HITRUST Authorized External Assessor

Powered by ValueMentor

HITRUST i1 Certification — from readiness to validated assessment.

Build stronger cybersecurity assurance with a structured path to HITRUST i1 certification. Secusy combines readiness support, remediation guidance, evidence preparation and the official validated assessment through ValueMentor, an Authorized HITRUST External Assessor.
182 requirements. One structured certification journey. Starting from $24,500.

Guided planFrom $24,500
Complete plan$34,500
Requirements assessed182 fixed HITRUST CSF requirements
Delivered byValueMentor — HITRUST Authorized External Assessor

The definition

What is HITRUST i1 certification?

The HITRUST i1 Validated Assessment provides a moderate level of cybersecurity assurance using a predefined set of 182 HITRUST CSF requirements. Unlike the entry-level e1 assessment, i1 evaluates a substantially broader range of cybersecurity practices and active cyber threats. Unlike the HITRUST r2 assessment, i1 does not use a customized risk-based control set — the assessment requirements are fixed, which can make the scope more predictable for organizations that need stronger assurance without moving immediately to r2. The assessment evaluates the Implemented maturity level of applicable requirements and must be validated by an Authorized HITRUST External Assessor before being submitted to HITRUST for independent quality assurance and certification consideration.
  • Guided plan

    From $24,500

  • Complete plan

    $34,500

  • Requirements assessed

    182 fixed HITRUST CSF requirements

  • Delivered by

    ValueMentor — HITRUST Authorized External Assessor

Overview

HITRUST i1 at a glance

Key characteristics of the HITRUST i1 assessment and one-year certification program.

  • Assessment scope

    182 fixed HITRUST CSF requirements

  • Assurance level

    Moderate

  • Assessment focus

    Implementation of cybersecurity controls

  • Control selection

    Fixed — no risk-based tailoring of the i1 control set

  • Validation

    Authorized HITRUST External Assessor

  • Certification validity

    1 year

  • Typical certification journey

    Approximately 6–12 months depending on readiness

  • Year 2

    Rapid Recertification option

  • Best suited for

    Organizations requiring stronger third-party cybersecurity assurance

HITRUST describes i1 as a fixed, threat-adaptive assessment covering 182 control requirements and providing one-year certification.

Is HITRUST i1 right for your organization?

HITRUST i1 may be appropriate when your organization:

  • Handle sensitive customer, healthcare or regulated information.
  • Are being asked by customers or enterprise procurement teams for HITRUST certification.
  • Have outgrown basic cybersecurity assurance such as HITRUST e1.
  • Need independently validated evidence of cybersecurity control implementation.
  • Operate as a SaaS, technology, healthcare, fintech or service provider supporting regulated customers.
  • Want a defined stepping stone toward HITRUST r2.
  • Need stronger assurance for third-party risk management programs.

HITRUST itself positions i1 for organizations with maturing cybersecurity programs, security-conscious vendors, organizations facing third-party risk requirements and companies preparing eventually for r2.

Not sure which HITRUST assessment you need?

Compare e1, i1 & r2

Choose your HITRUST i1 plan

Every plan includes scope confirmation, an i1 readiness assessment, assessment against all 182 i1 requirements, gap identification, remediation recommendations, evidence review, External Assessor validation, submission to HITRUST and support during HITRUST QA.

Guided

Organizations with an established security program and an internal team capable of completing most remediation activities

$24,500one-time

Package scope
  • Evidence preparation supportGuidance only
  • HITRUST QA response coordinationIncluded

Timeline depends on your readiness, scope complexity and team availability.

Enterprise

Larger or complex organizations requiring customized scoping, multiple systems, business units or locations

Custom pricing

Everything in Complete, plus
  • Detailed remediation planningIncluded
  • Policy & procedure development supportIncluded
  • Evidence preparation supportCustom
  • Implementation working sessionsCustom
  • Project managementDedicated project governance
  • HITRUST QA response coordinationIncluded

Timeline depends on your readiness, scope complexity and team availability.

