Drummond Group
Drummond Group is a privately held, independent compliance testing and certification body founded in 1999, providing impartial third-party assessments across 20+ frameworks (ONC Health IT, PCI DSS, ISO 27001, DEA EPCS, FHIR, SOC 2, NIST) for healthcare, financial services, pharma, and supply chain clients.
- Company typePrivate
- Founded1999
- HeadquartersAustin, United States
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Drummond Group does
Drummond Group, LLC is a privately held, independent compliance testing and certification body founded in 1999 and headquartered in Durham, North Carolina. The company operates as an impartial third-party assessor across more than 20 frameworks spanning healthcare (ONC Health IT, FHIR interoperability, DEA EPCS/CSOS, HIPAA, FDA CFR 21 Part 11, MARS-E), financial services (PCI DSS as a QSA, SOC 2, NYDFS 23 NYCRR 500, FTC Safeguards), technology (ISO 27001, NIST CSF 2.0, NIST AI RMF, penetration testing, vulnerability scanning, code analysis), and supply chain (AS2, AS4, ebMS, GS1 GDSN, DSCSA OCI). It serves healthcare IT vendors, payers, EHR developers, regulated financial institutions, pharmaceutical companies, manufacturers, and standards bodies such as GS1.
The company's technology stack includes the proprietary Full-Matrix Test Automation Platform for interoperability events, the FHIRplace multi-party FHIR testing platform supporting payer and patient access certification, web-based vulnerability scanning and EPCIS Interoperability Conformance Checker tools, and the Drummond Certified® and Drummond Validated™ trademarked seals used as market credentials. Senior assessors holding CISSP, CISM, CISA, and OSCP credentials staff engagements from day one. Key regulatory authorizations include ONC-ATL and ONC-ACB (ANAB/ANSI accredited, ID# 1045), QSA for PCI DSS, ANAB-accredited ISO 27001 certification body, DEA-approved third-party auditor, and GS1-approved testing provider.
Drummond's business model is professional services fee-for-testing, with quote-based pricing set during a free consultation phase that produces a custom Action Plan. Revenue is project-based with engagement timelines varying by framework. The company distributes through a consultative enterprise sales channel plus a customer portal for test event registration and certified product lookup, and supports demand generation via content marketing (blog, market studies, WEDI webinars, newsletters, and SEO). Ownership is family-controlled, with no disclosed institutional investors, and the company is navigating a leadership transition following the February 2026 death of founder/Chairman George Daniel Drummond.
Drummond Group firmographics
Firmographics- Name
- Drummond Group
- Legal name
- Drummond Group, LLC
- Website
- https://drummondgroup.com
- Company type
- Private
- Founded year
- 1999
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Drummond Group is a privately held, independent compliance testing and certification body founded in 1999, providing impartial third-party assessments across 20+ frameworks (ONC Health IT, PCI DSS, ISO 27001, DEA EPCS, FHIR, SOC 2, NIST) for healthcare, financial services, pharma, and supply chain clients.
- Ownership category
- akta.pro rank
Drummond Group industry classification
Industry- Product category
- Compliance Testing and Certification Services
- NAICS
- Professional Organizations (813920)
- SIC
- Services-Testing Laboratories (8734)
- akta.pro primary industry
- Audit Management, Controls & SOX Compliance (BPAEAPAH)
- akta.pro secondary industries
- EHS Auditing, Inspections & Assurance (BPAHAJAG), Data Assurance, Audit & Attestation (ISAE 3000/3410, SOC, Chain-of-Custody) (EUABACAJ)
Keywords
Where Drummond Group is headquartered
LocationHeadquarters
- HQ city
- Austin
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Drummond Group business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations, Marketing or Sales, Infrastructure
Revenue model
- Testing and Certification Services: Drummond generates revenue through fee-for-service testing and certification engagements across multiple compliance frameworks. Services include formal certifications (ONC Health IT, DEA EPCS, PCI DSS, ISO 27001, GS1 GDSN) and compliance assessments (HIPAA, NIST, SOC 2, FTC Safeguards). Revenue is project-based with engagement timelines varying by framework scope from weeks to months.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | HIPAA Gap Assessment with complimentary vulnerability scan |
Go-to-market motion1 record
Distribution channels2 records
Marketing channels6 records
Drummond Group product offering
Product offeringCore offering
Drummond Group, LLC is an independent third-party testing and certification body that assesses software, systems, and processes against more than 20 regulatory and industry frameworks. Its portfolio spans ONC Health IT, FHIR, DEA EPCS/CSOS, ISO 27001, PCI DSS, SOC 2, NIST, HIPAA, GS1 GDSN, AS2/AS4, and ebMS programs, delivered through formal certifications, audits, penetration testing, vulnerability scanning, and code analysis engagements.
