Guided plan
From $24,500
HITRUST Authorized External Assessor
Powered by ValueMentor
Build stronger cybersecurity assurance with a structured path to HITRUST i1 certification. Secusy combines readiness support, remediation guidance, evidence preparation and the official validated assessment through ValueMentor, an Authorized HITRUST External Assessor.
182 requirements. One structured certification journey. Starting from $24,500.
The definition
From $24,500
$34,500
182 fixed HITRUST CSF requirements
ValueMentor — HITRUST Authorized External Assessor
Overview
Key characteristics of the HITRUST i1 assessment and one-year certification program.
182 fixed HITRUST CSF requirements
Moderate
Implementation of cybersecurity controls
Fixed — no risk-based tailoring of the i1 control set
Authorized HITRUST External Assessor
1 year
Approximately 6–12 months depending on readiness
Rapid Recertification option
Organizations requiring stronger third-party cybersecurity assurance
HITRUST describes i1 as a fixed, threat-adaptive assessment covering 182 control requirements and providing one-year certification.
HITRUST i1 may be appropriate when your organization:
HITRUST itself positions i1 for organizations with maturing cybersecurity programs, security-conscious vendors, organizations facing third-party risk requirements and companies preparing eventually for r2.
Not sure which HITRUST assessment you need?
Compare e1, i1 & r2Every plan includes scope confirmation, an i1 readiness assessment, assessment against all 182 i1 requirements, gap identification, remediation recommendations, evidence review, External Assessor validation, submission to HITRUST and support during HITRUST QA.
Organizations with an established security program and an internal team capable of completing most remediation activities
$24,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Organizations that want hands-on assistance through readiness, remediation and the validated assessment
$34,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Larger or complex organizations requiring customized scoping, multiple systems, business units or locations
Custom pricing
Timeline depends on your readiness, scope complexity and team availability.
| Feature | Guided | Complete | Enterprise |
|---|---|---|---|
| Best for | Organizations with an established security program and an internal team capable of completing most remediation activities | Organizations that want hands-on assistance through readiness, remediation and the validated assessment | Larger or complex organizations requiring customized scoping, multiple systems, business units or locations |
| Detailed remediation planning | — | ||
| Policy & procedure development support | — | ||
| Evidence preparation support | Guidance only | Hands-on support | Custom |
| Implementation working sessions | — | Regular sessions | Custom |
| Project management | — | Dedicated project governance | |
| HITRUST QA response coordination |
HITRUST/MyCSF licensing, report, assessment processing or other fees charged by HITRUST are not included in the ValueMentor service fee and will be identified separately.
Every plan covers the full journey from scoping through HITRUST submission and QA support.
We start by determining what will be included within the certification boundary — your applications, infrastructure, cloud environments, supporting systems, people, locations and business processes relevant to the assessment. Although organizations can define their assessment boundary, the 182-requirement i1 control set itself is fixed rather than individually tailored like r2.
We evaluate your current security practices against the HITRUST i1 requirements. For each requirement, we determine whether sufficient implementation and evidence exist to support the expected assessment score, giving your organization a clear Ready / Improvement Required / Significant Gap view and a prioritized roadmap before formal validation begins.
Certification should not begin with surprises. Our team helps you understand what must change before the validated assessment — depending on your plan, this may include policy improvements, security process changes, technical control recommendations, evidence improvements and implementation guidance. The objective is to resolve material gaps before formal validation.
HITRUST requires the External Assessor to validate control implementation using appropriate evidence and documented testing procedures. We help ensure evidence is relevant, current, complete and mapped to the correct requirement — better evidence preparation can significantly reduce unnecessary back-and-forth during validation.
ValueMentor is an Authorized HITRUST External Assessor. Our assessment team performs the required independent validation procedures, documents testing and validates the assessment information within MyCSF. ValueMentor Infosec Limited is currently included in HITRUST's official External Assessor directory.
Once validation is completed and the required assessment documentation is finalized, the assessment is submitted to HITRUST. HITRUST then performs its own Quality Assurance review before determining the certification result — a separate layer of assurance beyond the External Assessor's testing.
Where the assessment satisfies HITRUST's applicable certification requirements and completes HITRUST QA successfully, HITRUST issues the certification, valid for one year. Certification is issued by HITRUST — purchasing Secusy or ValueMentor services does not by itself guarantee certification.
