Roadmap
Where NOVA is heading
An honest view of what NOVA does today and what is planned next. Planned items are labelled clearly and are never represented as operational.
Available now
13 items
Capability
Framework management
Activate the frameworks your organisation works towards, record scope, and map requirements once instead of maintaining parallel programmes.
Learn moreCapability
Controls and control testing
Define what each control is expected to do, who owns it, how often it is tested, and whether the last test passed.
Learn moreCapability
Evidence management
Collect evidence into governed storage, map it to the controls it supports, and have a person validate it before it counts.
Learn moreCapability
Policy management
Govern policy intent with versioning, approval routing and scheduled review, so the published policy is the approved one.
Learn moreCapability
Risk management
Record risks with owners, assess them consistently, assign treatment, and capture acceptance as an explicit decision.
Learn moreCapability
Reporting
Readiness and coverage reporting derived from live control and evidence records, not from a separately maintained status sheet.
Learn moreCapability
Trust Centre
Publish approved assurance information to customers and prospects without exposing the underlying confidential evidence.
Learn moreCapability
Auditor Portal
Give auditors and assessors scoped access to the evidence for an engagement, with requests and findings tracked in one workflow.
Learn moreCapability
NOVA AI Assistant
Assistance grounded in your governed workspace content: interpretation, drafting and gap identification, always for human approval.
Learn moreFramework
SOC 2
Service organisation reporting against the Trust Services Criteria, used widely in enterprise procurement.
Learn moreFramework
ISO/IEC 27001
The international standard for an information security management system, certified by an accredited body.
Learn moreFramework
Essential Eight
Eight prioritised mitigation strategies published by the Australian Cyber Security Centre, assessed by maturity level.
Learn moreFramework
ISO/IEC 42001
The management system standard for artificial intelligence, covering governance of AI systems across their lifecycle.
Learn morePartly available
1 items
Capability
Asset governance
Maintain the register of systems, services and data stores your controls depend on, and relate them to risks and evidence.
Learn morePlanned
3 items
Framework
NIST Cybersecurity Framework
A voluntary framework organising cybersecurity outcomes into functions, categories and subcategories.
Learn moreFramework
HIPAA
United States requirements for safeguarding protected health information held by covered entities and business associates.
Learn moreFramework
Australian Government Information Security Manual
A cybersecurity framework of controls published by the Australian Signals Directorate for government systems and their suppliers.
Learn moreThe roadmap reflects current development intent, not a commitment. Timing and scope can change, and planned items are never represented as operational.
Have a framework or capability you would like prioritised? Tell us through the contact page.
See NOVA against your own compliance obligations
Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.
NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.