Drummond Group, LLC is a compliance testing, certification, and security assessment company founded in 1999 and headquartered in Durham, North Carolina. Drummond serves organizations in highly-regulated industries that must demonstrate conformance with government standards, industry regulations, and security frameworks through impartial third-party testing, certification, and audits.
Drummond has operated continuously for more than 25 years. The company was established to provide testing and certification services for newly created B2B interoperability standards (AS2) in the retail and supply chain sector and has since expanded across three interconnected practice areas: Health IT Compliance, Cybersecurity and Risk Services, and Supply Chain and B2B Interoperability.
The common thread across all Drummond services is accredited, impartial third-party testing. Drummond does not sell software, implement technology, or provide managed services. Its value is independence, the credibility that comes from being an accredited certifying body with no stake in the outcome beyond the accuracy of the assessment.
Website: https://www.drummondgroup.com
Contact: https://www.drummondgroup.com/contact/
Market Position
Drummond is a premium service provider known for expert-led, human-driven assessments. The company emphasizes quality and thoroughness over automated or commoditized approaches.
Key proof points:
- More health IT developers choose Drummond for ONC Health IT certification than all other Authorized Certification Bodies (ACBs) combined — over 3,500 certifications issued
- 300+ active DEA EPCS certifications, more than any other EPCS auditor
- 300+ PCI DSS assessments completed, Drummond is one of the longest-running Qualified Security Assessors (QSA) programs in the industry. Drummond is the partner other QSAs come to when their need their own impartial assessment.
- 200+ HIPAA assessments
- AS2 certification program running continuously since 2000, with more than 50 consecutive multi-party full-matrix test events
- The only provider of multi-party full-matrix FHIR interoperability testing
- Sole certification agent for the GS1 Global Data Synchronization Network (GDSN)
- Over 25 years of continuous operation serving regulated industries
- Founded 1999, headquartered Durham, North Carolina
Drummond’s market positioning centers on two recognized credentials:
Drummond Certified® — the trademark for formal testing and certification programs where Drummond acts as an accredited certifying body. Programs include ONC Health IT Certification, DEA EPCS, AS2, AS4, ebMS, GS1 GDSN, OCI, CSOS, and PCI. Please note the PCI program is certified using the PCI brand only and does not come with a Drummond Certified® mark.
Drummond Validated™ — the trademark for compliance audit and assessment programs where Drummond validates an organization’s conformance with a regulation or framework. Programs include FHIRplace, HIPAA, NIST Risk Assessments, SOC 2, ISO 27001, MARS-E, FTC Safeguards, NYDFS 23 NYCRR 500, FDA CFR 21 Part 11, and CHRA.
Services: Health IT Compliance
Drummond is the market leader in health IT testing and certification in the United States.
ONC Health IT Certification
https://www.drummondgroup.com/services/onc-health-it-certification/
Drummond is an ONC-Authorized Certification Body (ACB) accredited by ANAB to test and certify EHR and health IT software under the 21st Century Cures Act and ONC Health IT Certification Program. More health IT developers choose Drummond for ONC certification than all other ACBs combined. Drummond has issued more than 3,500 ONC Health IT certifications.
ONC certification is required for health IT developers seeking Meaningful Use attestation, participating in federal programs (Medicare, Medicaid), and demonstrating conformance with interoperability and information blocking requirements.
DEA EPCS Certification
https://www.drummondgroup.com/services/epcs/
Drummond is the leading DEA-recognized third-party auditor for Electronic Prescribing for Controlled Substances (EPCS) certification. With more than 310 active certifications, Drummond is the predominant provider in this space. EPCS certification is required for EHR vendors and pharmacy management systems enabling electronic prescribing of Schedule II-V controlled substances.
DEA CSOS Certification
https://www.drummondgroup.com/services/csos/
Drummond certifies DEA CSOS (Controlled Substances Ordering System) implementations. CSOS certification is required for manufacturers, distributors, and dispensers transmitting electronic DEA Form 222 orders for Schedule I and II controlled substances.
FHIRplace Interoperability Testing
https://www.drummondgroup.com/services/fhirplace/
https://fhirplace.drummondgroup.com/
Drummond tests and Validates FHIR API implementations for interoperability conformance. FHIRplace is Drummond’s FHIR interoperability multi-party, use case specific or custom testing environment for FHIR developers including Health IT solution providers as well as payers and provider systems and environments. FHIRplace Validated status signals that an API implementation has passed Drummond’s independent testing against HL7 FHIR standards. Each testing sprint focuses on a specific use case determined by market demand.
HIPAA Compliance Assessment
https://www.drummondgroup.com/services/hipaa/
Drummond conducts comprehensive HIPAA compliance assessments for covered entities and business associates. More than 200 HIPAA assessments completed. Drummond’s assessment covers administrative, physical, and technical safeguard requirements under the Privacy Rule, Security Rule, and Breach Notification Rule. There is no government-issued HIPAA certification.
