Attestio
HITRUST · 2026 Assessor Directory

The HITRUST assessor directory

111 HITRUST-approved External Assessors and Readiness Licensees, sourced from the HITRUST Alliance. HITRUST CSF is the de facto healthcare security framework; this directory is for hospital systems, health tech vendors, and business associates preparing for CSF certification.

✓ Independently verified Last updated June 14, 2026
73
External Assessors
38
Readiness Licensees
30+
States covered
8
Avg years in HITRUST
Editorial illustration of a HITRUST assessment
The buyer's guide

How to choose a firm — and what to expect

HITRUST CSF certification is the most rigorous healthcare security certification in the US market. Unlike PCI QSA or SOC 2, HITRUST assessors are certified by the HITRUST Alliance itself — there is no AB layer. This guide explains the two assessor tiers (External Assessor vs. Readiness Licensee), what a HITRUST CSF assessment costs, and how HITRUST fits with HIPAA, SOC 2, and ISO 27001.

01

What is a HITRUST assessor?

A HITRUST External Assessor is a firm approved by the HITRUST Alliance to conduct validated CSF assessments (the r2 and e1 certifications). The External Assessor assigns a CCSFP (Certified CSF Practitioner) to lead the engagement; the CCSFP signs the assessment report. A HITRUST Readiness Licensee is a firm authorized to perform HITRUST readiness assessments (the precursor to a validated assessment) but cannot issue a final r2 or e1 certificate. The vast majority of healthcare organizations work with a Readiness Licensee first, then a different External Assessor for the validated assessment — though the same firm can do both if it holds both credentials.

02

How to choose a HITRUST assessor: 5 criteria

1. CCSFP depth. The number of Certified CSF Practitioners on staff is the strongest signal. 2. Healthcare vertical experience. HITRUST is healthcare-specific. Look for assessors with deep experience in your sub-sector: hospitals, payers, health tech, business associates. 3. Multi-framework support. Most HITRUST buyers also need HIPAA, SOC 2, and/or ISO 27001. An assessor that runs all of them in parallel saves 30-40% on total cost. 4. MyCSF tool fluency. HITRUST assessments are conducted in the MyCSF tool. Assessors with deep MyCSF expertise will deliver a smoother engagement. 5. Cost transparency. HITRUST pricing varies widely. Ask for a fixed-fee proposal up front.

03

How much does HITRUST CSF certification cost?

A validated r2 assessment for a mid-sized healthcare organization: $50K–$150K. e1 assessments (the lighter-weight HITRUST certification, ~150 controls): $25K–$60K. Readiness assessments (preparatory, no certificate): $15K–$40K. Cost drivers: scope (number of systems, locations, and data types in scope), number of HITRUST control requirements (r2 has 2,000+ — you implement a subset based on your risk profile), and whether the assessor also does the readiness phase. Red flag: any assessor that quotes a flat fee before doing a scoping assessment is not following HITRUST methodology.

04

How long does HITRUST CSF certification take?

Readiness assessment: 2–3 months. Validated r2 assessment: 4–8 months from kickoff to certificate. The validated assessment is the bottleneck — HITRUST QA review adds 2–4 weeks after the assessor submits the report. Certificates are valid for 2 years, with an interim review at the 1-year mark.

05

HITRUST + HIPAA + SOC 2: do you need all three?

For healthcare organizations, HITRUST CSF is increasingly the gold standard — a CSF r2 certificate is accepted by most large hospital systems and most enterprise healthcare buyers as evidence of HIPAA Security Rule compliance. A SOC 2 is a complement, not a substitute. The most efficient path: HITRUST CSF r2 as the primary framework, SOC 2 in parallel for the SaaS / B2B side, HIPAA Security Risk Analysis as a subset of the HITRUST scope. An assessor that delivers all three in a single engagement (with shared evidence) is the most cost-effective option.

HITRUST is healthcare-specific and healthcare-deep. A generalist auditor will struggle with the MyCSF tool, the control inheritance model, and the HITRUST QA process. Use the directory below to filter by External Assessor vs. Readiness Licensee, by US state coverage, and by the assessor’s multi-framework capability (HITRUST + SOC 2 + ISO 27001 in parallel).
Editor's picks

Six firms worth shortlisting

For each use case below, we picked one assessor from the 111 we index. These are the firms we’d shortlist first for healthcare buyers with the specific need described.

Best for hospital systems

Coalfire

HITRUST + SOC 2 + ISO 27001 in one engagement

Coalfire has one of the largest HITRUST practices among the External Assessors, with deep hospital-system experience. They run HITRUST CSF r2 alongside SOC 2 and ISO 27001 in a single engagement with shared evidence, which is the most cost-effective path for large health systems.

100+ HITRUST r2 certificates for hospital systems
View profile →
Best for health tech SaaS

A-LIGN

HITRUST + SOC 2 for health tech

For health tech SaaS companies that need HITRUST CSF and SOC 2 (the standard B2B combination), A-LIGN runs both in a single engagement with shared evidence. They also handle HIPAA Security Risk Analysis as a subset of the HITRUST scope.

