Assessor & consultant directory

Firms that do NIST CSF 2.0 and HITRUST work

Every firm below is a real, operating practice with a verified website. Firms described as HITRUST-authorized assessors appear on HITRUST’s published external assessor list (checked September 2026). Firms we could not confirm there are labeled as such — verify directly before engaging one for a validated assessment. Sponsorship never affects ranking; see our methodology.

All firms

Firm

A-LIGN

A-LIGN is a compliance and audit firm working across SOC 2, ISO 27001, PCI DSS, and healthcare frameworks. It appears on HITRUST's published external assessor list and performs HITRUST assessments alongside multi-framework audit programs.

Tampa, Florida · Founded 2009
HITRUST (authorized assessor), SOC 2, ISO 27001, PCI DSS, NIST CSF
Firm

Coalfire

Coalfire is a cybersecurity advisory and assessment firm with practices spanning HITRUST, FedRAMP, and enterprise frameworks. It appears on HITRUST's published external assessor list and advises on NIST CSF 2.0 programs for mid-market and enterprise clients.

Westminster, Colorado · Founded 2001
HITRUST (authorized assessor), FedRAMP (authorized 3PAO), SOC 2, ISO 27001, NIST CSF, PCI DSS
Firm

Schellman

Schellman is an independent assessment firm known for audit work across SOC, ISO, FedRAMP, and HITRUST. It appears on HITRUST's published external assessor list. The firm is assessment-only by posture — it does not sell the remediation it would later assess.

Tampa, Florida · Founded 2002
HITRUST (authorized assessor), SOC 1/2, ISO 27001, FedRAMP (authorized 3PAO), PCI DSS
Firm

KirkpatrickPrice

KirkpatrickPrice is an audit and assessment firm focused on SOC 2, ISO 27001, and HITRUST. It appears on HITRUST's published external assessor list and works with SaaS and healthcare companies on recurring audit programs.

Nashville, Tennessee · Founded Not disclosed
HITRUST (authorized assessor), SOC 2, ISO 27001, PCI DSS
Firm

360 Advanced

360 Advanced is a compliance and audit firm working across SOC 2, ISO 27001, and HITRUST. It appears on HITRUST's published external assessor list and serves healthcare and SaaS clients on assessment programs.

St. Petersburg, Florida · Founded Not disclosed
HITRUST (authorized assessor), SOC 2, ISO 27001, PCI DSS
Firm

Sensiba

Sensiba is an accounting and advisory firm whose cybersecurity practice covers SOC 2, ISO 27001, and HITRUST. It appears on HITRUST's published external assessor list and works with growth-stage companies on combined audit programs.

San Ramon, California · Founded 1977
HITRUST (authorized assessor), SOC 2, ISO 27001, NIST CSF
Firm

BARR Advisory

BARR Advisory is a cybersecurity compliance firm focused on SOC 2, ISO 27001, and HITRUST engagements for cloud and SaaS companies. It appears on HITRUST's published external assessor list.

Not disclosed · Founded Not disclosed
HITRUST (authorized assessor), SOC 2, ISO 27001, PCI DSS
Firm

Lazarus Alliance

Lazarus Alliance is a cybersecurity compliance firm serving healthcare and enterprise clients on HITRUST readiness, SOC 2, and multi-framework programs. Note: we could not confirm this firm on HITRUST's published external assessor list as of September 2026 — verify assessor status directly if you need a validated (r2) assessment.

Not disclosed · Founded Not disclosed
HITRUST readiness, SOC 2, ISO 27001, PCI DSS, NIST CSF

Comparing firms? Tell us your scope once — get quotes from your shortlist. Free · 2 minutes · no obligation.

Get matched quotes
Firm

Compass IT Compliance

Compass IT Compliance is an IT audit and compliance firm working across SOC 2, ISO 27001, PCI DSS, and NIST CSF implementations. Note: we could not confirm this firm on HITRUST's published external assessor list as of September 2026 — verify assessor status directly if you need a validated assessment.

Not disclosed · Founded Not disclosed
SOC 2, ISO 27001, PCI DSS, NIST CSF, HIPAA security assessments
Firm

Eide Bailly

Eide Bailly is a national accounting and advisory firm whose technology consulting practice covers cybersecurity assessments including HITRUST. It appears on HITRUST's published external assessor list (as Eide Bailly LLP).

