In NORA, your software and SaaS are assets, assessed in the Risk model. A vendor is different: it's an outside organization — a consultancy, managed service provider, staffing partner, or specialist firm — that you engage and that touches your systems or data. NORA assesses those relationships: how much access the firm has, how well they protect what they can reach, and whether relying on them is a risk you can defend. This isn't third-party software risk management — it's about the people and firms behind the badge.
A vendor's rating only means something relative to what it can touch. NORA's Asset–Vendor Network Map puts each firm at the center and shows the systems it can reach, colored by each system's own risk — then flags the combinations that matter: a middling firm with a path into a critical system. That's the exposure a score alone will hide, and one of the most common ways attackers actually get in. The map is built from the access your team records for each firm — NORA never scans your systems.
A Medium-rated firm with access to a Critical system is a finding — not a footnote.
NORA evaluates each firm across eight risk domains — the questions that actually determine whether you can rely on an outside organization with access to your business.
How the firm protects the data you share with them.
Who at the firm can reach your systems, and how that access is controlled and revoked.
Whether the firm can detect, contain, and tell you about a breach on their side.
Whether the firm can keep operating — and keep you operating — through disruption.
Whether the right protections and obligations are actually written into your agreement.
The firms your firm relies on, and the risk they pass through to you.
How the firm finds and fixes weaknesses in what they run.
How the firm secures the physical places your data and work live.
You don't send a questionnaire and wait for the vendor to return it. NORA guides the person inside your organization who owns the relationship through a short, plain-English conversation — usually a confident score in three or four questions per domain — tailored to the kind of firm being assessed. No security background required, and where the owner isn't sure, that uncertainty becomes a documented exposure instead of a blank.
Like everywhere in NORA, every vendor score traces back to the owner's own answers — no black-box rating. Uncertainty is captured, not hidden. Each domain carries a decision and an owner. And the network map keeps every score in context, so "we assessed the vendor" becomes "we know exactly what this firm can reach, and what we decided about it."