Compare plans

FeatureGuidedCompleteEnterprise
Best forOrganizations with an established security program and an internal team capable of completing most remediation activitiesOrganizations that want hands-on assistance through readiness, remediation and the validated assessmentLarger or complex organizations requiring customized scoping, multiple systems, business units or locations
Detailed remediation planning—
Policy & procedure development support—
Evidence preparation supportGuidance onlyHands-on supportCustom
Implementation working sessions—Regular sessionsCustom
Project management—Dedicated project governance
HITRUST QA response coordination

HITRUST/MyCSF licensing, report, assessment processing or other fees charged by HITRUST are not included in the ValueMentor service fee and will be identified separately.

What's included in our HITRUST i1 service

Every plan covers the full journey from scoping through HITRUST submission and QA support.

  • 1. Scope Your HITRUST Assessment

    We start by determining what will be included within the certification boundary — your applications, infrastructure, cloud environments, supporting systems, people, locations and business processes relevant to the assessment. Although organizations can define their assessment boundary, the 182-requirement i1 control set itself is fixed rather than individually tailored like r2.

  • 2. Assess Your Current Readiness

    We evaluate your current security practices against the HITRUST i1 requirements. For each requirement, we determine whether sufficient implementation and evidence exist to support the expected assessment score, giving your organization a clear Ready / Improvement Required / Significant Gap view and a prioritized roadmap before formal validation begins.

  • 3. Remediate Identified Gaps

    Certification should not begin with surprises. Our team helps you understand what must change before the validated assessment — depending on your plan, this may include policy improvements, security process changes, technical control recommendations, evidence improvements and implementation guidance. The objective is to resolve material gaps before formal validation.

  • 4. Prepare Your Evidence

    HITRUST requires the External Assessor to validate control implementation using appropriate evidence and documented testing procedures. We help ensure evidence is relevant, current, complete and mapped to the correct requirement — better evidence preparation can significantly reduce unnecessary back-and-forth during validation.

  • 5. Perform the HITRUST i1 Validated Assessment

    ValueMentor is an Authorized HITRUST External Assessor. Our assessment team performs the required independent validation procedures, documents testing and validates the assessment information within MyCSF. ValueMentor Infosec Limited is currently included in HITRUST's official External Assessor directory.

  • 6. Submit the Assessment to HITRUST

    Once validation is completed and the required assessment documentation is finalized, the assessment is submitted to HITRUST. HITRUST then performs its own Quality Assurance review before determining the certification result — a separate layer of assurance beyond the External Assessor's testing.

  • 7. Receive Your HITRUST i1 Certification

    Where the assessment satisfies HITRUST's applicable certification requirements and completes HITRUST QA successfully, HITRUST issues the certification, valid for one year. Certification is issued by HITRUST — purchasing Secusy or ValueMentor services does not by itself guarantee certification.

How it works

Typical journey

  1. Step 1

    Scope

    We confirm the systems, applications, infrastructure and organizational boundaries covered by your assessment.

  2. Step 2

    Readiness

    We evaluate your current implementation against the 182 HITRUST i1 requirements.

  3. Step 3

    Remediation

    Your team resolves identified gaps with guidance from ValueMentor.

  4. Step 4

    Evidence

    Evidence is collected, reviewed and mapped to the correct requirement.

  5. Step 5

    Validation

    ValueMentor's assessment team independently tests the applicable controls.

  6. Step 6

    HITRUST QA

    The validated assessment is submitted to HITRUST for its own quality assurance review.

  7. Step 7

    Certification

    If certification requirements are satisfied, HITRUST issues your i1 certification.

We establish your project plan after the initial scoping and readiness review.

How long does HITRUST i1 certification take?

HITRUST currently advises that most organizations complete the overall i1 certification process within approximately 6–12 months. Typical journey: Scope → Readiness → Remediation → Evidence → Validation → HITRUST QA → Certification.

  • Typical overall timeline

    6–12 months

    Actual duration depends heavily on your starting level of readiness. A company with mature controls and well-organized evidence may progress much faster through readiness and remediation than an organization implementing its security program for the first time.

