framework hub
NIST AI RMF AI Compliance Tools
NIST AI RMF is the voluntary US framework for trustworthy AI. These tools support Map, Measure, Manage, and Govern functions across the AI lifecycle.
24 tools supporting NIST AI RMF
Enterprise
CalypsoAI
AI security platform for model-agnostic guardrails, red-teaming, and inference protection — part of F5 since Sep 2025.
Enterprise
Credo AI
AI governance platform for model registries, risk assessments, and EU AI Act conformity.
Free
CSA AI Controls Matrix
Cloud Security Alliance's AI Controls Matrix v1.0.1 (Jul 2025): 243 controls across 18 domains with a five-role shared-responsibility model, crosswalked to NIST AI 600-1.
Enterprise
Dynamo AI
Compliance-focused AI evaluation, guardrails, and privacy testing for regulated industries.
Paid
Enkrypt AI
AI red-teaming and guardrails platform with compliance-mapped risk scoring for LLMs.
Paid
FairNow
AI governance software for compliance tracking, bias audits, and risk management across jurisdictions.
Enterprise
HiddenLayer
Enterprise platform for ML model security: scanning, detection, and response for AI assets.
Enterprise
Holistic AI
AI governance platform for auditing, risk management, and regulatory compliance tracking.
Enterprise
IBM watsonx.governance
IBM's enterprise AI governance platform for lifecycle monitoring, risk management, and regulatory compliance.
Paid
Lakera Guard
Runtime LLM firewall for prompt injection, jailbreaks, and data leakage — now part of Check Point.
Enterprise
Mindgard
Continuous automated red teaming and security testing for AI systems.
Enterprise
Modulos
ETH Zurich spin-out; first AI governance platform with ISO/IEC 42001 product conformity certification.
Open Source
NeMo Guardrails
NVIDIA's open-source toolkit for programmable conversational rails and safety policies inside LLM applications.
Free
NIST AI 600-1 (Generative AI Profile)
NIST's Generative AI Profile (Jul 2024): 12 GenAI risk categories with 200+ suggested actions, layered on the AI RMF's govern/map/measure/manage functions.
Free
NIST AI RMF
The US reference framework for AI risk management: Govern, Map, Measure, Manage.
Enterprise
Noma Security
Platform securing the AI lifecycle: supply chain, posture, and runtime threat detection.
Enterprise
OneTrust AI Governance
AI governance module of the OneTrust trust intelligence platform.
Free
OWASP LLM Top 10
Community-maintained checklist of the ten most critical risks for LLM applications.
Paid
Patronus AI
Automated evaluation and guardrails platform for scoring and monitoring LLM system failures.
Open Source
Promptfoo
CLI and library for systematic LLM testing, red-teaming, and eval-driven development — acquired by OpenAI in 2026.
Open Source
PyRIT
Microsoft's Python Risk Identification Toolkit for automated generative-AI red teaming.
Enterprise
Trustible
AI governance platform for inventory, risk assessment, policy, and regulatory compliance workflows.
Paid
Vanta
Automated compliance platform covering ISO 42001, NIST AI RMF, and EU AI Act alongside SOC 2.
Enterprise
WitnessAI
Enterprise AI observability and policy guardrails for safe employee and app AI usage.
faq
Frequently asked questions
- Which AI tools support NIST AI RMF compliance?
- The directory below lists every tool we have verified as supporting NIST AI RMF. Each entry links to the vendor and shows last-verified date.
- Is NIST AI RMF certification required for AI systems?
- NIST AI RMF itself is not always mandatory, but most enterprise buyers require it (or an equivalent attestation) before approving an AI system. The right tool depends on your scope, data class, and deployment model.
- How are these NIST AI RMF tools selected?
- We index vendor documentation, public trust pages, and product changelogs. Each tool's compliance posture is re-verified on a rolling basis; the "last verified" timestamp on the tool page reflects the most recent review.
- What's the difference between NIST AI RMF and other frameworks?
- NIST AI RMF has a specific scope and control set. Most teams stack two or three frameworks (e.g. SOC 2 + ISO 27001 + a privacy regime). Use the directory filters to see tools that cover multiple frameworks at once.
