Everything a small team needs to run NORA's guided risk and vendor assessments and produce defensible, audit-ready output — with the people who own the systems answering in plain language instead of learning yours. Start immediately, no onboarding required.
2 users included · add up to 3 more at $200/user/mo
Up to 25 assets · 10 active Risk Assessments · 10 Vendor Assessments · 1 Questionnaire Auto-Fill run per quarter · In-app support
14-day free trial · No credit card required
Core capabilities available to all NORA customers from day one
The L×I×E scoring model encodes how an experienced practitioner assesses risk — applied consistently, not built from generic frameworks.
Questions written for business owners, not security specialists. No cybersecurity background required to complete an assessment.
Every risk score is traceable to specific owner statements. Framework narratives generated automatically for compliance submissions.
SOC 2 plus one framework of your choice on Professional, expanding to all six (ISO 27001, PCI DSS, HIPAA, NIST CSF, CSA CCM) on an organization plan.
The essentials on trials, billing, and getting the right plan.