Fargo, North Dakota · Founded 1917
HITRUST (authorized assessor), SOC 2, ISO 27001, NIST CSF
Firm

LBMC

LBMC's Security & Risk Services practice provides cybersecurity assessment and advisory services including HITRUST. It appears on HITRUST's published external assessor list (as LBMC Security & Risk Services) and is also listed as a HITRUST authorized reseller.

Nashville, Tennessee · Founded 1984
HITRUST (authorized assessor), SOC 2, ISO 27001, NIST CSF, PCI DSS
Firm

Optiv

Optiv is a cybersecurity advisory firm covering strategy, architecture, and managed security. It appears on HITRUST's published external assessor list and advises enterprises on NIST CSF 2.0 program design and implementation.

Denver, Colorado · Founded 2015
NIST CSF 2.0, HITRUST (authorized assessor), zero trust, managed security
Firm

Kroll

Kroll is a global risk advisory firm whose cyber practice covers incident response, risk assessments, and security program consulting. Note: we could not confirm this firm on HITRUST's published external assessor list as of September 2026 — it is positioned here for NIST CSF program work, not validated HITRUST assessments.

New York, New York · Founded 1932
NIST CSF 2.0, incident response, cyber risk assessments, managed detection

Healthcare & HITRUST

HITRUST-authorized assessors and healthcare-focused firms for HIPAA-adjacent assurance programs.

FirmTypePlanning rangeTypical timeline
A-LIGNCybersecurity compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal
CoalfireCybersecurity advisory and assessment firmNot published — request a scoped quoteVaries — confirm in proposal
SchellmanIndependent cybersecurity assessment firmNot published — request a scoped quoteVaries — confirm in proposal
KirkpatrickPriceCybersecurity audit and assessment firmNot published — request a scoped quoteVaries — confirm in proposal
360 AdvancedCybersecurity compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal
SensibaAccounting and advisory firm with a cybersecurity practiceNot published — request a scoped quoteVaries — confirm in proposal
Lazarus AllianceCybersecurity compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal
Eide BaillyAccounting and business advisory firm with a cybersecurity practiceNot published — request a scoped quoteVaries — confirm in proposal
LBMCProfessional services firm (LBMC Security & Risk Services)Not published — request a scoped quoteVaries — confirm in proposal

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

Growth-stage companies

Firms that work with startups and mid-market teams on their first CSF program or HITRUST assessment.

FirmTypePlanning rangeTypical timeline
A-LIGNCybersecurity compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal
KirkpatrickPriceCybersecurity audit and assessment firmNot published — request a scoped quoteVaries — confirm in proposal
360 AdvancedCybersecurity compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal
SensibaAccounting and advisory firm with a cybersecurity practiceNot published — request a scoped quoteVaries — confirm in proposal
BARR AdvisoryCybersecurity compliance and advisory firmNot published — request a scoped quoteVaries — confirm in proposal
Lazarus AllianceCybersecurity compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal
Compass IT ComplianceIT compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

Enterprise programs

CSF 2.0 program consulting and large-scope assessments for complex organizations.

FirmTypePlanning rangeTypical timeline
A-LIGNCybersecurity compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal
CoalfireCybersecurity advisory and assessment firmNot published — request a scoped quoteVaries — confirm in proposal
SchellmanIndependent cybersecurity assessment firmNot published — request a scoped quoteVaries — confirm in proposal
BARR AdvisoryCybersecurity compliance and advisory firmNot published — request a scoped quoteVaries — confirm in proposal
Compass IT ComplianceIT compliance and audit firmNot published — request a scoped quoteVaries — confirm in proposal
Eide BaillyAccounting and business advisory firm with a cybersecurity practiceNot published — request a scoped quoteVaries — confirm in proposal
LBMCProfessional services firm (LBMC Security & Risk Services)Not published — request a scoped quoteVaries — confirm in proposal
OptivCybersecurity advisory and solutions firmNot published — request a scoped quoteVaries — confirm in proposal
KrollGlobal risk and cybersecurity consulting firmNot published — request a scoped quoteVaries — confirm in proposal

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

Get matched quotes

One brief reaches the firms above — scoped quotes, free, no obligation.

Get a free quote