Audit firms by framework and region

    Each page below lists the independent firms on Nomona that carry out one framework in one region. A page exists only where at least five firms explicitly serve that region, so the listings stay substantive rather than near-identical. Firms that work globally appear on every regional page for the frameworks they cover.

    10 regional pages across 8 frameworks.

    CMMC is the US Department of Defense's cybersecurity certification requirement for contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), assessed by accredited C3PAOs (Level 2) or the government's DIBCAC (Level 3).

    GDPR is the EU's data protection law. Compliance is demonstrated through audits and documentation, not a single official certificate.

    HIPAA is US law governing how protected health information is safeguarded. There is no official certificate. Compliance is shown through independent assessment.

    HITRUST CSF is a certifiable framework widely required in US healthcare and health-tech, increasingly used alongside or instead of HIPAA, assessed by HITRUST Authorized External Assessor organizations.

    ISO/IEC 27001 is the international standard for information security management. An accredited certification body audits your ISMS and issues a certificate.

    NIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable.

    PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits payment card data, assessed by Qualified Security Assessor (QSA) firms via a Report on Compliance (RoC).

    SOC 2 is an AICPA attestation report that shows how a company protects customer data. A licensed CPA firm tests your controls and issues an independent opinion.