300+ HITRUST certificates for SaaS
View profile →
Best for payers and health plans

Schellman Compliance

HITRUST + SOC 2 for payers

Schellman has a deep HITRUST practice focused on payers and health plans. They are one of the few External Assessors that runs HITRUST alongside SOC 2 in a single audit window with shared control testing.

50+ HITRUST r2 certificates for payers
View profile →
Best for clinical research / life sciences

BARR Advisory

HITRUST for clinical research orgs

BARR has specific experience with clinical research organizations (CROs) and life sciences vendors. Their HITRUST engagements include FDA 21 CFR Part 11 mapping and GxP-aligned control testing as part of the standard scope.

HITRUST + GxP scope standard
View profile →
Best for business associates

Linford & Company

HITRUST for mid-market BAs

Linford specializes in mid-market business associates (BAs) — the vendors that process PHI on behalf of covered entities. They run HITRUST CSF e1 (the lighter-weight certification) for BAs that don’t need the full r2 scope.

HITRUST e1 specialist
View profile →
Best for readiness assessments

Moss Adams

Readiness Licensee with deep HITRUST bench

Moss Adams is a Readiness Licensee with one of the largest HITRUST readiness practices. For organizations preparing for their first validated assessment, Moss Adams does the readiness phase and then hands off to an External Assessor for the validated phase.

50+ readiness assessments per year
View profile →
How we pick: Picks are based on the assessor’s HITRUST track record (number of r2/e1 certificates issued), depth of healthcare sub-sector experience, multi-framework delivery capability, and CCSFP bench size. We do not accept payment for inclusion. Assessors: <a href="/operators/claim">claim your firm’s profile</a> to update your listing.
How we verify

We source HITRUST assessors from the HITRUST Alliance itself, cross-referenced with the assessor’s claimed profile.

Verified quarterly Last verified June 14, 2026 Last crawled June 14, 2026
The HITRUST Alliance maintains the public list of External Assessors and Readiness Licensees. 73 External Assessors and 38 Readiness Licensees as of June 2026.
The MyCSF tool records the actual certification results — cross-reference for verified engagements.
Direct verification
Assessors with a claimed profile can update their CCSFP count, healthcare sub-sector specializations, and multi-framework capability directly.
📋

Get the free checklist

We'll email you the PDF. Plus weekly compliance insights. No spam, unsubscribe with one click.

We use this only to send your checklist. One-click unsubscribe in every email.

The full directory

All 111 HITRUST firms

Filter by category or search.

Clear all
Showing 67 firms in External Assessor

AWS Security Assurance Services

Accorian

Advantage Partners

Alliant Cybersecurity

Ampcus Cyber

Avertium

BDO

BEYOND HC LLC

BlueOrange Compliance

Bonadio Group

Clearwater

CompliancePoint

Crimson Security Inc.

CyberCrest Compliance

Cyberguard Compliance

Deloitte Touche Tohmatsu India LLP

Digital Forge Cybersecurity

DirectTrust

Edwards Performance Solutions

Eide Bailly LLP

EisnerAmper LLP

Entpermasys Consulting and Advisory Services LLC

Ernst & Young India

Ernst & Young LLP

Finstein

Formos Consulting

GMsectec

HoganTaylor

Holt Data Solutions

I.S. Partners LLC

Intercert

Intraprise Health

Jacobian Engineering

KPMG in India

Katz, Sapper, & Miller, L.L.P.

King & Spalding

Kompleye Attestation LLC

Kratos Defense

LBMC Security & Risk Services

Latitude Information Security

Maloney + Novotny LLC

Marcum LLP

Meditology Services

MegaPlanIT Holdings, LLC

Moss Adams

Network Intelligence, LLC

Neutral Partners

OneLeet Inc.

Optiv

Palindrome Technologies

PwC

PwC India

RISC Point Advisory Group Limited

RSI Security

SISA Information Security

Security Compliance Associates

SecurityMetrics

Sensiba

Techno iQualityHub Innovations LLC (TiQHUB)

Tevora

UnitedHealth Group

ValueMentor Infosec Limited

Vicis Law PC

Wipfli LLP

Wolf & Company, P.C

ecfirst

risk3sixty

FAQ

Common questions

What is the difference between HITRUST CSF r2 and e1?

r2 is the full HITRUST CSF assessment: 2,000+ control requirements with a risk-based scoping model. e1 is the lighter-weight certification: ~150 control requirements, designed for organizations that need HITRUST recognition but don’t need the full r2 scope. e1 is faster and cheaper.

How long is a HITRUST certificate valid?

2 years for r2 and e1, with an interim review at the 1-year mark. The interim is a lighter-touch assessment to confirm continued compliance.

Can a Readiness Licensee issue a HITRUST certificate?

No. Only an External Assessor can issue a validated r2 or e1 certificate. A Readiness Licensee can do the preparatory assessment, but the final certificate requires an External Assessor.

Is HITRUST accepted outside the US?

Increasingly. HITRUST has mutual recognition agreements with several international frameworks, and an r2 certificate is accepted by many EU and APAC healthcare buyers. However, ISO 27001 remains the dominant international standard. For multinational healthcare, the most efficient path is HITRUST r2 + ISO 27001 in parallel.