NormShield, Inc. DBA Black Kite: Third-Party Risk Intelligence System (TRIS)'s
What its stage means
An independent assessor found the provider ready to pursue an authorization. It is not an authorization.
The provider's description
Black Kite is delivered as a SaaS offering using a multi-tenant public cloud computing environment. It is available to the public, federal, state, local, and tribal governments, as well as research institutions, federal contractors, government contractors etc. Black Kite offers a separate configuration for federal/public sector customers to maintain the highest possible level of information security. Black Kite provides a defensive platform that spans the entirety of the third-party risk management life cycle for cyber risk professionals looking to quantify and maintain visibility of their risk exposure. Black Kite’s core application, is a multi-user, transaction-based application suite that gives a three-dimensional risk picture of a company and its vendors through: • A cyber risk technical assessment. • A factor analysis of information risk (FAIR) analysis (the probable financial impact of a breach caused by a vendor). • An external estimate of compliance (assessing that vendors have appropriate policies and processes in place). • Executives get an easy-to-understand “Cyber Risk Report” with letter grade scores. • IT security teams can drill down to the technical details behind each risk category. • Risks/vulnerabilities are prioritized by severity so that security engineers can quickly identify critical issues and mitigate them. • Industry benchmarks and comparisons are provided to help identify trends and pinpoint areas for improvement. • Grading is based on industry standards and best practices (NIST, MITRE CVSS, FAIR, etc.)
What FedXchange has recorded
No change since FedXchange began following it on April 14, 2026. Each change of stage, impact level, or number of authorizations appears here.