Year-two HITRUST i1 Rapid Recertification

One advantage of HITRUST i1 is its year-two Rapid Recertification option. Instead of repeating the complete 182-requirement assessment, eligible organizations can follow a lighter assessment focused on approximately 60 requirements. HITRUST designed this process to reduce the effort required to maintain i1 assurance during the following certification cycle.

Year 1

182 requirements


Year 2 (Rapid Recertification)

~60 requirements

Secusy can support your Rapid Recertification as a separate service.

Included

What you get

At the end of the engagement, depending on the assessment outcome, you will receive:

Your engagement includes

  • Defined HITRUST i1 assessment scope
  • HITRUST readiness assessment
  • Requirement-level gap analysis
  • Remediation roadmap
  • Evidence requirements and mapping
  • Policy and control guidance according to your selected plan
  • Validated HITRUST i1 assessment
  • External Assessor testing and documentation
  • Assessment submission to HITRUST
  • HITRUST QA coordination
  • HITRUST i1 certification report where certification criteria are successfully achieved

The HITRUST certification and final certification report are issued by HITRUST, not by ValueMentor or Secusy.

Your role

What we need from you

Successful HITRUST certification requires active participation from your organization. You will need to provide:

You will normally provide

  • A designated HITRUST project owner
  • Access to relevant control owners
  • Information about systems and infrastructure
  • Existing policies and procedures
  • Technical and operational evidence
  • Access required for assessment interviews and testing
  • Timely remediation of identified gaps
  • Management review and approval of required representations

Scope boundaries

What's not included

Unless specifically included in your proposal or purchased as an additional service, the standard HITRUST i1 service does not include — these services can be added separately where required:

  • MyCSF subscription and HITRUST platform charges
  • Major technology implementations
  • Purchase of security products or third-party software
  • Managed security operations
  • Penetration testing
  • Cloud architecture implementation
  • Privacy legal advice
  • Certification outside the agreed assessment boundary
  • HITRUST r2 certification
  • Future annual recertification

The Complete plan reduces the workload on your internal team, but your organization remains responsible for implementing and operating its controls.

Why Secusy + ValueMentor?

One journey from readiness to validated assessment and HITRUST submission. Many organizations coordinate separate readiness support and assessor organizations — ValueMentor, as an Authorized External Assessor, supports the full i1 path in one structured program.

Authorized HITRUST External Assessor

The validated assessment is delivered through ValueMentor, an Authorized HITRUST External Assessor listed by HITRUST.

One journey from readiness to assessment

Avoid coordinating multiple disconnected providers. Secusy brings readiness, remediation support, project coordination and validated assessment into a structured certification journey.

Cybersecurity expertise behind the assessment

HITRUST certification requires more than completing questionnaires. Our teams understand cybersecurity implementation, cloud environments, governance, risk, vulnerability management, security testing and compliance.

Digital-first delivery

Manage the engagement, evidence requirements, activities and progress through Secusy with expert support from ValueMentor.

Global delivery

Our remote delivery model enables organizations across multiple markets to work with experienced HITRUST professionals without unnecessary onsite dependencies.

HITRUST e1 vs i1 vs r2

HITRUST e1HITRUST i1HITRUST r2
AssuranceFoundationalModerateHighest
Requirements43182Tailored
Control setFixedFixedRisk-based and tailored
Primary maturity focusImplementedImplementedMultiple maturity levels
Certification validity1 year1 year2 years
Best suited forFoundational assuranceStronger threat-focused assuranceComprehensive risk-based assurance
External validationYesYesYes

Not sure which one you need?

Talk to a HITRUST Expert

Questions

Frequently asked questions

Start your HITRUST i1 certification journey

Move from uncertainty about HITRUST requirements to a structured certification program with one team supporting you from readiness through validated assessment.

Guided

$24,500one-time

Enterprise

Custom pricing

HITRUST assessment delivered by ValueMentor — Authorized HITRUST External Assessor.