Product overview
Drummond Group is a compliance, risk, and security testing and certification body with 25+ years of experience offering impartial third-party assessments across 20+ frameworks. The company operates as a platform of distinct certification and testing services rather than a unified software product. Core offerings include ONC Health IT Certification (as an ONC-Authorized Testing Laboratory and Certification Body), FHIRplace interoperability testing, DEA EPCS and CSOS certifications, and AS2/AS4/ebMS B2B interoperability testing. Security and compliance services encompass SOC 2, NIST Risk Assessments (CSF 2.0, SP 800-53, AI RMF, IR 8374), ISO 27001, PCI DSS (as a Qualified Security Assessor), HIPAA audits, FTC Safeguards, FDA CFR 21 Part 11, and MARS-E. Additional services include penetration testing, vulnerability scanning, code analysis, GS1 GDSN certification, pediatric health IT certification, and the ONC Compliance Learning Series educational program. The company serves healthcare, financial services, retail, technology, pharmaceutical, and supply chain industries.
Differentiator
Problem solved
Functional benefit
Brands
- FHIRplace: Drummond's managed FHIR interoperability testing platform for multi-party testing events
- Drummond Certified®
- Drummond Validated™
Products and services
- ONC Health IT Certification ONC-Authorized Testing Laboratory (ONC-ATL) and ONC-Authorized Certification Body (ONC-ACB) program that tests and certifies electronic health record systems and health IT products against federal functionality, security, and interoperability standards.
- FHIRplace Interoperability Testing Managed multi-party FHIR conformance and member-to-member interoperability testing platform that validates FHIR implementations against real-world partner systems, including automated test execution, scenario coverage, and centralized results analysis.
- DEA EPCS Certification DEA-approved third-party auditor certification for Electronic Prescriptions for Controlled Substances, verifying e-prescribing workflows meet DEA regulatory requirements.
- DEA CSOS Certification Certification service for the DEA Controlled Substances Ordering System, validating secure electronic ordering of controlled substances.
- pDSI-Risk Assessment Pre-Diabetes Software Initiative risk certification program supporting healthcare AI developer partnerships with ONC-certified Health IT systems, addressing AI risk management standards.
- AS2 Interoperability Testing and Certification B2B interoperability testing and certification for the AS2 messaging standard, enabling secure data exchange across automotive, financial services, government, healthcare, and retail industries.
- AS4 Interoperability Testing and Certification B2B interoperability testing and certification for the AS4 messaging standard, an ebXML Messaging Services profile for secure enterprise data exchange.
- ebMS Testing and Certification OASIS ebMS (ebXML Messaging Services) testing and certification program certifying products for compliance with ebMS 2.0 messaging standard for secure data exchange.
- GS1 GDSN Certification Testing and certification for the GS1 Global Data Synchronization Network enabling accurate product data synchronization across global supply chains.
- Open Credentialing Initiative (OCI) Drug Supply Chain Security Act compliance testing for the Open Credentialing Initiative, verifying interoperable data exchange for pharmaceutical supply chain security.
- SOC 2 Assessments SOC 2 assessments evaluating controls against AICPA Trust Services Criteria (Security, Privacy, Confidentiality, Availability, Processing Integrity) with Type I and Type II report options.
- NIST Risk Assessments Risk assessments against NIST frameworks including Cybersecurity Framework (CSF) 2.0, Special Publication 800-53, AI Risk Management Framework 1.0, and Interagency Report 8374 for ransomware.
- ISO 27001 Certification ANAB-accredited certification for information security management systems demonstrating compliance with ISO/IEC 27001.
- PCI DSS QSA Assessments PCI DSS assessment services delivered by Qualified Security Assessors producing Report on Compliance (RoC) and Attestation of Compliance (AoC) documentation for Level 1 merchants and service providers.
- HIPAA Compliance Audits HIPAA compliance audit and gap assessment services evaluating administrative, physical, and technical safeguards for protecting Protected Health Information.
- FTC Safeguards Compliance Compliance assessments for FTC Safeguards Rule requirements applicable to financial institutions and entities handling sensitive consumer data.
- FDA CFR 21 Part 11 Compliance Audits Compliance audits for FDA regulation on electronic records and signatures, ensuring integrity of digital records in pharmaceutical and medical device industries.
