Drummond Group, LLC is a compliance testing, certification, and security assessment company founded in 1999 and headquartered in Durham, North Carolina. Drummond serves organizations in highly-regulated industries that must demonstrate conformance with government standards, industry regulations, and security frameworks through impartial third-party testing, certification, and audits.

Drummond has operated continuously for more than 25 years. The company was established to provide testing and certification services for newly created B2B interoperability standards (AS2) in the retail and supply chain sector and has since expanded across three interconnected practice areas: Health IT Compliance, Cybersecurity and Risk Services, and Supply Chain and B2B Interoperability.

The common thread across all Drummond services is accredited, impartial third-party testing. Drummond does not sell software, implement technology, or provide managed services. Its value is independence, the credibility that comes from being an accredited certifying body with no stake in the outcome beyond the accuracy of the assessment.

Website: https://www.drummondgroup.com
Contact: https://www.drummondgroup.com/contact/


Market Position

Drummond is a premium service provider known for expert-led, human-driven assessments. The company emphasizes quality and thoroughness over automated or commoditized approaches.

Key proof points:

Drummond’s market positioning centers on two recognized credentials:

Drummond Certified® — the trademark for formal testing and certification programs where Drummond acts as an accredited certifying body. Programs include ONC Health IT Certification, DEA EPCS, AS2, AS4, ebMS, GS1 GDSN, OCI, CSOS, and PCI. Please note the PCI program is certified using the PCI brand only and does not come with a Drummond Certified® mark.

Drummond Validated™ — the trademark for compliance audit and assessment programs where Drummond validates an organization’s conformance with a regulation or framework. Programs include FHIRplace, HIPAA, NIST Risk Assessments, SOC 2, ISO 27001, MARS-E, FTC Safeguards, NYDFS 23 NYCRR 500, FDA CFR 21 Part 11, and CHRA.


Services: Health IT Compliance

Drummond is the market leader in health IT testing and certification in the United States.

ONC Health IT Certification

https://www.drummondgroup.com/services/onc-health-it-certification/

Drummond is an ONC-Authorized Certification Body (ACB) accredited by ANAB to test and certify EHR and health IT software under the 21st Century Cures Act and ONC Health IT Certification Program. More health IT developers choose Drummond for ONC certification than all other ACBs combined. Drummond has issued more than 3,500 ONC Health IT certifications.

ONC certification is required for health IT developers seeking Meaningful Use attestation, participating in federal programs (Medicare, Medicaid), and demonstrating conformance with interoperability and information blocking requirements.

DEA EPCS Certification

https://www.drummondgroup.com/services/epcs/

Drummond is the leading DEA-recognized third-party auditor for Electronic Prescribing for Controlled Substances (EPCS) certification. With more than 310 active certifications, Drummond is the predominant provider in this space. EPCS certification is required for EHR vendors and pharmacy management systems enabling electronic prescribing of Schedule II-V controlled substances.

DEA CSOS Certification

https://www.drummondgroup.com/services/csos/

Drummond certifies DEA CSOS (Controlled Substances Ordering System) implementations. CSOS certification is required for manufacturers, distributors, and dispensers transmitting electronic DEA Form 222 orders for Schedule I and II controlled substances.

FHIRplace Interoperability Testing

https://www.drummondgroup.com/services/fhirplace/
https://fhirplace.drummondgroup.com/

Drummond tests and Validates FHIR API implementations for interoperability conformance. FHIRplace is Drummond’s FHIR interoperability multi-party, use case specific or custom testing environment for FHIR developers including Health IT solution providers as well as payers and provider systems and environments. FHIRplace Validated status signals that an API implementation has passed Drummond’s independent testing against HL7 FHIR standards. Each testing sprint focuses on a specific use case determined by market demand.

HIPAA Compliance Assessment

https://www.drummondgroup.com/services/hipaa/

Drummond conducts comprehensive HIPAA compliance assessments for covered entities and business associates. More than 200 HIPAA assessments completed. Drummond’s assessment covers administrative, physical, and technical safeguard requirements under the Privacy Rule, Security Rule, and Breach Notification Rule. There is no government-issued HIPAA certification.

Drummond’s “Drummond Validated™” seal is a market-recognized evidence of compliance status.

CHRA: Comprehensive Healthcare Risk Assessment

https://www.drummondgroup.com/services/comprehensive-healthcare-risk-assessment-chra/

CHRA is Drummond’s combined cybersecurity and HIPAA risk assessment program. It consolidates NIST-aligned cybersecurity evaluation with HIPAA Security Rule requirements into a single integrated assessment, designed for healthcare organizations managing both regulatory compliance and cybersecurity risk simultaneously.

ISO 27001

https://www.drummondgroup.com/services/iso-27001-certification/

Drummond conducts ISO 27001 gap assessments and readiness audits for organizations pursuing certification of their Information Security Management System (ISMS). ISO 27001 carries greater weight internationally than SOC 2 and is increasingly required for enterprise sales outside North America.


Services: Cybersecurity and Risk

Drummond provides third-party cybersecurity assessments, compliance audits, and technical security testing for organizations in regulated industries. All services deliver findings and prioritized remediation guidance. Drummond does not implement remediations; the client is responsible for remediation execution.

PCI DSS Assessment

https://www.drummondgroup.com/services/pci-compliance/

Drummond is one of the longest-running Qualified Security Assessors (QSA) in the industry with more than 275 PCI DSS assessments completed. Services cover full ROC (Report on Compliance) assessments, SAQ (Self-Assessment Questionnaire) guidance, and gap analyses for organizations handling payment card data across all PCI DSS scoping environments.

