Find your auditor.
Searchable. Transparent.
Nomona is the independent marketplace where compliance buyers search audit firms by framework, scope, region, and budget, with transparent price discovery and verified reviews to compare on substance.
How Nomona works
Browse the Directory
Search audit firms by framework, scope, and region. Compare published price ranges, read verified post-audit reviews, and contact firms directly. Pricing is published by auditors, not Nomona.
Browse the directoryPost a Bid Request
Use it as an anonymous RFP to find the best price. Describe your scope, timeline, and budget once, and receive sealed, competitive bids from qualified auditors within 48–72 hours.
Post a bid requestThe numbers don't lie. Neither do we.
Three ways to find an auditor. Only one is built around the buyer.
- Conflict of interestNone
- Price transparencyPublic ranges
- Auditor choiceOpen, verified & transparent
- Time to first quote48–72 hours
- IndependenceBuyer-first, always
- Conflict of interestBuilt into the model
- Price transparencyHidden behind sales
- Auditor choiceInfluenced by partnerships
- Time to first quote1–2 weeks
- IndependencePlatform-first
- Conflict of interestNone
- Price transparencyOne quote at a time
- Auditor choiceLimited to your network
- Time to first quoteWeeks of outreach
- IndependenceVariable
Every standard your buyer expects.
Attestation over controls relevant to financial reporting at a service organisation.
Trust services attestation for SaaS and cloud providers.
Public-facing summary report derived from a SOC 2 Type II engagement.
Global standard for information security management systems.
Privacy information management extension to ISO 27001.
AI management system certification. The emerging benchmark.
US healthcare privacy and security compliance assessment.
EU data protection readiness and Article 32 controls review.
EU cybersecurity directive for essential and important entities.
EU digital operational resilience for the financial sector.
EU Cyber Resilience Act conformity for products with digital elements.
US Department of Defense cybersecurity maturity certification for the defense industrial base.
Payment card industry data security standard for merchants and service providers.
Certifiable framework used across US healthcare and regulated industries.
Accredited penetration testing and technical assurance delivered by CREST member companies.
Need PCI DSS, FedRAMP, TISAX, C5, or something niche? Tell us what you're auditing for and we'll surface matching firms.
Send requestSearch audit firms the way you'd buy any service.
Filter by framework, scope, region, and budget. Compare published pricing and verified reviews. Get qualified bids and pick the firm that fits.
Planning a SOC 2? Read our full SOC 2 audit cost breakdown for typical price ranges.