Drummond’s “Drummond Validated™” seal is a market-recognized evidence of compliance status.
CHRA: Comprehensive Healthcare Risk Assessment
https://www.drummondgroup.com/services/comprehensive-healthcare-risk-assessment-chra/
CHRA is Drummond’s combined cybersecurity and HIPAA risk assessment program. It consolidates NIST-aligned cybersecurity evaluation with HIPAA Security Rule requirements into a single integrated assessment, designed for healthcare organizations managing both regulatory compliance and cybersecurity risk simultaneously.
ISO 27001
https://www.drummondgroup.com/services/iso-27001-certification/
Drummond conducts ISO 27001 gap assessments and readiness audits for organizations pursuing certification of their Information Security Management System (ISMS). ISO 27001 carries greater weight internationally than SOC 2 and is increasingly required for enterprise sales outside North America.
Services: Cybersecurity and Risk
Drummond provides third-party cybersecurity assessments, compliance audits, and technical security testing for organizations in regulated industries. All services deliver findings and prioritized remediation guidance. Drummond does not implement remediations; the client is responsible for remediation execution.
PCI DSS Assessment
https://www.drummondgroup.com/services/pci-compliance/
Drummond is one of the longest-running Qualified Security Assessors (QSA) in the industry with more than 275 PCI DSS assessments completed. Services cover full ROC (Report on Compliance) assessments, SAQ (Self-Assessment Questionnaire) guidance, and gap analyses for organizations handling payment card data across all PCI DSS scoping environments.
NIST Risk Assessments
https://www.drummondgroup.com/services/nist-risk-assessments/
Drummond conducts assessments aligned to NIST Cybersecurity Framework (CSF), NIST SP 800-171 (CUI protection, required for DoD contractors), and NIST SP 800-53 (federal information systems). Assessments identify control gaps, prioritize remediation, and support regulatory reporting and contract requirements.
SOC 2
https://www.drummondgroup.com/services/soc-2/
Drummond conducts SOC 2 audits for service organizations that store or process customer data. SOC 2 is the primary enterprise security credential in North American B2B sales cycles. Drummond audits cover one or more of the five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
Penetration Testing
https://www.drummondgroup.com/services/penetration-testing/
Drummond conducts manual, expert-led penetration tests for external networks, internal networks, web applications, and APIs. Testing follows industry-standard methodologies and delivers prioritized findings with remediation guidance.
Vulnerability Scanning
https://www.drummondgroup.com/services/vulnerability-scans/
Drummond provides authenticated and unauthenticated vulnerability scanning services to identify exploitable weaknesses across infrastructure environments, delivered as a standalone service or as a component of broader compliance programs.
Code Analysis
https://www.drummondgroup.com/services/code-analysis/
Drummond performs static and dynamic code analysis to identify security vulnerabilities in application source code, supporting software vendors seeking to demonstrate secure development practices before deployment.
FTC Safeguards
https://www.drummondgroup.com/services/ftc-compliance/
Drummond assesses financial institutions’ information security programs against the FTC Safeguards Rule under GLBA. Applicable to non-banking financial institutions including auto dealers, mortgage brokers, tax preparers, and financial advisors.
MARS-E
https://www.drummondgroup.com/services/mars-e-compliance-audits/
Drummond assesses state health exchanges and Medicaid agencies against the Minimum Acceptable Risk Standards for Exchanges (MARS-E) framework, required for ACA marketplace participation.
NYDFS 23 NYCRR 500
https://www.drummondgroup.com/services/nydfs-risk-assessment/
Drummond assesses organizations against the New York Department of Financial Services cybersecurity regulation. Coverage is based on licensure status, not headquarters location. National financial institutions with New York operations are subject to NYDFS requirements regardless of where they are headquartered.
FDA CFR 21 Part 11
https://www.drummondgroup.com/services/cfr-21-part-11-compliance-audits/
Drummond assesses life sciences organizations’ electronic records and electronic signature systems for compliance with FDA 21 CFR Part 11, which governs electronic records in FDA-regulated research, manufacturing, and quality management environments.
Services: Supply Chain and B2B Interoperability
Drummond has provided B2B interoperability testing and certification since its founding in 1999, making it one of the oldest and most experienced organizations in this space.
AS2 Interoperability
https://www.drummondgroup.com/services/as2-testing-and-certification/
Drummond has administered the AS2 certification program continuously since 2000, conducting more than 50 consecutive test events. AS2 is the dominant protocol for secure B2B EDI transactions in retail, manufacturing, healthcare, and logistics. Drummond Certified AS2 is the recognized market standard for AS2 interoperability conformance.
