Skip to main content
NOVACompliance

Roadmap

Where NOVA is heading

An honest view of what NOVA does today and what is planned next. Planned items are labelled clearly and are never represented as operational.

Available now

13 items

Capability

Framework management

Available now

Activate the frameworks your organisation works towards, record scope, and map requirements once instead of maintaining parallel programmes.

Learn more

Capability

Controls and control testing

Available now

Define what each control is expected to do, who owns it, how often it is tested, and whether the last test passed.

Learn more

Capability

Evidence management

Available now

Collect evidence into governed storage, map it to the controls it supports, and have a person validate it before it counts.

Learn more

Capability

Policy management

Available now

Govern policy intent with versioning, approval routing and scheduled review, so the published policy is the approved one.

Learn more

Capability

Risk management

Available now

Record risks with owners, assess them consistently, assign treatment, and capture acceptance as an explicit decision.

Learn more

Capability

Reporting

Available now

Readiness and coverage reporting derived from live control and evidence records, not from a separately maintained status sheet.

Learn more

Capability

Trust Centre

Available now

Publish approved assurance information to customers and prospects without exposing the underlying confidential evidence.

Learn more

Capability

Auditor Portal

Available now

Give auditors and assessors scoped access to the evidence for an engagement, with requests and findings tracked in one workflow.

Learn more

Capability

NOVA AI Assistant

Available now

Assistance grounded in your governed workspace content: interpretation, drafting and gap identification, always for human approval.

Learn more

Framework

SOC 2

Available now

Service organisation reporting against the Trust Services Criteria, used widely in enterprise procurement.

Learn more

Framework

ISO/IEC 27001

Available now

The international standard for an information security management system, certified by an accredited body.

Learn more

Framework

Essential Eight

Available now

Eight prioritised mitigation strategies published by the Australian Cyber Security Centre, assessed by maturity level.

Learn more

Framework

ISO/IEC 42001

Available now

The management system standard for artificial intelligence, covering governance of AI systems across their lifecycle.

Learn more

Partly available

1 items

Capability

Asset governance

Partly available

Maintain the register of systems, services and data stores your controls depend on, and relate them to risks and evidence.

Learn more

Planned

3 items

Framework

NIST Cybersecurity Framework

Planned

A voluntary framework organising cybersecurity outcomes into functions, categories and subcategories.

Learn more

Framework

HIPAA

Planned

United States requirements for safeguarding protected health information held by covered entities and business associates.

Learn more

Framework

Australian Government Information Security Manual

Planned

A cybersecurity framework of controls published by the Australian Signals Directorate for government systems and their suppliers.

Learn more

The roadmap reflects current development intent, not a commitment. Timing and scope can change, and planned items are never represented as operational.

Have a framework or capability you would like prioritised? Tell us through the contact page.

See NOVA against your own compliance obligations

Start free to explore the workflow, or walk through your framework, evidence and reporting requirements with us.

NOVA supports the readiness decision. Final launch and risk decisions remain human decisions.