Brand Compliance
UnverifiedUnclaimed accountRvA- and BELAC-accredited certification body for ISO 27001 and Belgium's CyberFundamentals (CyFun) NIS2 scheme.
5 accredited NIS2 audit firms serving Europe on Nomona. NIS2 is an EU cybersecurity law requiring essential and important entities to manage security risks, report incidents, and hold management accountable. Typical timeline: NIS2 compliance is continuous rather than a one-time audit. Organizations typically run a gap assessment against the national transposing law, implement the required risk-management measures over several months, and then maintain them under ongoing supervision. Essential entities should be prepared for regulator-initiated audits at any time.. Typical cost: There is no fixed audit fee. Cost is driven by a gap assessment plus the implementation effort to meet the national transposing law; larger essential entities in regulated sectors should budget accordingly..
RvA- and BELAC-accredited certification body for ISO 27001 and Belgium's CyberFundamentals (CyFun) NIS2 scheme.
One of France's longest-running cybersecurity firms, PASSI RGS/LPM qualified since 1995.
ANSSI PASSI-qualified auditors covering all four audit scopes, plus NIS2, DORA and GDPR advisory.
Single Audit, Multiple Standards: SOC, ISAE, ISO, NIS2 and DORA in one integrated process.
One of only two BELAC-accredited bodies authorized to perform NIS2 CyberFundamentals (CyFun) verification audits in Belgium.
Directive deadline was 17 October 2024. Transposition and enforcement dates still differ by member state. January 2026 Commission proposal for certification-based pathways remains a proposal, not law.
Key date: October 17, 2024. Last verified Jul 13, 2026
Cyberbeveiligingswet (national NIS2 implementation) still being finalized. Expected entry into force in 2026; exact date depends on parliamentary passage.
Last verified Jul 13, 2026
Nomona lists 5 independent, accredited NIS2 audit firms serving Europe today, including firms with global coverage.
There is no fixed audit fee. Cost is driven by a gap assessment plus the implementation effort to meet the national transposing law; larger essential entities in regulated sectors should budget accordingly.