How it works
We confirm the systems, applications, infrastructure and organizational boundaries covered by your assessment.
We evaluate your current implementation against the 182 HITRUST i1 requirements.
Your team resolves identified gaps with guidance from ValueMentor.
Evidence is collected, reviewed and mapped to the correct requirement.
ValueMentor's assessment team independently tests the applicable controls.
The validated assessment is submitted to HITRUST for its own quality assurance review.
If certification requirements are satisfied, HITRUST issues your i1 certification.
We establish your project plan after the initial scoping and readiness review.
HITRUST currently advises that most organizations complete the overall i1 certification process within approximately 6–12 months. Typical journey: Scope → Readiness → Remediation → Evidence → Validation → HITRUST QA → Certification.
6–12 months
Actual duration depends heavily on your starting level of readiness. A company with mature controls and well-organized evidence may progress much faster through readiness and remediation than an organization implementing its security program for the first time.
One advantage of HITRUST i1 is its year-two Rapid Recertification option. Instead of repeating the complete 182-requirement assessment, eligible organizations can follow a lighter assessment focused on approximately 60 requirements. HITRUST designed this process to reduce the effort required to maintain i1 assurance during the following certification cycle.
182 requirements
~60 requirements
Secusy can support your Rapid Recertification as a separate service.
Included
At the end of the engagement, depending on the assessment outcome, you will receive:
Your engagement includes
The HITRUST certification and final certification report are issued by HITRUST, not by ValueMentor or Secusy.
Your role
Successful HITRUST certification requires active participation from your organization. You will need to provide:
You will normally provide
Scope boundaries
Unless specifically included in your proposal or purchased as an additional service, the standard HITRUST i1 service does not include — these services can be added separately where required:
The Complete plan reduces the workload on your internal team, but your organization remains responsible for implementing and operating its controls.
One journey from readiness to validated assessment and HITRUST submission. Many organizations coordinate separate readiness support and assessor organizations — ValueMentor, as an Authorized External Assessor, supports the full i1 path in one structured program.
The validated assessment is delivered through ValueMentor, an Authorized HITRUST External Assessor listed by HITRUST.
Avoid coordinating multiple disconnected providers. Secusy brings readiness, remediation support, project coordination and validated assessment into a structured certification journey.
HITRUST certification requires more than completing questionnaires. Our teams understand cybersecurity implementation, cloud environments, governance, risk, vulnerability management, security testing and compliance.
Manage the engagement, evidence requirements, activities and progress through Secusy with expert support from ValueMentor.
Our remote delivery model enables organizations across multiple markets to work with experienced HITRUST professionals without unnecessary onsite dependencies.
| HITRUST e1 | HITRUST i1 | HITRUST r2 | |
|---|---|---|---|
| Assurance | Foundational | Moderate | Highest |
| Requirements | 43 | 182 | Tailored |
| Control set | Fixed | Fixed | Risk-based and tailored |
| Primary maturity focus | Implemented | Implemented | Multiple maturity levels |
| Certification validity | 1 year | 1 year | 2 years |
| Best suited for | Foundational assurance | Stronger threat-focused assurance | Comprehensive risk-based assurance |
| External validation | Yes | Yes | Yes |
Foundational assurance with 43 core requirements when a lighter HITRUST entry point fits your scope.
View e1 serviceComprehensive, risk-based assurance for complex, high-risk or highly regulated environments.
Talk to an assessorNot sure which one you need?
Talk to a HITRUST ExpertStrengthen your HITRUST program with related services available through Secusy:
Identify exploitable vulnerabilities before assessment.
Learn moreCombine HITRUST assurance with SOC 2 reporting where customers require both.
Learn moreBuild an ISO 27001-aligned ISMS alongside your HITRUST program.
Learn moreEstablish ongoing identification and remediation of security vulnerabilities.
Learn moreAdd experienced security leadership without hiring a full-time CISO.
Learn moreQuestions
Move from uncertainty about HITRUST requirements to a structured certification program with one team supporting you from readiness through validated assessment.
$24,500one-time
$34,500one-time
Custom pricing
HITRUST assessment delivered by ValueMentor — Authorized HITRUST External Assessor.