Compliance management for SMB & mid-market

Map once.
Comply everywhere.

Norma turns the policies, procedures and logs you already have into a living, audit-ready record across ISO 27001, SOC 2, CIS v8, CMMC and NIS2. AI reads and proposes. Your people verify. Auditors see only what is approved.

First gap assessment within the hour · no credit card · invite clients and auditors when you are ready

One evidence base forISO 27001:2022SOC 2CIS Controls v8.1CMMC Level 1NIS2
Product tour

See the whole product in eight minutes

A new customer goes from sign-up to an audit-ready workspace: real uploads, real AI reading, real reports. Nothing in the film is a mock-up.

Tap a chapter to jump straight to that part of the tour.

How it works

From a folder of documents to a defensible record

Four steps, and the first three happen on day one.

1

Upload what you have

Policies, SOPs, logs, reports, screenshots. Drag them in, forward them by email, or bulk-upload during onboarding.

2

Norma reads and proposes

Text is extracted, passages are matched to the controls of every framework you selected, and every excerpt is verified verbatim against the source.

3

People verify and decide

Approve or reject each excerpt on its control, set the status, approve the document as an organisational record. Every decision carries a name and a time.

4

Prove it to anyone

Readiness reports, the Statement of Applicability, evidence bundles and a read-only auditor package, generated from the same record.

Gap assessment

Know where you stand within the hour

The onboarding wizard takes a new workspace from frameworks and scoping to a first assessment: covered, partial and gaps per control, with Norma's narrative and top priorities, all from the documents you uploaded.

  • Every exclusion needs a justification and lands in the Statement of Applicability
  • Proposed statuses are applied by you, never automatically
  • Refine control by control from there
Gap assessment summary with Norma's narrative and proposed statuses
Control detail

Every control, every framework, one evidence base

The official text, a plain-language reading, status and scope, mapped controls in other frameworks, and the excerpts that support it. Verify an excerpt once and it counts everywhere the requirement recurs.

  • Policy, procedure and operational proof as separate layers
  • “Claimed” versus “proven”: implemented controls only count as proven with approved evidence
  • Create a remediation item straight from a gap
Control detail page with mapped controls and an AI-found excerpt awaiting verification
Evidence lifecycle

Documents that stay alive

Draft, in review, approved. New versions supersede the old one, reset the review and reopen accepted excerpts for re-verification. Point-in-time proof expires; policies come up for renewal.

  • Maker-checker approval, with overrides logged
  • Single-use review links for people outside the workspace
  • Signed, short-lived download links; nothing is ever public
Document page showing the AI reading, review state and located excerpts
Deliverables

Audit-ready on demand

Generate the readiness report, the Statement of Applicability as PDF and Excel, and a zipped evidence bundle per framework. Hand your auditor a package link instead of a login.

  • Only human-approved documents and attested excerpts, never AI content
  • Every open of an auditor package is logged
  • Same numbers as the dashboard, because they come from the same record
Reports page with generated deliverables and the auditor package form
Technology

Specialised AI, read twice, quoted verbatim

Automated assessment is only useful if an auditor can trust it. Every finding in Norma can be traced, checked and, if needed, disputed.

Automated assessment

Specialised AI, one job

Norma reads policies, procedures and logs and maps each passage to the controls of every framework you selected, at once. It classifies the document, extracts the effective date and proposes what each passage evidences.

Access ProvisioningSOP v2.1passage · p. 2Normareads · mapsISO 27001 · A.5.15SOC 2 · CC6.1CIS v8.1 · Control 6CMMC · AC.L1-3.1.1NIS2 · Art. 21(2)(i)
Second Reader verification

Every passage, read twice

Two independent AI models assess each passage. Their structured answers are compared by code, not by another model. Where they differ, a referee decides or the passage is read again, and the outcome is recorded, never hidden.

verification loop · re-read with the dispute attached · max 2×Passagefrom your documentTwo independent readersSpecialised compliance modeltuned to control mappingIndependent second modeldifferent provider · same schemaVerbatim checkevery excerpt in the sourceComparedeterministic · in codeVerificationreferee resolves disputesunclear → read againagreement + score recordedYour teamapproves · alwaysEvery reading, comparison and referee decision is stored with the finding. Nothing is applied automatically.
Hallucination-free evidence

Verbatim or nothing

An excerpt only exists in Norma if it is found character for character in your document. Quotes are checked against the source before anyone sees them, so the evidence in your record is always your own text, with the page it came from.

