Guides
Long-form, independent guides on choosing and working with security and compliance auditors. Each one covers the same ground a buyer has to cover in practice: what the standard actually requires of the auditor, what accreditation or licensing means, what the engagement costs and how long it runs, and which questions separate a firm that fits your scope from one that does not.
These guides are written for the person who owns the audit inside the company: a founder, a head of security, a compliance lead, or the operations manager who inherited the project. They assume you have been told you need a report or a certificate, and that you now have to pick a firm, agree a scope, and defend the cost internally. They do not assume prior audit experience.
We keep them separate from the blog on purpose. Blog posts respond to something happening in the market. Guides are reference material: we revise them when a standard, an accreditation rule, or a price band changes, and each one carries the date it was last reviewed so you can judge how current it is. Where a claim comes from a standard or a published source, the guide says so rather than asserting it.
One thing worth stating plainly, because it shapes what you will read: Nomona does not take referral fees from audit firms. The guidance below is written to help you choose well, including the cases where the answer is to delay the audit, narrow the scope, or work with a firm you did not find here.
All guides
- ISO 27001How to Choose an ISO 27001 Auditor
What accreditation actually means for ISO 27001, what a certification audit costs, and the impartiality questions to ask before you sign.
Last updated 21 July 2026 · 14 min read
Read the guide - SOC 2How to Choose a SOC 2 Auditor
Why a SOC 2 report has to come from a CPA firm, how Type 1 and Type 2 differ, and how to compare quotes without buying on price alone.
Last updated 21 July 2026 · 16 min read
Read the guide
Frameworks these guides relate to
Each framework page sets out who the standard applies to, what the audit covers, typical cost and timeline, and the firms on Nomona that carry it out. Start there if you are still deciding which report you need.
- SOC 2Trust services attestation for SaaS and cloud providers.
- ISO 27001Global standard for information security management systems.
- ISO 42001AI management system certification. The emerging benchmark.
- HIPAAUS healthcare privacy and security compliance assessment.
- GDPREU data protection readiness and Article 32 controls review.