Maps defined security controls and obligations across frameworks — ISO 27001, SOC 2, RBI, DPDP — to a single assessment workflow.
What you claim to control, proven the way an auditor would demand it.
NORMA™ — Normative Obligation, Risk & Mapping Assessment — is the evidence-assurance engine behind RixControl™, turning your security controls and compliance obligations into evidence-backed assurance across the CNIS™ platform before it ever reaches a dashboard.
Assessment that runs, not a spreadsheet that decorates
Control mapping builds a hypothesis about what's actually covered — pulled from policy documents and evidence gathered across the CNIS™ platform. Evidence correlation, run by the NORMA™ engine, confirms or rejects sufficiency, scoped to the framework in question.
Every control that survives assessment gets a source, a confidence weight, and a place in the evidence graph — never a bare pass/fail with nothing behind it.
NORMA™ speaks the same language as the rest of CNIS™
Every module — NORMA™ included — moves evidence through the same three-stage framework before it reaches a decision-maker.
Signals
Deviations across your control landscape — new obligations, expired evidence, unresolved exceptions.
→Scenarios
Signals resolved into the single most material control gap — not a flat checklist of unrelated exceptions.
→Intelligence
A structured CRI result your team — and the rest of CNIS™ — can act on directly.
// SIGNALS → SCENARIOS → INTELLIGENCE — the SSI framework CyberNeurix Pulse runs across cybersecurity and neurotechnology alike.
Can we actually prove the controls we say we have?
Not another GRC platform. NORMA™ maps your defined controls and obligations to an assessment workflow, evaluates the evidence behind them, and hands your team a structured result instead of a compliance checklist.
Shows an evidence-oriented view of control assessment, not a generic pass/fail with no backing.
Surfaces exceptions and areas lacking sufficient evidence across the assessment.
Outputs a structured control-assessment result that flows into the wider CNIS™ decision context.
Control existence and control evidence are not the same thing
- Auditors and security leaders need to understand the evidentiary basis of a control assessment, not just that a control exists on paper.
- Organizations manage multiple obligations across frameworks and need a common assessment view.
- Evidence often lives scattered across the platform and sits disconnected from the compliance record it should be informing.
- Security-control evidence as the primary product object, not a checkbox.
- Explicit separation between what is known and what lacks sufficient evidence.
- Useful to security and GRC stakeholders without becoming a full enterprise GRC replacement.
- Designed to contribute a control view to the wider CNIS™ picture.
CRI — an honest band, not false precision
This page describes what the band means and how teams read it. What sits behind it — the obligation mapping, evidence-class weighting, and calibration — is deliberately not published.
A band with its evidence tier alongside it, so a control assured by human attestation never presents like one confirmed by a system.
A clear separation between what NORMA™ can evidence and what your team signs off. Structured for an auditor, a reviewer, and the next engine in the chain.
Where NORMA™ sits, and what it defends
A capability-level view based on public 2026 market sources. Not a claim of feature parity with every platform listed — a statement of category boundary.
| Market alternative | Category | Typical strength | CNIS™ distinction |
|---|---|---|---|
| ServiceNow IRM / GRC | Enterprise GRC / IRM | Broad enterprise governance, risk and compliance workflows. | NORMA™ is positioned around evidence-backed security control assessment rather than attempting to replace a broad enterprise GRC system. |
| RSA Archer | Enterprise GRC | Enterprise risk, compliance and governance management. | NORMA™ is more focused on the evidentiary condition of security controls and obligations. |
| MetricStream | GRC / compliance | Large-scale governance, risk and compliance management. | NORMA™ emphasizes assessment evidence and security-control context rather than broad enterprise workflow coverage. |
| Vanta / Drata | Compliance automation | Automated evidence collection and audit-readiness workflows. | NORMA™'s product boundary is security-control assessment — not marketed as a universal audit automation platform. |
Market landscape reviewed: CIOPages GRC buyer guide (June 2026); ComplianceStack 2026 compliance software comparison.
Assure the evidence. Don't become the GRC system of record.
GRC platforms are good at holding policy and bad at proving it. NORMA™ does not try to replace the register — it attaches an evidence tier to each claim in it, so the difference between a machine-verified control and an attested one stops being invisible.
Where NORMA™ competes
- Security-control evidence as the primary product object, not a checkbox.
- Explicit separation between what is known and what lacks sufficient evidence.
- Useful to security and GRC stakeholders without becoming a full enterprise GRC replacement.
- Designed to contribute a control view to the wider CNIS™ picture.
Where it deliberately doesn't
Do not position this product as a universal replacement for SIEM, enterprise GRC, global threat intelligence, vulnerability management, or broad enterprise risk software.
The strategy is specialization plus composition. NORMA™ answers whether a control can be proven; VERITA™ answers whether it is still running. Neither pretends to be the other.
Where NORMA™ sits in the pipeline
What assurance teams actually do with it
Establish an evidence-based baseline for control & obligation assessment.
Pull the evidence trail behind a specific obligation before the auditor asks for it.
Present control assurance with its evidence tier visible, rather than a single reassuring percentage.
Give VERITA™ the control set to watch, and give INFERA™ the assurance picture to reason over.
Bought after the first audit finding nobody saw coming
The buyer has a control register that says everything is fine and an auditor who disagreed. What they need is to know which of their green controls are green because someone typed it, and which are green because a system confirmed it.
Can RixControl™ give us a clearer view of our control & obligation assessment position?
Can we see which controls are machine-verified and which are only attested?
Will a control with thin evidence ever present as more assured than it is?
Can we scope this to one framework or business unit before expanding?
Know what you can prove, not just what you claim
A live demonstration walks through a realistic input, the RixControl™ workflow, the resulting CRI, supporting evidence, and the decision it supports.