# Norma

> EU compliance methodology and templates. Use this skill when the user asks about EU AI Act, ISO 42001 (AIMS), ISO 27001 (ISMS), ISO 22301 (BCMS), ISO 27701 (PIMS), NIS2 Directive, DORA, CRA (Cyber Resilience Act), GDPR-adjacent topics, or any combination — gap analysis, control mapping, policy/procedure drafting, risk assessment, conformity assessment, AI risk classification, third-party assessment, business continuity, privacy impact assessment, incident response, vulnerability disclosure, SBOM, or generic "compliance" requests with no specific framework named. Also use for cross-framework mapping (NIST AI RMF, ENISA, GDPR Art. 30 RoPA), high-risk AI Annex III classification, Statement of Applicability authoring, or template selection across the 8 supported frameworks. Provides 32 curated templates and 8 framework methodologies adapted from the NORMA corpus by Kynosure.

## Facts
- Page: https://tashan.sh/capability/skill-kynosure-ai-norma
- tashan id: skill:kynosure-ai/norma
- Source: https://github.com/kynosure-ai/norma-claude-skill
- Type: skill
- Category: security
- tashan score: not scored (catalogued only — too little public evidence)
- Adoption: 9.0
- Upkeep: 51.0
- Freshness: 72.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- GitHub stars: 0
- License: NOASSERTION
- Official: no

## Install

```sh
cp -r norma ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-09 by tashan (https://tashan.sh) from public evidence. Scorer s5.
