Voluntary standardUS

NIST AI Risk Management Framework

The NIST AI Risk Management Framework (AI RMF 1.0) provides a voluntary, rights-preserving, non-sector-specific, and use-case-agnostic approach to managing risks from AI. It is organized around four core functions — Govern, Map, Measure, and Manage — and is widely adopted by US federal agencies and enterprises as the de facto governance baseline.

Jurisdiction

US

Enforcement

January 26, 2023

Maximum penalty

Voluntary framework; no statutory penalties

Key obligations

  • 01Govern: establish a culture of risk management
  • 02Map: identify context and categorize AI risks
  • 03Measure: assess, analyze, and track risks
  • 04Manage: prioritize risks and act on them
  • 05Generative AI Profile (NIST AI 600-1) — July 2024

Vendors that support NIST AI RMF

Sorted by coverage level. Full coverage shown first.

20 vendors

VendorHQFoundedSizePricingCoverageLast verified
LatticeFlow AIZurich, Switzerland202011-50No public pricing. Enterprise platform sold via direct sales. Contact sales for demo and pricing.FullApr 22, 2026
Holistic AILondon, United Kingdom202051-200Enterprise-only with modular pricing by use case.FullApr 21, 2026
EnzaiBelfast, United Kingdom20212-10SaaS platform, enterprise subscription. No public pricing listed. Contact sales via enz.ai.FullApr 22, 2026
Robust IntelligenceSan Francisco, United States201911-50Now integrated into Cisco AI Defense / Cisco Security Cloud. Standalone Robust Intelligence is no longer sold independently. Pricing through Cisco.FullApr 22, 2026
FairNowNew York, United States202311-50Pricing not publicly listed; contact sales.FullApr 21, 2026
Credo AISan Francisco, United States202051-200Enterprise-only; typical engagements start in the mid-five figures annually.FullApr 21, 2026
Collibra AI GovernanceNew York, United States20081000+Enterprise subscription; contact sales for custom quote based on users, assets, modules.FullApr 23, 2026
MonitaurBoston, United States201911-50Enterprise annual subscription; no public pricing listed. Forrester Wave cited 'pricing flexibility and transparency' as a highest-score criterion. Contact sales for quotes.FullApr 22, 2026
TrustibleArlington, United States202311-50Contact sales for enterprise pricing; no public plans listedFullApr 23, 2026
ModelOpChicago, United States201811-50No public pricing listed; contact sales for enterprise quotes.FullApr 23, 2026
SaidotHelsinki, Finland201811-50No public pricing listed; contact sales implied via demos and sign-ups.PartialApr 23, 2026
ArthurNew York, United States201851-200Shield has a free tier; enterprise monitoring is contact-only.PartialApr 21, 2026
HiddenLayerAustin, United States202251-200Enterprise-only, contact sales for pricing. No public pricing listed on website.PartialApr 22, 2026
LakeraZurich, Switzerland202151-100Enterprise-focused SaaS. No public pricing listed. API-based pricing model expected. Contact sales.PartialApr 22, 2026
Prompt SecurityTel Aviv, Israel202311-50Now part of SentinelOne Singularity Platform. Continues as a standalone product. Enterprise pricing only; contact sales or SentinelOne.PartialApr 22, 2026
Protect AISeattle, United States202251-200Now integrated into Palo Alto Networks Prisma AIRS. Original standalone Protect AI pricing was enterprise-only, contact sales. Current pricing through Palo Alto Networks.PartialApr 22, 2026
Fairly AIKitchener, Canada202011-50On-premises or private-cloud deployments; quote-based.PartialApr 21, 2026
TrojAISaint John, Canada201911-50Enterprise-only, no public pricing. Contact sales at troj.ai.PartialApr 22, 2026
Fiddler AIPalo Alto, United States201851-200Contact for pricingPartialApr 21, 2026
OneTrust AI GovernanceAtlanta, United States20161000+Enterprise platform; contact sales for quote, no public pricing listedPartialApr 23, 2026

Compare across industries

See which vendors support NIST AI RMF in your sector.

Last verified April 21, 2026. Informational summary only — not legal advice. Consult qualified counsel for specific obligations.