Decision science for the defense industrial base

Everyone sells you where the risk is.Nørn tells you what to do about it, by when, and what it costs to be wrong.

Nørn is a decision product for the defense supply chain. Not a map of your exposure — a ranked list of the calls in front of you, each with a probability, the date the world will settle it, and what it would take to sharpen it. When that date passes, the call is scored against what actually happened.

A risk score that is never checked against an outcome is an opinion with a number on it.

Access is invitation-only today. Tell us what you’re trying to protect and we’ll come back inside two business days.

What a decision looks like when it arrives

A risk register hands you a list of suppliers. Nørn hands you two different numbers for each one, because collapsing them is how this whole category misleads: the dollars whose date will move, and the dollars expected to come back off the award. Nationally those are 67% and 3.8% of the same book.

Program · 47 suppliers holding open workIllustrative — synthetic suppliers, real mechanics
SupplierOpen obligationSlipsDate will moveExpected backMeridian Forge$4.2M61.9%$2.60M$146KLarge awards. Its own measured rate, from 118 resolved awards over $2.5M — but a large award that slips is no likelier to lose its money (5.62%) than one that does not (5.97%). Slipping is how big programs run.
SupplierOpen obligationSlipsDate will moveExpected backAtlas Components$31M1.6%$496K$97KSmall awards. Rarely slips — but when a small award does slip it is 16.6× likelier to have money taken back (19.6% against 1.2%). Seven times the obligation of the row above and a fifth of the date-risk, yet two thirds of the loss.
SupplierOpen obligationSlipsDate will moveExpected backNovaline Precision$2.8M61.9% pop.$1.73M$97KOnly 4 resolved awards, so the estimate rests almost entirely on the population rate for its band rather than its own record — and the row says which. Same expected loss as the $31M supplier above, for the opposite reason.
Replaceability
1 approved sourceNobody else is approved against this stock number.
Next resolution
14 Nov 2026The date the current delivery order comes due, and the call gets scored.
What would sharpen this
A second approved sourceOr 11 more resolved awards, which moves this supplier off a borrowed rate onto its own.
Site hazard
93rd percentileShares a county with three other suppliers on this program.

The decision

Qualify a second source before 14 November, or accept a single-source dependency through the window. Either way the finding becomes a situation that has to declare, before it is created, what will settle it and roughly when.

“This supplier’s next award holds its date” settles itself, from the federal record. “This supplier is a concentration risk” is a true statement and a useless one — no evidence can ever arrive that closes it. Nørn refuses to create the second kind. A queue of findings that can never be settled is how every risk register turns into wallpaper.

Four things the product always does, enforced in code rather than promised in a deck

These are the difference between a decision product and a dashboard with a confidence column. Each one is a constraint the system will not let an analyst route around.

Every projection names what would sharpen it

Every probability ships with the specific thing that would tighten it — a source to qualify, a record to resolve, a question to answer, so the next hour of work is chosen rather than guessed.

Every rate says whose record it rests on

A supplier’s estimate is a beta-binomial posterior — its own record blended toward the population rate, weighted by how much record exists. A hard cut-off was tried and abandoned: it put a cliff at ten observations and collapsed almost every supplier onto the population rate. The blend is continuous; the basis is always stated.

A probability and its weakness in one glance

Confidence is encoded in fill, not color — solid for a supplier’s own measured rate, hollow for a borrowed population rate. A rate earned from 118 awards must never render like one borrowed from a band.

Every call carries the date it settles

Not “elevated risk” but a probability attached to a date the world will decide. When that date passes the call is scored against what happened, and the score is kept.

Six questions, each tied to a source you can check

Replaceability

If this supplier stops, who else is approved to make this part? Counted per part, from the federal catalog — two firms approved against the same stock number are substitutes as a matter of record.

FLIS / PUB LOG · observed

Schedule slip

The probability this award misses its date, banded by size and measured against resolved history — with the date it will be settled on.

FPDS · measured

Site hazard

Expected annual loss for the county a supplier sits in, and where a dozen suppliers that look diversified share one physical exposure.

FEMA National Risk Index · 3,232 counties

Restricted parties

Every supplier screened against twelve government lists, with the entity resolution to keep a name collision from becoming an accusation.

