Guided plan
From $14,500
HITRUST Authorized External Assessor
Powered by ValueMentor
Build a strong cybersecurity foundation and demonstrate it through independent validation. ValueMentor is a HITRUST Authorized External Assessor and can support your organization from HITRUST e1 readiness through the validated assessment and submission to HITRUST. e1 focuses on 43 foundational cybersecurity controls — a practical, lower-complexity entry point into HITRUST assurance.
Starting from $14,500.
The definition
From $14,500
$19,500
Remote, delivered globally
ValueMentor — HITRUST Authorized External Assessor
HITRUST e1 can be a good fit if you:
If customers require broader threat-based assurance, regulatory coverage or a more comprehensive HITRUST assessment, HITRUST i1 or r2 may be more appropriate.
Not sure which HITRUST assessment you need?
Talk to usEvery plan includes HITRUST e1 scoping, a readiness/gap assessment, gap remediation guidance, evidence requirements guidance, the validated assessment, submission to HITRUST and QA support.
Organizations with an established security program
$14,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Organizations that want structured end-to-end support
$19,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Complex or multi-environment organizations
Custom pricing
Timeline depends on your readiness, scope complexity and team availability.
| Feature | Guided | Complete | Enterprise |
|---|---|---|---|
| Best for | Organizations with an established security program | Organizations that want structured end-to-end support | Complex or multi-environment organizations |
| HITRUST policy & procedure templates | — | ||
| Pre-assessment evidence review | Up to 2 reviews | Up to 4 reviews | Custom |
| HITRUST readiness workshops | Up to 6 | Weekly during readiness period | Custom |
| Dedicated project manager | — | ||
| Remediated evidence follow-up | 1 review | Up to 2 reviews | Custom |
| Support period | Up to 8 weeks | Up to 12 weeks | Custom |
HITRUST/MyCSF licensing, report, assessment processing or other fees charged by HITRUST are not included in the ValueMentor service fee and will be identified separately.
Every plan covers the full journey from scoping through HITRUST submission and QA support.
We work with your team to define exactly what will be covered by the assessment. The standard Guided and Complete packages are designed around one legal entity and one defined HITRUST assessment scope — typically one SaaS platform, product, service or defined technology environment. Complex multi-product, multi-entity or materially distributed environments may require Enterprise scoping.
Before validation begins, we evaluate your current environment against the applicable HITRUST e1 requirements — identifying controls already implemented, missing or insufficient controls, documentation and evidence gaps, potential inheritance opportunities, and areas requiring remediation. You receive a prioritized readiness action plan showing what should be addressed before the validated assessment.
Our team explains what is missing, why it matters, what needs to be implemented, and what evidence will be required. Your organization remains responsible for implementing and operating its security controls. The Complete plan adds workshops, templates and evidence preparation support to reduce the administrative burden on your team.
HITRUST certification requires more than having policies — controls must be implemented and supported by appropriate evidence. We help your team understand what evidence is expected and review documentation before the validated assessment begins. Typical evidence includes configuration records, screenshots, system reports, logs, policies, procedures, tickets and approvals.
Once your organization is ready, ValueMentor performs the official HITRUST e1 Validated Assessment as a HITRUST Authorized External Assessor — testing the applicable controls, reviewing supporting evidence, validating control implementation and completing the applicable assessment scoring. The validated assessment is then prepared for submission to HITRUST.
ValueMentor manages the assessment submission and works through the HITRUST quality assurance process. If HITRUST raises questions or requests clarification relating to the validated assessment, our assessment team coordinates the required responses. The final certification decision remains with HITRUST.
Organizations that successfully meet HITRUST's certification requirements receive a HITRUST e1 Certification Report, valid for one year. Organizations must undergo reassessment to maintain their HITRUST e1 certified status after the certification period.
How it works
Choose your service plan, complete onboarding and meet your HITRUST team.
We confirm the system, application, infrastructure and organizational boundaries covered by your assessment.
