Independent directory · not affiliated with HITRUST Services LLC
Every organization authorized to run your HITRUST assessment, in one ledger.
HITRUST doesn't perform assessments itself — that work belongs to a vetted roster of External Assessor Organizations and Readiness Licensees. We track the firms on that roster so you can shortlist before the first call, without digging through a picker widget.
HITRUST certifies. Assessors do the testing.
Every HITRUST assurance product is built around independent testing. The tier you pursue determines how deep that testing goes — and which class of assessor you'll need at your side.
e1
Foundational cybersecurity assurance covering 43 core controls. The fastest entry point onto the HITRUST roster.
i1
Threat-adaptive assurance across 182 control requirements, built to track emerging attack patterns year over year.
r2
Tailored, risk-based assurance at the highest control depth — the tier most often required by enterprise partners.
How this ledger is built.
Three commitments that shape everything on this site.
Pulled from the public list
Every firm name here comes directly from HITRUST's published "Find an External Assessor" page — not a purchased list or manual guesswork.
No invented detail
HITRUST's own picker doesn't publish structured firm data the way some registries do, so website and HQ for each firm were independently verified. 68 of 111 firms are confirmed so far; the rest are clearly flagged rather than guessed at.
Confirm before you engage
Authorization status changes. Always confirm a firm's current standing directly with HITRUST before signing an engagement letter.
Open the full ledger of 111 assessors.
Search by name, scan alphabetically the same way HITRUST's own picker groups them, or tell us what you need and we'll help you shortlist.