SOURCEInformation Security Policy v4p. 4Excerpt accepted“Access is granted on a least-privilege,need-to-know basis…”found character for character · p. 4Paraphrase discardednot in the source · never shown
Everything in one workspace

Built as a system, not a checklist

Each part feeds the others: evidence proves controls, controls roll into readiness, readiness becomes reports, and every step lands in the activity log.

01

Evidence library

Every document with owner, version history, effective date, freshness and review state. Point-in-time proof expires; policies renew on a cycle.

02

Cross-framework control library

Controls that overlap between frameworks share one evidence base. Implement once and it counts everywhere it applies.

03

Norma: verbatim excerpts

The assistant reads each document and proposes page-referenced excerpts, each verified word for word against the source before you see it.

04

Human verification

Every excerpt is approved or rejected by a person, with name and timestamp. Nothing is applied automatically.

05

Reports & auditor package

Readiness reports, the Statement of Applicability as PDF and Excel, zipped evidence bundles and a read-only auditor link.

06

Workforce attestation

Publish approved policies to employees; acknowledgements become living evidence for awareness controls without giving anyone workspace access.

07

Email intake

Each workspace has an inbox address. Attachments from allow-listed senders are filed as drafts and read automatically.

08

Risks, remediation, calendar

A scored risk register, remediation items with tasks and milestones, and recurring obligations with next-due dates, all rolled into next-best actions.

For consultancies and the companies they serve

Everyone sees exactly what they should

One workspace per client. Roles are enforced by the platform, not by convention.

Internal

Your team

Full access, settings, members and invitations. Consultancies switch between client workspaces from the sidebar.

Client

The customer's people

Upload, review and remediate inside their workspace. No member management, no other clients.

Auditor

Read-only, AI-free

Sees readiness, approved documents and attested excerpts. Never a suggestion, never a draft. Every view is logged.

Workforce

Employees

A personal link to a minimal attestation page: read the policy, acknowledge it. They never enter the workspace.

Principles

Norma proposes. People decide.

Verbatim or nothing

Every proposed excerpt is checked word for word against the document before anyone sees it. If it cannot be found in the source, it is discarded.

Nothing applied automatically

Statuses, approvals, risks entering the register, attestations: each one is a human action with a name and a timestamp in the activity log.

Auditors never see AI

Suggestions, drafts and assistant answers exist only for editors. The auditor package and auditor role show the approved record and nothing else.

Questions

Frequently asked

Which frameworks are supported?

ISO 27001:2022, SOC 2 (Trust Services Criteria), CIS Controls v8.1, CMMC Level 1 and the NIS2 Article 21(2) measures ship today. Frameworks are data, so additional regulations are added as packs, not as projects.

Does the AI make compliance decisions?

No. Norma reads documents, proposes excerpts and drafts assessments. A person verifies every excerpt, sets every control status and approves every document. Auditors never see AI-generated content.

How fast is the first gap assessment?

Typically within the hour: create a workspace, pick frameworks, scope the controls, upload what you already have, and the gap assessment is ready as soon as the reading finishes.

Do auditors need an account?

No. You share a read-only auditor package link that shows readiness, approved documents and human-attested excerpts, with short-lived downloads. Every open is logged.

Where is our data stored?

In a dedicated managed Postgres and private object storage with row-level isolation per workspace. Files are served only through signed, short-lived links. Regional hosting is available on request.

Is there a free trial?

Yes. Create a workspace, run your first gap assessment and invite your team. Talk to us when you are ready to bring clients or auditors on board.

See what your evidence already proves.

Create a workspace, upload what you have, and get your first gap assessment today.

Norma — Map once. Comply everywhere.