Independent audit marketplace

    Find your auditor.
    Searchable. Transparent.

    Nomona is the independent marketplace where compliance buyers search audit firms by framework, scope, region, and budget, with transparent price discovery and verified reviews to compare on substance.

    Transparent
    Pricing & reviews
    100%
    Independent
    Filter
    By framework, scope, region
    How it works

    How Nomona works

    Why Nomona

    The numbers don't lie. Neither do we.

    Three ways to find an auditor. Only one is built around the buyer.

    Conflict of interest
    Nomona
    None
    Incumbent platforms
    Built into the model
    Going direct
    None
    Price transparency
    Nomona
    Public ranges
    Incumbent platforms
    Hidden behind sales
    Going direct
    One quote at a time
    Auditor choice
    Nomona
    Open, verified & transparent
    Incumbent platforms
    Influenced by partnerships
    Going direct
    Limited to your network
    Time to first quote
    Nomona
    48–72 hours
    Incumbent platforms
    1–2 weeks
    Going direct
    Weeks of outreach
    Independence
    Nomona
    Buyer-first, always
    Incumbent platforms
    Platform-first
    Going direct
    Variable
    Frameworks

    Every standard your buyer expects.

    View all auditors
    SOC 1

    Attestation over controls relevant to financial reporting at a service organisation.

    Typical: 8–14 weeksBrowse auditors
    SOC 2

    Trust services attestation for SaaS and cloud providers.

    Typical: 8–14 weeksBrowse auditors
    SOC 3

    Public-facing summary report derived from a SOC 2 Type II engagement.

    Typical: 4–8 weeksBrowse auditors
    ISO 27001

    Global standard for information security management systems.

    Typical: 12–20 weeksBrowse auditors
    ISO 27701

    Privacy information management extension to ISO 27001.

    Typical: 10–16 weeksBrowse auditors
    ISO 42001

    AI management system certification. The emerging benchmark.

    Typical: 16–24 weeksBrowse auditors
    HIPAA

    US healthcare privacy and security compliance assessment.

    Typical: 6–12 weeksBrowse auditors
    GDPR

    EU data protection readiness and Article 32 controls review.

    Typical: 6–10 weeksBrowse auditors
    NIS2

    EU cybersecurity directive for essential and important entities.

    Typical: 10–16 weeksBrowse auditors
    DORA

    EU digital operational resilience for the financial sector.

    Typical: 12–18 weeksBrowse auditors
    CRA

    EU Cyber Resilience Act conformity for products with digital elements.

    Typical: 10–16 weeksBrowse auditors
    CMMC

    US Department of Defense cybersecurity maturity certification for the defense industrial base.

    Typical: 12–20 weeksBrowse auditors
    PCI DSS

    Payment card industry data security standard for merchants and service providers.

    Typical: 10–16 weeksBrowse auditors
    HITRUST

    Certifiable framework used across US healthcare and regulated industries.

    Typical: 16–24 weeksBrowse auditors
    CREST

    Accredited penetration testing and technical assurance delivered by CREST member companies.

    Typical: 2–6 weeksBrowse auditors
    Request a framework

    Need PCI DSS, FedRAMP, TISAX, C5, or something niche? Tell us what you're auditing for and we'll surface matching firms.

    Send request

    Search audit firms the way you'd buy any service.

    Filter by framework, scope, region, and budget. Compare published pricing and verified reviews. Get qualified bids and pick the firm that fits.

    Planning a SOC 2? Read our full SOC 2 audit cost breakdown for typical price ranges.