- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework AI Governance & Privacy Frameworks
NIST Privacy Framework
The NIST Privacy Framework is a voluntary US tool for managing the privacy risks that arise from how an organization processes personal data.
Version 1.0 was published in January 2020 and is built like the NIST Cybersecurity Framework: a Core of functions (Identify-P, Govern-P, Control-P, Communicate-P, and Protect-P), Profiles that describe current and target states, and Implementation Tiers.
NIST released an initial public draft of version 1.1 on April 14, 2025 to line the framework up with CSF 2.0 and the AI RMF, with a section on AI privacy risks; final publication was signaled for 2026 (verify current status on the NIST page).
The framework itself imposes nothing, but organizations that adopt it end up producing a data inventory and data flow maps, a privacy governance policy with assigned roles, privacy risk assessments, a record of the controls chosen to manage each risk, notices and consent mechanisms, and processes for handling individual requests and incidents.
It is commonly used to structure compliance with US state privacy laws, GDPR, and sector rules, and to support ISO/IEC 27701 work.
Who has to comply
Voluntary. Any organization processing personal data. It is referenced by some US state laws and regulators as an acceptable structure for a privacy program but is not mandated.
What the assessor asks to see
Data inventory and processing maps; privacy governance policy and role assignments; privacy risk assessment method and results; control selections tied to risks; privacy notices and consent records; data subject request handling logs; vendor and processor agreements; incident and breach handling records; training records; management review of the target Profile.
Where the requirement sits: Privacy Framework 1.0 Identify-P / Govern-P / Control-P / Communicate-P / Protect-P
Version 1.1
The initial public draft of Privacy Framework 1.1 was issued April 14, 2025 with comments accepted until June 13, 2025. It keeps the 1.0 structure, realigns with Cybersecurity Framework 2.0, and adds AI-related privacy content. Check the NIST Privacy Framework page for whether the final version has been published.
What AllyMatter does here
Organise privacy policies against the framework.
AllyMatter publishes this site.
Assessors
Who assesses NIST Privacy Framework
None. No certification exists. Organizations self-assess or have privacy controls examined as part of another engagement such as a SOC 2 privacy criteria report or ISO/IEC 27701 audit.
No firm has claimed a NIST Privacy Framework assessor listing yet. Claim yours →
Consultants
Who helps with NIST Privacy Framework
Privacy consultancies, law firms, and GRC platform vendors offer mapping and program-build services. Typical engagement is a gap assessment against the Core, a data inventory exercise, and drafting of the governance policy and risk register, followed by a target Profile and roadmap.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- VCISO / ISO 27001 consultancy
- Who they help
- Control and Function is a vCISO / ISO 27001 consultancy based in Denver, CO, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- Multi-framework consultancy
- Who they help
- Cybervantage 360 is a multi-framework consultancy based in Navi Mumbai, India. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
- What they do
- Privacy governance + ISO 27001
- Who they help
- XpertDPO is a privacy governance + ISO 27001 based in UK/Ireland. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for NIST Privacy Framework
Tools that name this framework in their own material.
Related reading
- A view from DC: an updated NIST Privacy FrameworkPrivacy profession's read on the 1.1 revision and why realignment with the Cybersecurity Framework matters for programme design.IAPP
- NIST updates Privacy Framework with AI and governance revisionsExplains the new AI and privacy risk section and the reshaped Govern function in plain terms.Dark Reading
- NIST releases updated Privacy FrameworkCounsel's summary of what moved in the Core and how the framework maps onto existing privacy obligations.Maynard Nexsen
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for NIST Privacy Framework
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
From the publisher
Run the Policy Side of NIST Privacy Framework in AllyMatter
Approve the policies NIST Privacy Framework asks for, keep every version, and record a named acknowledgment from each person who has to read them.