- MARS-E Compliance Audits Compliance assessments for MARS-E (Medicare & Medicaid Electronic Prescribing) requirements governing e-prescribing transactions.
- NYDFS 23 NYCRR 500 Risk Assessment Cybersecurity risk assessments for New York Department of Financial Services regulation 23 NYCRR Part 500, including penetration testing and vulnerability assessments.
- Penetration Testing Active security testing simulating real-world attack scenarios to identify and remediate vulnerabilities in systems and applications.
- Vulnerability Scanning Automated scanning services to identify security weaknesses and misconfigurations in IT infrastructure and applications, delivered through a web-based vulnerability portal.
- Code Analysis Security review of source code and application logic to identify vulnerabilities and compliance issues before deployment.
- Pediatric Health IT Certification Testing and certification program addressing pediatric-specific requirements for health IT systems and EHR products.
- Payer and Patient Access FHIR Certification Certification program for payer systems implementing FHIR-based Patient Access APIs and Provider Directory APIs under CMS interoperability requirements.
- FHIR Client Certification Certification program validating FHIR client applications against implementation guides, security measures, and efficiency standards.
- Comprehensive Healthcare Risk Assessment Holistic healthcare risk assessment combining multiple healthcare compliance dimensions into a single engagement.
- ONC Compliance Learning Series Educational program for health IT developers seeking ONC certification, consisting of six bi-weekly sessions covering health IT standards, ONC test procedures, compliance guides, and test tools.
Quantifiable outcome
- 69% reduction in median prior authorization decision time (from 18.7 hours to 5.7 hours) achieved by organizations implementing ePA solutions
- +1 more outcomes
Companies that use Drummond Group
Customer profileNamed customers13 records
Segments6 records
Ideal customer profiles5 records
Drummond Group technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
Drummond Group partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- ONC (Office of the National Coordinator for Health IT)coreDrummond is an ONC-Authorized Testing Laboratory (ONC-ATL) and ONC-Authorized Certification Body (ONC-ACB) operating under ANAB/ANSI accreditation (Accreditation ID# 1045). The partnership involves testing and certifying health IT products against ONC Certification Criteria including FHIR-based APIs.
- GS1coreGS1 has approved Drummond as a testing and certification provider for the Global Data Synchronization Network (GDSN). Drummond conducts AS2 interoperability testing and certification supporting GS1 standards. Susie McIntosh-Hinson, GS1 Sr. Director Operations & Conformance, has publicly acknowledged Drummond as a valued partner ensuring confidence in the GDSN network.
- ANAB (ANSI National Accreditation Board)coreDrummond's ONC-ACB operates under ANAB accreditation (Accreditation ID# 1045). Drummond is also ANAB-accredited for ISO 27001 certification. ANAB provides the accreditation framework that validates Drummond's certification body operations.
- KONZA HealthcoreKONZA Health joined FHIRplace as the first intermediary participant to expand interoperability testing. KONZA Health participated in a WEDI webinar with Drummond demonstrating the intermediary role in FHIR-based exchange and common failure points in FHIR compliance testing.
- WEDI (Workgroup for Electronic Data Interchange)minorDrummond hosted a WEDI webinar titled 'Beyond Connectathons: How Scalable FHIR Testing Is Possible With FHIRplace' featuring industry panelists discussing FHIR interoperability testing challenges and solutions.
- Shift (Health Data Exchange Task Force)minorTimothy Bennett, Drummond's Director of Strategic Healthcare Initiatives, serves as a governing board member of Shift, a task force of industry stakeholders working through barriers of equitable interoperability by addressing obstacles of privatized patient health data exchange.
- CMS (Centers for Medicare & Medicaid Services)coreDrummond supports CMS regulatory requirements including FHIR-based Prior Authorization under CMS-0057-F. Drummond participates in the CMS Health Tech Pledge, an industry-wide initiative to improve patient care through enhanced health data interoperability using FHIR standards.
- DEA (Drug Enforcement Administration)coreDrummond is a DEA-approved third-party auditor for EPCS (Electronic Prescriptions for Controlled Substances) and CSOS (Controlled Substances Ordering System) certification programs.
Scale indicators4 records
Recent moves6 records
Expansion highlights6 records
Drummond Group competitors and assessment
Company assessmentDirect peers
- ICSA Labs: ICSA Labs is an independent testing and certification body for healthcare IT, IoT, and connected device security. It is a direct competitor to Drummond's ONC Health IT certification program and shares the third-party impartial testing and certification model with recognized lab accreditations.