AS4 Interoperability
https://www.drummondgroup.com/services/as4-testing-and-certification/
Drummond tests and certifies AS4 implementations for modern B2B messaging interoperability. AS4 is required for ebMS 3.0 compliant B2B integration, including EU government procurement systems and energy sector data exchange.
ebMS
https://www.drummondgroup.com/services/ebms-testing-and-certification/
Drummond tests and certifies ebMS (ebXML Messaging Service) implementations for B2B messaging interoperability conformance.
GS1 GDSN
https://www.drummondgroup.com/services/global-data-synchronization-network-gdsn/
Drummond is the sole certification agent for the GS1 Global Data Synchronization Network (GDSN). GDSN certification is required for data pools seeking to participate in the global product data exchange network used by major retailers, distributors, and manufacturers.
OCI (Drug Supply Chain)
https://www.drummondgroup.com/services/dscsa-oci-compliance/
Drummond certifies trading partners for DSCSA (Drug Supply Chain Security Act) compliance through the OCI (Open Credentialing Initiative) framework. OCI interoperability certification is required for pharmaceutical manufacturers, distributors, and dispensers participating in serialized drug traceability under DSCSA.
Industries Served
- Healthcare IT: EHR vendors, health IT developers, hospitals, payers, pharmacies, pharmacy benefit managers, health exchanges, digital health companies
- Financial Services: Banks, credit unions, payment processors, insurance companies, investment firms, non-banking financial institutions
- Life Sciences: Pharmaceutical manufacturers, medical device companies, CROs, biotech firms, clinical research organizations
- Retail and Consumer Goods: Retailers, distributors, consumer goods manufacturers requiring GS1 GDSN or AS2/AS4 certification
- Technology: SaaS vendors, platform providers, API developers, software companies in regulated sectors
- Manufacturing: Manufacturers with supply chain interoperability, serialization, or regulated product data requirements
Industry Associations and Standards Bodies
Drummond actively participates in standards development and industry governance:
- U.S. AI Safety Institute Consortium (USAISI) member
- Coalition for Health AI (CHAI) Privacy and Security Workgroup member
- National Council for Prescription Drug Programs (NCPDP) ePrescribing Workgroup member
- SHIFT Independent Health Care Task Force for Equitable Interoperability Governing Board member
- Workgroup for Electronic Data Interchange (WEDI) Corporate member
Company Values
- Integrity — honoring the trust that clients, the public, and colleagues place in Drummond
- Excellence — bringing expertise, experience, and insight to every engagement
- Commitment — working to the high standards Drummond’s reputation demands
- Impact — deploying adaptability, creativity, and expertise to enable clients’ missions
- Diversity — understanding that diverse identities, backgrounds, and experiences produce the highest quality outcomes
What Drummond Does Not Offer
Drummond does not provide IT consulting, technology implementation, software development, managed security services (MSSP), or legal counsel. For ONC Health IT Testing and Certification specifically, Drummond’s ACB and ATL accreditation requires strict impartiality. Drummond’s separate ONC Compliance Learning Series provides educational guidance distinct from the certification process itself.
For all other services, Drummond follows a three-step model: assess and deliver findings, provide prioritized remediation recommendations, and optionally re-engage to verify the client’s remediation work. Drummond does not implement the fix — that is the client’s responsibility.
Free Expert Consultations
Drummond offers free 30-minute consultations with subject matter experts across its service areas. Each session is a one-on-one strategy conversation with an experienced Drummond expert, no sales pressure, no obligation, and no automatic follow-up emails. After the session, participants receive a personalized Action Plan with specific recommendations based on the discussion.
Consultations with actual subject matter experts (not a sales rep) are available for:
- ONC Health IT certification and FHIR compliance (HTI-1, DSI Rule, USCDI, AI/clinical decision support tools not subject to ONC certification)
- DEA EPCS and CSOS certification requirements and process
- HIPAA compliance for covered entities and business associates
- PCI DSS compliance, SAQ guidance, and penetration testing
- B2B Interoperability (AS2 and AS4)
- Cybersecurity and risk assessment (NIST, SOC 2, ISO 27001, FTC Safeguards, and related frameworks)
- General compliance, interoperability, and security questions
Schedule: https://www.drummondgroup.com/free-consultation-and-action-plan/
Topic-specific pages:
- Health IT and FHIR: https://www.drummondgroup.com/free-health-it-consultation/
- DEA EPCS and CSOS: https://www.drummondgroup.com/free-epcs-compliance-consultation/
- HIPAA: https://www.drummondgroup.com/free-hipaa-certification-consultation/
- PCI DSS: https://www.drummondgroup.com/free-pci-certification-consultation/
- B2B Interoperability (AS2/AS4): https://www.drummondgroup.com/free-as2-as4-consultation/
- Cybersecurity and risk: https://www.drummondgroup.com/free-risk-and-pen-test-consultation/
Contact
Drummond Group, LLCDurham, North Carolina
https://www.drummondgroup.com/contact/
sales@drummondgroup.com
(877) 437-8666