NORA
Pricing

Simple, Honest Pricing

Start solo, scale to your whole organization. Every plan runs NORA's guided assessments and produces defensible, audit-ready output — you add depth, scale, and enterprise controls as you grow.

Professional
Monthly
Annual
$600/mo

Everything a small team needs to run NORA's guided risk and vendor assessments and produce defensible, audit-ready output — with the people who own the systems answering in plain language instead of learning yours. Start immediately, no onboarding required.

2 users included · add up to 3 more at $200/user/mo

For System Owners
  • See the systems and vendors you own, in one place
  • Plain-English questions — no security background, no risk vocabulary
  • Your answers are the assessment — nothing to translate, nothing to submit
For the Security Team
  • Scope and run guided risk and vendor assessments across the portfolio
  • L×I×E scoring — consistent, traceable, defensible after the fact
  • Threat intelligence matched to the systems you actually run
  • AI exposure surfaced inside the assessment, not as a separate exercise
  • Risk heatmap and portfolio dashboard
  • Answer inbound security questionnaires from work you've already done
  • SOC 2 plus one framework of your choice, mapped from those same answers
  • Audit-ready PDF reports

Up to 25 assets · 10 active Risk Assessments · 10 Vendor Assessments · 1 Questionnaire Auto-Fill run per quarter · In-app support

14-day free trial · No credit card required

For Your Organization

NORA, running across your whole program

At organization scale NORA is working for three groups at once — the owners who answer for what they run, the security team running the program, and the executives who have to report on it.

For System Owners
  • Coverage across every business unit — each owner answers for what they actually run
  • Business Justification — owners say why we have this, in their own words
  • Remediation tasks land with the owner who can fix them, not in a security backlog
For the Security Team
  • Remediation tracking and the Advisor — every finding becomes an owned task with a recommended fix
  • A sequenced remediation roadmap you can hand to leadership
  • All six frameworks — ISO 27001, PCI DSS, HIPAA, NIST CSF and CSA CCM alongside SOC 2
  • Questionnaires when the deal needs them, not once a quarter
For the Executive Team
  • Executive and portfolio analytics — risk across the program, not asset by asset
  • Organizational Security Profile — the security controls you've invested in, and how they're actually holding up across your systems

Scales across teams, assets and business units · SSO/SAML, audit log, network controls and integrations · SLA-backed uptime · dedicated success manager and guided onboarding

Priced to the scope of your program · volume and multi-year options available.

Every Plan Includes

Core capabilities available to all NORA customers from day one

Practitioner-Built Methodology

The L×I×E scoring model encodes how an experienced practitioner assesses risk — applied consistently, not built from generic frameworks.

Plain-English Guided Scoring

Questions written for business owners, not security specialists. No cybersecurity background required to complete an assessment.

Audit-Ready Output

Every risk score is traceable to specific owner statements. Framework narratives generated automatically for compliance submissions.

Framework Compliance Mapping

SOC 2 plus one framework of your choice on Professional, expanding to all six (ISO 27001, PCI DSS, HIPAA, NIST CSF, CSA CCM) on an organization plan.

Common Questions

The essentials on trials, billing, and getting the right plan.

Not sure which plan is right for you?

Book a 30-minute call and we'll walk you through NORA's capabilities and help you find the right fit for your program.