HITRUST e1 Certification Report when certification requirements are successfully met

The HITRUST certification and final certification report are issued by HITRUST, not by ValueMentor or Secusy.

Your role

What you need to provide

To keep the assessment moving efficiently, your team will need to:

You will normally provide

  • Nominate an internal HITRUST project owner
  • Confirm the systems and services included within scope
  • Provide requested policies, procedures and security documentation
  • Provide evidence demonstrating control implementation
  • Make relevant technical and business control owners available for interviews
  • Implement required remediation
  • Maintain ownership and operation of your controls
  • Provide required access to the HITRUST/MyCSF assessment environment

Scope boundaries

What is not included

Unless specifically included in your order, the standard HITRUST e1 service does not include — these services can be scoped separately where required:

  • HITRUST or MyCSF fees
  • Security technology or software licenses
  • Implementation or operation of customer security controls
  • Custom policy writing
  • Penetration testing
  • Vulnerability remediation
  • SOC/MDR services
  • HITRUST i1 or r2 assessment
  • HITRUST AI Security Certification
  • Additional compliance Insights Reports or combined assessments
  • On-site assessment activities
  • Certification guarantees

The faster evidence and remediation actions are completed, the faster the assessment can progress.

Why Secusy + ValueMentor?

One journey from readiness to validated assessment and HITRUST submission. Many organizations coordinate separate readiness support and assessor organizations — ValueMentor, as an Authorized External Assessor, supports the full e1 path in one structured program.

Authorized HITRUST External Assessor

ValueMentor is formally listed by HITRUST as an Authorized HITRUST External Assessor Organization, authorized to perform validated assessments that can be submitted to HITRUST for certification.

One journey from readiness to validation

Avoid coordinating separate readiness and assessor organizations — a structured process from scoping through readiness, assessment and HITRUST QA, maintaining required assessor independence between advisory and validation activities.

Clear scope and pricing

Know the ValueMentor professional-service cost before you begin. Third-party HITRUST fees are separated so you can clearly see what you are paying for.

Digital onboarding

Purchase or initiate your assessment online, complete your scope information and begin evidence collection without a lengthy traditional sales process.

Cybersecurity expertise beyond HITRUST

If your assessment identifies areas requiring deeper security work, ValueMentor can support related cybersecurity requirements through appropriately separated teams and services.

HITRUST e1 vs i1 vs r2

HITRUST e1HITRUST i1HITRUST r2
Primary objectiveFoundational cybersecurity assuranceModerate, threat-adaptive assuranceComprehensive risk-based assurance
Core requirements43182Tailored to risk and scope
Control selectionFixedFixedRisk-based and tailored
Certification period1 year1 year2 years
Best suited forLower-risk / less complex organizationsOrganizations requiring stronger cybersecurity assuranceComplex, high-risk or highly regulated environments
Relative effortLowerMediumHighest

Not sure which one you need?

Talk to a HITRUST Assessor

Optional services

Organizations pursuing HITRUST e1 can add related cybersecurity services where required:

Questions

Frequently asked questions

Start your HITRUST e1 journey

Get independent HITRUST assurance without starting with the complexity of a full r2 assessment. Choose the level of support you need — ValueMentor will help you understand the requirements, prepare for validation, perform the authorized external assessment and manage the assessment through HITRUST submission and QA.

Guided

$14,500one-time

Enterprise

Custom pricing