Guides

    Long-form, independent guides on choosing and working with security and compliance auditors. Each one covers the same ground a buyer has to cover in practice: what the standard actually requires of the auditor, what accreditation or licensing means, what the engagement costs and how long it runs, and which questions separate a firm that fits your scope from one that does not.

    These guides are written for the person who owns the audit inside the company: a founder, a head of security, a compliance lead, or the operations manager who inherited the project. They assume you have been told you need a report or a certificate, and that you now have to pick a firm, agree a scope, and defend the cost internally. They do not assume prior audit experience.

    We keep them separate from the blog on purpose. Blog posts respond to something happening in the market. Guides are reference material: we revise them when a standard, an accreditation rule, or a price band changes, and each one carries the date it was last reviewed so you can judge how current it is. Where a claim comes from a standard or a published source, the guide says so rather than asserting it.

    One thing worth stating plainly, because it shapes what you will read: Nomona does not take referral fees from audit firms. The guidance below is written to help you choose well, including the cases where the answer is to delay the audit, narrow the scope, or work with a firm you did not find here.

    All guides