- Coalfire: Coalfire is a cybersecurity advisory and assessment firm that operates as a PCI QSA, FedRAMP 3PAO, and HITRUST assessor, providing SOC 2, ISO 27001, HIPAA, and penetration testing services. It directly competes with Drummond across PCI DSS QSA, SOC 2, HIPAA, and penetration testing lines, and shares the regulatory-authorization-driven business model.
- Schellman & Co. Schellman is a top-tier independent attestation firm specializing in SOC 2, ISO 27001, HITRUST, and PCI DSS assessments. It is a direct competitor to Drummond's SOC 2 and ISO 27001 lines and shares the senior-led, multi-framework third-party attestation model.
- A-LIGN: A-LIGN is a cybersecurity and compliance firm providing SOC 2, ISO 27001, HITRUST, PCI DSS, and FedRAMP assessments with a tech-enabled delivery model. It directly competes with Drummond in SOC 2 and ISO 27001 while serving overlapping SaaS and healthcare technology customers.
- 360 Advanced: 360 Advanced is a cybersecurity compliance firm providing SOC 2, ISO 27001, HITRUST, PCI DSS, HIPAA, and penetration testing services. It is a direct competitor to Drummond across multiple frameworks with overlapping healthcare technology and financial services customer bases.
- BARR Advisory: BARR Advisory is a cybersecurity and compliance firm providing SOC 2, ISO 27001, HITRUST, PCI DSS, and FedRAMP assessments. It is a direct competitor in SOC 2 and ISO 27001 attestation, particularly serving SaaS and technology customers that overlap with Drummond's Technology & SaaS vertical.
- KirkpatrickPrice: KirkpatrickPrice is a cybersecurity audit and assessment firm offering SOC 2, ISO 27001, PCI DSS, HIPAA, and penetration testing services. It is a direct competitor in third-party attestation and penetration testing, with comparable senior-led engagement models.
- HITRUST: HITRUST operates the HITRUST CSF certification program and trains authorized external assessors to issue HITRUST certifications. It is a direct competitor to Drummond in healthcare security assurance, particularly for healthcare technology and payer customers that need both HITRUST and ONC certification.
- EHNAC: EHNAC is a non-profit standards development organization and accrediting body for health information exchange, electronic prescribing, and healthcare cybersecurity programs. It directly overlaps with Drummond's healthcare IT certification portfolio, particularly in payer and provider accreditation.
Broad incumbents
- UL LLC: UL is a global safety science company that operates testing, inspection, and certification services across dozens of industries including cybersecurity, healthcare, and industrial compliance. It is a broad incumbent offering comparable third-party certification and testing infrastructure at significantly larger scale than Drummond.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Drummond Group social profiles
Digital presenceDrummond Group compliance and trust
Trust signalCompliance6 records
Drummond Group financial estimates
Financial estimateRevenue estimate
Valuation estimate
Drummond Group leadership team
Management profileNumber of profiles
Profiles3 records
Drummond Group funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Drummond Group M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Drummond Group
What does Drummond Group do?
Drummond Group, LLC is an independent third-party testing and certification body that assesses software, systems, and processes against more than 20 regulatory and industry frameworks. Its portfolio spans ONC Health IT, FHIR, DEA EPCS/CSOS, ISO 27001, PCI DSS, SOC 2, NIST, HIPAA, GS1 GDSN, AS2/AS4, and ebMS programs, delivered through formal certifications, audits, penetration testing, vulnerability scanning, and code analysis engagements.
Is Drummond Group a public or private company?
Drummond Group is a private company. It is classified as family owned and is currently operating.
When was Drummond Group founded?
Drummond Group was founded in 1999. It employs 11 to 50 people.
Where is Drummond Group based?
Drummond Group is headquartered in Austin, United States, in the North America region.
How does Drummond Group make money?
One revenue line is on record: testing and Certification Services.
Who are Drummond Group's main competitors?
Direct peers on record are ICSA Labs, Coalfire, Schellman & Co., A-LIGN, 360 Advanced, BARR Advisory, KirkpatrickPrice, HITRUST and EHNAC. UL LLC is listed as a broad incumbent.
Does Drummond Group have an API?
No public API is recorded for Drummond Group.
What industry is Drummond Group in?
Drummond Group's product category is Compliance Testing and Certification Services. Its primary akta.pro industry code is BPAEAPAH, Audit Management, Controls & SOX Compliance, with a secondary code of BPAHAJAG, EHS Auditing, Inspections & Assurance. Its NAICS code is 813920 and its SIC code is 8734.