NIST AI RMF MCP
About
NIST AI Risk Management Framework compliance — risk profiling, govern/map/measure/manage functions by MEOK AI Labs
Details
- Author
- csoai-org
- Categories
- Other, Security, AI
Jump to
Setup
Install NIST AI RMF MCP in your MCP client (Claude Desktop, Cursor, Windsurf, and others).
Repository: https://github.com/csoai-org/nist-rmf-ai-mcp
Follow the installation instructions in the repository README, then restart your MCP client.
mcp-name: io.github.CSOAI-ORG/nist-rmf-ai-mcp
NIST AI Risk Management Framework MCP — MAP, MEASURE, MANAGE, GOVERN functions, risk register, tr...
NIST AI Risk Management Framework MCP — MAP, MEASURE, MANAGE, GOVERN functions, risk register, trustworthy AI assessment.
# Install via pip pip install nist_rmf_ai_mcp # Or install via Smithery npx -y @smithery/cli@latest install nist-rmf-ai-mcp --client claude
- MCP protocol compliant
- Easy installation
- Well-documented API
- Production-ready
- Active maintenance
- Full Documentation
- API Reference
- EU AI Act Compliance Guide
This MCP server is built withEU AI Act compliancebuilt-in:
- ✅ Article 9 — Risk Management System
- ✅ Article 13 — Transparency & Instructions for Use
- ✅ Article 15 — Bias Detection & Testing
- ✅ Article 26 — FRIA Support (where applicable)
- ✅ Article 50 — AI Content Watermarking (where applicable)
Need help getting compliant?Book a free 15-min diagnostic →
Need custom development, SLA guarantees, or white-label deployment?
- Pro:$99/mo — Full MCP suite + EU AI Act tracking
- Enterprise:$499/mo — Custom dev + SLA + Dedicated support
This server is part of theMEOK AI Labsecosystem — 300+ MCP servers for sovereign AI governance.
Built with 💜 byMEOK AI Labs· UK Companies House 16939677
Build something that touches users? You need compliance. MEOK ships 38 governance MCPs that drop in alongside this tool — EU AI Act, DORA, NIS2, CRA, GDPR, ISO 42001, FDA SaMD, MDR, Basel, MiFID II, MiCA, COPPA, and more.
# One-shot install of the governance pack npx meok-setup --pack governance
Free tier: 10 calls/day per MCP. Pro tier (£79/mo): unlimited + cryptographically signed compliance attestations your auditor verifies independently.
→ Full catalogue:councilof.ai/catalogue→ MEOK AI Labs:meok.ai
💸 Try MEOK in 30 seconds — instant buy ladder
Refundable. UK Stripe — VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report athttps://meok.ai/verify.
Add to yourclaude_desktop_config.json(Claude Desktop) or your MCP client config:
{ "mcpServers": { "nist-rmf-ai-mcp": { "command": "uvx", "args": ["nist-rmf-ai-mcp"] } } }
Or:pip install nist-rmf-ai-mcpthen run thenist-rmf-ai-mcpcommand (stdio transport).
Once configured, ask your assistant, for example:
- "Useassess_risk_profileto …"
- "Usemap_ai_impactto …"
- "Usegenerate_risk_controlsto …"
MEOK compliance MCP fleet:meok-eu-aia-art-9-rms-mcp,risk-assessment-ai-mcp
KHEPRA MCP Server smithery badge MCP Registry License Container PQC Sovereign compliance engine with 36,195 STIG/CCI/NIST/CMMC mappings. Air-gappable. Zero token costs. Run ert_scan → get a Godfather Report with dollar-denominated business impact. The only MCP compliance server that runs on your metal — with the World's First DoD PQC STIG built in. PQC-01-STIG-V1R1 — Full Whitepaper → 17 controls covering CNSA 2.0, FIPS 203/204/205, and the NSA's May 2026 MCP security advisory. The world's first DoD-style Post-Quantum Cryptography STIG, including the first PQC controls for agentic AI and MCP deployments.
Cryptographic runtime governance for AI agents. 20 tools. Sealed policy artifacts, continuous measurement, tamper-evident proof. Ed25519 + SHA-256.
AI Agent Supply Chain Security - Intercepts and validates every package installation, git clone, and script download triggered by AI coding agents before it executes.
Structured AI incident reporting for EU AI Act Article 62 — generates mandatory incident reports, severity classification, root cause analysis, and regulator-ready submissions for serious AI incidents.
Enforces organisational AI usage policies at the agent layer — blocks prohibited model calls, enforces data residency rules, logs policy violations, and ensures AI governance policies are machine-executable.
AI agent governance with quantum-safe audit trails and three-tier policy enforcement
Guardrails service for AI agents. Default-deny tool call evaluation with LLM safety analysis, priority-ordered decision matrix, and human-in-the-loop escalations. Session recording, behavioral analysis, MCP proxy, secret redaction, and real-time audit.
ISO 42001 AI management system compliance — gap analysis, control mapping, certification readiness by MEOK AI Labs
Security scanner for MCP servers — detects prompt injection, credential leaks, and tool poisoning with 52 CVSS-scored rules
Multi-framework AI governance reports across EU AI Act, NIST AI RMF, ISO 42001, and DORA with automated gap analysis
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.