Consolidated Screening List · 1260H · UFLPA

Cyber

Suppliers running software with known-exploited vulnerabilities — scoped to what is actually measurable from the outside, and no further.

CISA KEV

Concentration

Where the open dollars pool behind one buyer, one product family, or one place — the exposure no per-supplier score can express.

FPDS · derived

You cannot war-game a condition. Only a choice with a door that closes.

A supplier score tells you where you are. It does not tell you which move to make, which fix does not help, or what stops being possible in March. Below is a live board — inject a shock and watch the moves re-rank, or close a gap and watch the interval tighten without the number moving.

One shipyard, two commitments, not enough of it to go aroundIllustrative — open sources, real mechanics
38%
1066% intervalbaselineBoth win conditions met by FY29

Candidate moves · scored

MoveWinsIf wrong
Surge Columbia; accept Virginia rate slipleads44%AUKUS certification becomes unmakeable. The alliance commitment is the thing that breaks.
Buy the constraint out — capitalize castings, forgings, a second weld source41%Money lands three tiers down and takes 30+ months to show up as a hull. Slow where the door is fast.
Hold Virginia at rate; accept Columbia risk27%A deterrent patrol gap. There is no recovery move on the far side of this one.
Re-phase the AUKUS transfer window22%Relieves the rate requirement, spends allied credibility, and does nothing for Columbia.

Inject a shock — the board re-ranks

Nothing injected. The board above is the baseline read.

One-way doors

Hull life
A reactor core has a service life. No appropriation buys another year of it — the only date on the board money cannot move.
FY27 Q3window closes
Alliance certification window
The transfer requires a determination that capability is not degraded. Rate at the time of the decision is the evidence.
FY29 Q1window closes
Long-lead casting slot
Order-book allocation, roughly 30 months ahead of need. After it, the metal exists for someone else.
FY28 Q2window closes

Gaps · close one and watch the band tighten

Actual first-year attrition in the trades pipeline, not the briefed figure±12 pts
Qualified throughput at the castings and forgings sub-tier±10 pts
How much module work the second yard can absorb at rate±6 pts

3 open questions hold the interval 56 points wide. Closing a gap narrows it and never moves the number — new information makes you more certain of what is true, not more optimistic about it.

Reading that a plan is fragile is an intellectual event. Watching the odds swing when you break it yourself is a different one, and it is the one that changes minds. A plan that survives only under the assumptions you started with is not a plan — it is a forecast you are fond of.

The floor, stated up front

The most honest number on this page is a range

Nørn does show tier-2 — the part of it that was actually filed. Primes report subcontracts over $30,000 under FFATA, and Nørn reads those filings directly. Nothing here infers who supplies whom.

Across twelve measured monthly windows of national DoD, between 0.28% and 0.72% of prime awards carried a subcontract filing — median 0.41%. Nørn reports the range rather than a single figure, because a rate that moves by more than a multiple cannot be described by its middle, and a single number is what gets quoted.

Coverage looks like it is falling in recent months. That is filing lag, not decline. Primes report after the fact, so the newest windows are still filling. Reading that curve as “subcontract reporting is collapsing” would be a confident, wrong finding of exactly the kind this product exists not to produce.

So the sub-tier is a drill-down, not a network view. “Here is what this prime filed” is defensible at this density. A graph is not: an absent link means nobody filed, which on a network is indistinguishable from a prime that has no subcontractors at all — and a tool that drew it anyway would invent chokepoints out of missing paperwork.

What it will not do is infer the rest. No complete sub-tier map exists at any price. There is no tier-3. And federal award records carry no stock numbers, so we will never tell you what share of a supplier’s dollars sits behind a single-source part — that figure would be an estimate wearing a measurement’s clothes.

The evidence underneath the call

Slip probability is estimated from resolved awards, banded by size, because a single pooled rate describes nobody. Every band shows the population it was measured against — including the one that is thin.

Award sizeSlipsMedian slip, when it doesResolved awards measured
Under $250k1.6%133 days7,888,754
$250k – $2.5M31.7%273 days89,952
Over $2.5M61.9%365 days23,375

A large award is roughly forty times likelier to move than a small one, and when it does the median slip is a full year.

