Can one firm do both HITRUST and SOC 2?
A HITRUST assessor can also issue SOC 2 when the same provider group holds CPA attestation capability. Verify current official status and the issuing entities, because the HITRUST and SOC 2 deliverables remain separate even when one provider coordinates both.
Verify current approved status, scope, and legal entity through HITRUST before signing. Directory labels here are a screening cut, not a substitute for that official check.
Some nonattest help may be possible depending on scope and safeguards, but the firm cannot assume management responsibility. Client management owns decisions and controls; ask the firm to document each party’s roles. Listed timelines and prices cover SOC 2 planning only, not HITRUST certification work.