Enterprise AI solutions that satisfy requirements of security and compliance standards from around the globe.
Data Center / Cloud
Public Sector
Risk Mitigation
Overview
Government agencies and regulated industries around the world are poised to unlock unprecedented efficiencies—potentially reducing complex data analysis time by half—through transformative AI, but deployment is stalled by complex security mandates. With a secure, compliance-ready AI software foundation, organizations can:
NVIDIA AI Enterprise government-ready software is designed to address all these needs in a commercially supported, production-scale software suite.
Quick Links
Carefully vet software and its dependencies for security vulnerabilities and integrity, and ensure they originate from trusted and verifiable sources.
Ensure that third-party, open source, and in-house development adhere to rigorous security processes designed to produce consistently secured software. This includes but is not limited to code scanning, vulnerability remediation, and malware protection prior to initial release.
Apply complex security configurations aligned with exacting standards like the Defense Information Systems Agency’s Security Technical Implementation Guides (DISA STIGs).
Integrate, configure, and validate Federal Information Processing Standards (FIPS) 140-3 compliant cryptographic modules to ensure all sensitive data, both at rest and in transit, is protected.
As an independent software provider, NVIDIA has invested in developing government-ready software that adheres to the applicable SDLC controls from FedRAMP High, FISMA High, and equivalent sovereign use cases. In adhering to these controls, NVIDIA enables its government-ready software for other global use cases, which require enhanced security and compliance.
NVIDIA provides the mapping report below to demonstrate that its government-ready software adheres to controls of various standards from around the world. NVIDIA has mapped these controls to the corresponding requirements for its government-ready software. This documentation facilitates customer assessments of the software within these various environments.
| Region | Country | Standards Body | Certification / Framework Report |
|---|---|---|---|
| NAM | Canada | <a href="https://www.cyber.gc.ca/en" target="_blank">Canadian Centre for Cyber Security (CCCS)</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-cccs-medium" target="_blank">CCCS</a> |
| NAM | U.S. | <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act" target="_blank">Federal Information Security Modernization Act | CISA</a> | <a href="https://docs.nvidia.com/ai-enterprise/planning-resource/ai-software-regulated-environments-white-paper/latest/index.html" target="_blank">FISMA</a> |
| NAM | U.S. | <a href="https://csrc.nist.gov/" target="_blank">NIST Computer Security Resource Center</a> | <a href="https://docs.nvidia.com/ai-enterprise/planning-resource/ai-software-regulated-environments-white-paper/latest/index.html" target="_blank">NIST 800-53</a> |
| NAM | U.S. | <a href="https://www.iso.org/standard/27001" target="_blank">International Standards Organization</a> | <a href="https://docs.nvidia.com/ai-enterprise/planning-resource/ai-software-regulated-environments-white-paper/latest/index.html" target="_blank">ISO27001</a> |
| NAM | U.S. | <a href="https://govramp.org/" target="_blank">GovRAMP</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-nvgovramp" target="_blank">GovRAMP High</a> |
| EMEA | EU | <a href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en" target="_blank">ENISA</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-eu-dora" target="_blank">DORA</a> |
| EMEA | EU | <a href="https://www.enisa.europa.eu/publications/eucs-cloud-service-scheme" target="_blank">ENISA</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-eucs" target="_blank">EUCS</a> |
| EMEA | EU | <a href="https://eur-lex.europa.eu/eli/dir/2022/2555" target="_blank">ENISA</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-nis2" target="_blank">NIS2</a> |
| EMEA | Germany | <a href="https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Empfehlungen-nach-Angriffszielen/Cloud-Computing/Kriterienkatalog-C5/kriterienkatalog-c5_node.html" target="_blank">BSI (Federal Office for Information Security)</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-c5" target="_blank">C5</a> |
| EMEA | Spain | <a href="https://ens.ccn.cni.es/en/" target="_blank">Esquema Nacional de Seguridad</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-spain-ens" target="_blank">ENS</a> |
| JAPAC | Australia | <a href="https://www.cyber.gov.au/business-government/protecting-devices-systems/assessment-evaluation-programs/irap" target="_blank">Australian Cyber Security Centre (ACSC)</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-irap" target="_blank">IRAP</a> |
| JAPAC | Japan | <a href="https://www.ismap.go.jp/csm?id=csm_ismap_index" target="_blank">Information Technology Protection Agency</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-ismap" target="_blank">ISMAP</a> |
| JAPAC | Korea | <a href="https://www.pipc.go.kr/eng/index.do" target="_blank">Personal Information Protection Commission</a> | <a href="https://resources.nvidia.com/en-us-govt-ai-software/nvidia-govready-soft-kisms" target="_blank">KISMS</a> |
No. NVIDIA AI Enterprise includes access to government-ready versions of a wide range of AI software and containers. Licensed customers can find this software on NGC by using the government-ready policy filter in the search.
Government-ready software does not differ in performance or functionality from other equivalent software. Instead, this software is built on a hardened, FIPS-compliant base image and undergoes a more rigorous development and maintenance process. More details can be found in the NVIDIA Enterprise AI Software for Regulated Environments Whitepaper.
No. While NVIDIA AI Enterprise software meets the applicable SDLC controls for adoption in FedRAMP High system environments, achieving full system compliance and final authorization cannot be attained by software alone. FedRAMP and other system-level certifications depend on the system owner implementing system-wide controls, including proper customer integration, configuration, data governance, continuous monitoring, and other controls.
The partner ecosystem is critical. The software, combined with the expertise of partners (including hardware vendors and systems integrators), forms a robust foundation for building auditable, compliant AI solutions. Partners contribute specialized capabilities like infrastructure orchestration, asset management, observability, and SIEM solutions to complement NVIDIA's government-ready software.
The government-ready, model-free NVIDIA NIM™ (aka multi-LLM NIM) allows you to bring and deploy your own trusted model (compatible with Hugging Face or NVIDIA TensorRT™-LLM formats) directly into production, within regulated environments. By using this, you are relieved of the burden of building a compliant inference stack and container yourself, as the government-ready NIM provides the necessary, trusted, and comprehensive software stack.
Get Started
NVIDIA AI Factory for Government reference design provides guidance for full-stack deployment in public sector and highly regulated industries. NVIDIA provides the trusted infrastructure powering these efforts, driving impact across all industries.