Norma turns the policies, procedures and logs you already have into a living, audit-ready record across ISO 27001, SOC 2, CIS v8, CMMC and NIS2. AI reads and proposes. Your people verify. Auditors see only what is approved.
A new customer goes from sign-up to an audit-ready workspace: real uploads, real AI reading, real reports. Nothing in the film is a mock-up.
Four steps, and the first three happen on day one.
Policies, SOPs, logs, reports, screenshots. Drag them in, forward them by email, or bulk-upload during onboarding.
Text is extracted, passages are matched to the controls of every framework you selected, and every excerpt is verified verbatim against the source.
Approve or reject each excerpt on its control, set the status, approve the document as an organisational record. Every decision carries a name and a time.
Readiness reports, the Statement of Applicability, evidence bundles and a read-only auditor package, generated from the same record.
The onboarding wizard takes a new workspace from frameworks and scoping to a first assessment: covered, partial and gaps per control, with Norma's narrative and top priorities, all from the documents you uploaded.

The official text, a plain-language reading, status and scope, mapped controls in other frameworks, and the excerpts that support it. Verify an excerpt once and it counts everywhere the requirement recurs.

Draft, in review, approved. New versions supersede the old one, reset the review and reopen accepted excerpts for re-verification. Point-in-time proof expires; policies come up for renewal.

Generate the readiness report, the Statement of Applicability as PDF and Excel, and a zipped evidence bundle per framework. Hand your auditor a package link instead of a login.

Automated assessment is only useful if an auditor can trust it. Every finding in Norma can be traced, checked and, if needed, disputed.
Norma reads policies, procedures and logs and maps each passage to the controls of every framework you selected, at once. It classifies the document, extracts the effective date and proposes what each passage evidences.
Two independent AI models assess each passage. Their structured answers are compared by code, not by another model. Where they differ, a referee decides or the passage is read again, and the outcome is recorded, never hidden.
An excerpt only exists in Norma if it is found character for character in your document. Quotes are checked against the source before anyone sees them, so the evidence in your record is always your own text, with the page it came from.
Each part feeds the others: evidence proves controls, controls roll into readiness, readiness becomes reports, and every step lands in the activity log.
Every document with owner, version history, effective date, freshness and review state. Point-in-time proof expires; policies renew on a cycle.
Controls that overlap between frameworks share one evidence base. Implement once and it counts everywhere it applies.
The assistant reads each document and proposes page-referenced excerpts, each verified word for word against the source before you see it.
Every excerpt is approved or rejected by a person, with name and timestamp. Nothing is applied automatically.
Readiness reports, the Statement of Applicability as PDF and Excel, zipped evidence bundles and a read-only auditor link.
Publish approved policies to employees; acknowledgements become living evidence for awareness controls without giving anyone workspace access.
Each workspace has an inbox address. Attachments from allow-listed senders are filed as drafts and read automatically.
A scored risk register, remediation items with tasks and milestones, and recurring obligations with next-due dates, all rolled into next-best actions.
One workspace per client. Roles are enforced by the platform, not by convention.
Full access, settings, members and invitations. Consultancies switch between client workspaces from the sidebar.
Upload, review and remediate inside their workspace. No member management, no other clients.
Sees readiness, approved documents and attested excerpts. Never a suggestion, never a draft. Every view is logged.
A personal link to a minimal attestation page: read the policy, acknowledge it. They never enter the workspace.
Every proposed excerpt is checked word for word against the document before anyone sees it. If it cannot be found in the source, it is discarded.
Statuses, approvals, risks entering the register, attestations: each one is a human action with a name and a timestamp in the activity log.
Suggestions, drafts and assistant answers exist only for editors. The auditor package and auditor role show the approved record and nothing else.
ISO 27001:2022, SOC 2 (Trust Services Criteria), CIS Controls v8.1, CMMC Level 1 and the NIS2 Article 21(2) measures ship today. Frameworks are data, so additional regulations are added as packs, not as projects.
No. Norma reads documents, proposes excerpts and drafts assessments. A person verifies every excerpt, sets every control status and approves every document. Auditors never see AI-generated content.
Typically within the hour: create a workspace, pick frameworks, scope the controls, upload what you already have, and the gap assessment is ready as soon as the reading finishes.
No. You share a read-only auditor package link that shows readiness, approved documents and human-attested excerpts, with short-lived downloads. Every open is logged.
In a dedicated managed Postgres and private object storage with row-level isolation per workspace. Files are served only through signed, short-lived links. Regional hosting is available on request.
Yes. Create a workspace, run your first gap assessment and invite your team. Talk to us when you are ready to bring clients or auditors on board.
Create a workspace, upload what you have, and get your first gap assessment today.