We evaluate your existing implementation against HITRUST e1 requirements.
Your team implements the required actions with guidance from ValueMentor.
Evidence is collected and reviewed for assessment readiness.
ValueMentor's assessment team independently tests the applicable controls and validates the assessment.
The validated assessment is submitted through the HITRUST process for quality assurance.
If the certification requirements are satisfied, HITRUST issues your e1 certification and report.
A well-prepared organization can move through HITRUST e1 significantly faster than an i1 or r2 assessment. HITRUST states that an e1 assessment can potentially be completed in as few as 4–6 weeks, depending on organizational readiness.
Up to 8 weeks
Readiness and assessment support included in the Guided plan.
Up to 12 weeks
Readiness and assessment support included in the Complete plan.
The actual certification timeline depends on your starting level of readiness, remediation requirements, evidence availability and the HITRUST quality assurance process. We do not guarantee certification within a specific number of days.
Included
At the end of the engagement, depending on the assessment outcome, you will receive:
Your engagement includes
The HITRUST certification and final certification report are issued by HITRUST, not by ValueMentor or Secusy.
Your role
To keep the assessment moving efficiently, your team will need to:
You will normally provide
Scope boundaries
Unless specifically included in your order, the standard HITRUST e1 service does not include — these services can be scoped separately where required:
The faster evidence and remediation actions are completed, the faster the assessment can progress.
One journey from readiness to validated assessment and HITRUST submission. Many organizations coordinate separate readiness support and assessor organizations — ValueMentor, as an Authorized External Assessor, supports the full e1 path in one structured program.
ValueMentor is formally listed by HITRUST as an Authorized HITRUST External Assessor Organization, authorized to perform validated assessments that can be submitted to HITRUST for certification.
Avoid coordinating separate readiness and assessor organizations — a structured process from scoping through readiness, assessment and HITRUST QA, maintaining required assessor independence between advisory and validation activities.
Know the ValueMentor professional-service cost before you begin. Third-party HITRUST fees are separated so you can clearly see what you are paying for.
Purchase or initiate your assessment online, complete your scope information and begin evidence collection without a lengthy traditional sales process.
If your assessment identifies areas requiring deeper security work, ValueMentor can support related cybersecurity requirements through appropriately separated teams and services.
| HITRUST e1 | HITRUST i1 | HITRUST r2 | |
|---|---|---|---|
| Primary objective | Foundational cybersecurity assurance | Moderate, threat-adaptive assurance | Comprehensive risk-based assurance |
| Core requirements | 43 | 182 | Tailored to risk and scope |
| Control selection | Fixed | Fixed | Risk-based and tailored |
| Certification period | 1 year | 1 year | 2 years |
| Best suited for | Lower-risk / less complex organizations | Organizations requiring stronger cybersecurity assurance | Complex, high-risk or highly regulated environments |
| Relative effort | Lower | Medium | Highest |
Moderate, threat-adaptive assurance when e1 is not enough for your customers or risk profile.
View i1 serviceComprehensive, risk-based assurance for complex, high-risk or highly regulated environments.
Talk to an assessorNot sure which one you need?
Talk to a HITRUST AssessorOrganizations pursuing HITRUST e1 can add related cybersecurity services where required:
Add AI-specific security assurance where AI systems are within your environment or product.
Learn moreValidate application, API, cloud or network security through independent security testing.
Learn moreEstablish and maintain security awareness across your workforce.
Learn moreGet ongoing security leadership and governance support.
Learn moreCombine HITRUST assurance with SOC 2 reporting where customers require both.
Learn moreBuild or certify an information security management system alongside your HITRUST program.
Learn moreQuestions
Get independent HITRUST assurance without starting with the complexity of a full r2 assessment. Choose the level of support you need — ValueMentor will help you understand the requirements, prepare for validation, perform the authorized external assessment and manage the assessment through HITRUST submission and QA.
$14,500one-time
$19,500one-time
Custom pricing