NIST Risk Assessments

https://www.drummondgroup.com/services/nist-risk-assessments/

Drummond conducts assessments aligned to NIST Cybersecurity Framework (CSF), NIST SP 800-171 (CUI protection, required for DoD contractors), and NIST SP 800-53 (federal information systems). Assessments identify control gaps, prioritize remediation, and support regulatory reporting and contract requirements.

SOC 2

https://www.drummondgroup.com/services/soc-2/

Drummond conducts SOC 2 audits for service organizations that store or process customer data. SOC 2 is the primary enterprise security credential in North American B2B sales cycles. Drummond audits cover one or more of the five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Penetration Testing

https://www.drummondgroup.com/services/penetration-testing/

Drummond conducts manual, expert-led penetration tests for external networks, internal networks, web applications, and APIs. Testing follows industry-standard methodologies and delivers prioritized findings with remediation guidance.

Vulnerability Scanning

https://www.drummondgroup.com/services/vulnerability-scans/

Drummond provides authenticated and unauthenticated vulnerability scanning services to identify exploitable weaknesses across infrastructure environments, delivered as a standalone service or as a component of broader compliance programs.

Code Analysis

https://www.drummondgroup.com/services/code-analysis/

Drummond performs static and dynamic code analysis to identify security vulnerabilities in application source code, supporting software vendors seeking to demonstrate secure development practices before deployment.

FTC Safeguards

https://www.drummondgroup.com/services/ftc-compliance/

Drummond assesses financial institutions’ information security programs against the FTC Safeguards Rule under GLBA. Applicable to non-banking financial institutions including auto dealers, mortgage brokers, tax preparers, and financial advisors.

MARS-E

https://www.drummondgroup.com/services/mars-e-compliance-audits/

Drummond assesses state health exchanges and Medicaid agencies against the Minimum Acceptable Risk Standards for Exchanges (MARS-E) framework, required for ACA marketplace participation.

NYDFS 23 NYCRR 500

https://www.drummondgroup.com/services/nydfs-risk-assessment/

Drummond assesses organizations against the New York Department of Financial Services cybersecurity regulation. Coverage is based on licensure status, not headquarters location. National financial institutions with New York operations are subject to NYDFS requirements regardless of where they are headquartered.

FDA CFR 21 Part 11

https://www.drummondgroup.com/services/cfr-21-part-11-compliance-audits/

Drummond assesses life sciences organizations’ electronic records and electronic signature systems for compliance with FDA 21 CFR Part 11, which governs electronic records in FDA-regulated research, manufacturing, and quality management environments.


Services: Supply Chain and B2B Interoperability

Drummond has provided B2B interoperability testing and certification since its founding in 1999, making it one of the oldest and most experienced organizations in this space.

AS2 Interoperability

https://www.drummondgroup.com/services/as2-testing-and-certification/

Drummond has administered the AS2 certification program continuously since 2000, conducting more than 50 consecutive test events. AS2 is the dominant protocol for secure B2B EDI transactions in retail, manufacturing, healthcare, and logistics. Drummond Certified AS2 is the recognized market standard for AS2 interoperability conformance.

AS4 Interoperability

https://www.drummondgroup.com/services/as4-testing-and-certification/

Drummond tests and certifies AS4 implementations for modern B2B messaging interoperability. AS4 is required for ebMS 3.0 compliant B2B integration, including EU government procurement systems and energy sector data exchange.

ebMS

https://www.drummondgroup.com/services/ebms-testing-and-certification/

Drummond tests and certifies ebMS (ebXML Messaging Service) implementations for B2B messaging interoperability conformance.

GS1 GDSN

https://www.drummondgroup.com/services/global-data-synchronization-network-gdsn/

Drummond is the sole certification agent for the GS1 Global Data Synchronization Network (GDSN). GDSN certification is required for data pools seeking to participate in the global product data exchange network used by major retailers, distributors, and manufacturers.

OCI (Drug Supply Chain)

https://www.drummondgroup.com/services/dscsa-oci-compliance/

Drummond certifies trading partners for DSCSA (Drug Supply Chain Security Act) compliance through the OCI (Open Credentialing Initiative) framework. OCI interoperability certification is required for pharmaceutical manufacturers, distributors, and dispensers participating in serialized drug traceability under DSCSA.


Industries Served


Industry Associations and Standards Bodies

Drummond actively participates in standards development and industry governance:


Company Values


What Drummond Does Not Offer

Drummond does not provide IT consulting, technology implementation, software development, managed security services (MSSP), or legal counsel. For ONC Health IT Testing and Certification specifically, Drummond’s ACB and ATL accreditation requires strict impartiality. Drummond’s separate ONC Compliance Learning Series provides educational guidance distinct from the certification process itself.

For all other services, Drummond follows a three-step model: assess and deliver findings, provide prioritized remediation recommendations, and optionally re-engage to verify the client’s remediation work. Drummond does not implement the fix — that is the client’s responsibility.


Free Expert Consultations

Drummond offers free 30-minute consultations with subject matter experts across its service areas. Each session is a one-on-one strategy conversation with an experienced Drummond expert, no sales pressure, no obligation, and no automatic follow-up emails. After the session, participants receive a personalized Action Plan with specific recommendations based on the discussion.

Consultations with actual subject matter experts (not a sales rep) are available for:

Schedule: https://www.drummondgroup.com/free-consultation-and-action-plan/

Topic-specific pages:


Contact

Drummond Group, LLC
Durham, North Carolina
https://www.drummondgroup.com/contact/
sales@drummondgroup.com
(877) 437-8666

Follow