Most of that forty is attention, not delivery, and the number should not stand alone. A slip is a recorded schedule change — somebody has to file the modification. After the promised date passes, 97.2% of small awards see no action of any kind, against 46.6% of large ones. A $50,000 award delivered six months late and one delivered exactly on time leave the same record, which is none. Among awards somebody actually touched, the spread is 2.5×, not forty.

So the figure is the right answer to will the promised date move, which is what the system predicts and scores. It is not a delivery-failure rate, and it is not the amount at risk.

Those are two different claims, and either alone misleads.Across the whole open federal book, $489.3B is expected to move — 67% of it. Of that, $27.8B is expected to come back off its award: 3.8%. The first reads as a catastrophe; the second reads as though nothing is late. Together they say the true thing, which is that most slipped work still lands and the money worth watching is a twentieth of what “at risk” implies.

The loss signal is not where you would look for it. A large award that slips is no likelier to have money taken back (5.62%) than one that does not (5.97%) — slipping is how big programs run. A small award that slips is 16.6× likelier to be reversed. And de-obligated dollars are frequently re-obligated elsewhere, so this is a floor on disruption, never a measurement of waste.

A number also means nothing without knowing what normal is. A third of open federal dollars land on their promised date. Across the fourteen buying components holding over $1B, the middle half sits between 32% and 37%. A program at 33% is ordinary, not a crisis — and Nørn says which, rather than leaving a reader to do the subtraction backwards.

All of it counted, not estimated, from the public federal record — FPDS, FLIS/PUB LOG, the Consolidated Screening List, CISA KEV and the FEMA National Risk Index. Free, citable, and auditable by anyone holding the same sources.

9,043,906Prime contract actions · 25 months · all 50 states
24,921Suppliers holding open work, scored
11,953,610Approved part-source relationships
7,101,798Distinct parts by national stock number
25,846Restricted-party entities screened · 12 government lists
3,232Counties with expected-loss modeling
$731.8BOpen obligations, inside the window held — not a claim about the federal book
52,574Companies, resolved from 55,312 registrations — Lockheed alone holds 46

None of this is supply-chain software

Nørn is three general capabilities. Supply chain is where they are deepest today, and the hardest place to fake them — the federal record is public, so every claim above can be checked against a source you also hold. That is the point of leading with it.

Calibration

Raw frontier-model forecasts are confidently wrong — on the hardest domains, worse than guessing the base rate. Nørn calibrates them against a corpus of resolved outcomes, then keeps scoring itself as new ones resolve.

Here
Slip probability banded by award size, scored against resolved awards.
Elsewhere
Geopolitics. Regulatory outcomes. Science and technology timelines.

Entity resolution

The same organization across three spellings, two aliases and a shell resolves to one entity. Ambiguity is the failure mode that quietly corrupts every downstream number.

Here
Keeping a name collision on a restricted-party list from becoming an accusation against a real company.
Elsewhere
Sanctions networks. Cap tables. Beneficial ownership. Any graph where the hard part is who is who.

Network-conditional projection

Build a twin of the situation, then change it. Remove an actor, sever a link, move a policy — and watch the calibrated picture move under the modified network.

Here
If this supplier fails, what happens to the program — and who else is approved to step in.
Elsewhere
Adversary response. Competitor entry. Deal and diligence scenarios.

The corpus of resolved outcomes that scores a supplier’s slip probability is the same corpus that scores Nørn’s geopolitical and scientific forecasts. It is one engine with one track record, not a supply-chain product with adjacent ambitions.

Pointed at, today and under the same calibration — click any role to see how it fits the work.

Founder

Blair Merlino is Nørn's founder. Former Army Special Operations, BU Questrom MBA + MS in Information Systems, management consulting at Deloitte, and infrastructure-focused VC and operator roles since.

The hardest part of high-stakes decision-making isn't access to information — it's the gap between information and a calibrated, actionable verdict. Nørn closes that gap because the founder spent a career living on the wrong side of it.

Ready to look?

Access is invitation-only today. Tell us who you are and what you're trying to track; we'll get back to you within two business days.

Security & data handling documentation — tenant isolation, collective layers, controls and compliance trajectory — is available on request.