Audit firms by framework and region
Each page below lists the independent firms on Nomona that carry out one framework in one region. A page exists only where at least five firms explicitly serve that region, so the listings stay substantive rather than near-identical. Firms that work globally appear on every regional page for the frameworks they cover.
10 regional pages across 8 frameworks.
CMMC
CMMC overviewCMMC is the US Department of Defense's cybersecurity certification requirement for contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), assessed by accredited C3PAOs (Level 2) or the government's DIBCAC (Level 3).
GDPR
GDPR overviewGDPR is the EU's data protection law. Compliance is demonstrated through audits and documentation, not a single official certificate.
HIPAA
HIPAA overviewHIPAA is US law governing how protected health information is safeguarded. There is no official certificate. Compliance is shown through independent assessment.
HITRUST
HITRUST overviewHITRUST CSF is a certifiable framework widely required in US healthcare and health-tech, increasingly used alongside or instead of HIPAA, assessed by HITRUST Authorized External Assessor organizations.
ISO 27001
ISO 27001 overviewISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate.
NIS2
NIS2 overviewNIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable.
PCI DSS
PCI DSS overviewPCI DSS is the mandatory security standard for any organization that stores, processes, or transmits payment card data, assessed by Qualified Security Assessor (QSA) firms via a Report on Compliance (RoC).
SOC 2
SOC 2 overviewSOC 2 is an AICPA attestation report that shows how a company protects customer data. A licensed CPA firm tests your controls and issues an independent opinion.