Cyber Risk Institute
Cyber Risk Institute is a Washington, D.C.-based non-profit standards body that develops the CRI Profile and related frameworks (Cloud, FS AI RMF, Maturity Model) to help global financial institutions manage cyber and AI risk under recognized regulatory mappings.
- Company typePrivate
- Founded2022
- HeadquartersWashington, United States
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Cyber Risk Institute does
Cyber Risk Institute (CRI) is a Washington, D.C.-based not-for-profit 501(c)(6) standards development organization that builds and maintains cybersecurity and AI risk frameworks for the global financial services industry. CRI originated as a Profile development effort under the Financial Services Sector Coordinating Council (FSSCC) beginning in 2016 and was spun out as an independent entity in 2022. Its core asset is the CRI Profile, a streamlined version of the NIST Cybersecurity Framework v2.0 comprising 318 diagnostic statements with 40 mappings to global regulatory and supervisory references. The product family has expanded to include the Cloud Profile (cloud security extension), the Financial Services AI Risk Management Framework (FS AI RMF) with 230 control objectives, a member-exclusive Maturity Model for benchmarking, and translations in Japanese, Spanish, and Portuguese.
The platform architecture is framework-centric rather than software-centric: CRI packages curated control catalogs, diagnostic questions, regulatory mappings, and assessment instruments that financial institutions map their internal controls and audit processes to. Supporting tools include an AI Adoption Stage Questionnaire, a Risk and Control Matrix, and integrations with standards such as MITRE ATT&CK. CRI distributes the core framework as a free download to drive adoption and operates member-exclusive products and a forthcoming CRI Marketplace for aligned third-party products, plus Innovator and Affiliate licensing programs.
CRI's revenue mechanics are diversified across membership dues (annual subscriptions from financial institutions and trade associations), commissions from CRI Marketplace, and licensing fees from the Innovator and Affiliate programs. It serves 130+ member organizations spanning large U.S. and global banks, payment networks and issuers, capital markets and trust firms, exchanges, crypto/fintech, and major industry associations (SIFMA, FS-ISAC, ABA, Bank Policy Institute). CRI is governed by a cross-industry board and operates with a small (1–10) staff footprint, with senior leadership and contributor participation drawn from member institutions.
Cyber Risk Institute firmographics
Firmographics- Name
- Cyber Risk Institute
- Legal name
- Cyber Risk Institute
- Website
- https://cyberriskinstitute.org
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Cyber Risk Institute is a Washington, D.C.-based non-profit standards body that develops the CRI Profile and related frameworks (Cloud, FS AI RMF, Maturity Model) to help global financial institutions manage cyber and AI risk under recognized regulatory mappings.
- Ownership category
- akta.pro rank
Cyber Risk Institute industry classification
Industry- Product category
- Cybersecurity Risk Management Frameworks
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- akta.pro primary industry
- AI Governance, Risk & Compliance (GRC) Platforms (HDAAAMAA)
- akta.pro secondary industries
- Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE), Model Governance, Risk & Compliance (GRC) Platforms (HDAAAKAA), Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001) (HDAAAMAE), Responsible AI, AI Governance & Compliance Services (BPAEAHAJ), Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)
Keywords
Where Cyber Risk Institute is headquartered
LocationHeadquarters
- HQ city
- Washington
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Cyber Risk Institute business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Others
Revenue model
- Membership Dues: CRI generates revenue through annual membership dues paid by financial institutions. Membership is at the organizational level. Annual participation dues are set by the Board of Directors and available upon request. Explorer tier is free, Full Member has a low-cost annual fee.
- CRI Marketplace: The CRI Marketplace is a hub for tools, products, and services designed to help financial institutions adopt and implement CRI resources. Third-party tool providers and consulting firms offer products through this marketplace.
- Innovator and Affiliate Programs: Non-financial institutions can join as Innovators (Basic or Premium levels) or Affiliates, gaining rights to integrate CRI tools into their offerings for a fee.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free tier with basic access to CRI Profile |
| Subscription | Annual | Full Member with comprehensive access and participation rights |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels6 records
Cyber Risk Institute product offering
Product offeringCore offering
CIRI develops and maintains cybersecurity, cloud security, and AI risk management frameworks tailored for the global financial services industry. The core CRI Profile harmonizes 3,500+ regulatory expectations into 318 diagnostic statements mapped to 40+ standards and regulations. Complementary offerings include the Cloud Profile (cloud security extension), the FS AI RMF (230 Control Objectives for AI risk), and the member-exclusive Maturity Model for peer benchmarking.
Product overview
The Cyber Risk Institute offers a suite of cybersecurity, technology, and AI risk management products for the financial services industry. The core offering consists of the CRI Profile (a NIST-based cybersecurity framework harmonizing 3,500+ regulatory expectations), the Cloud Profile (an extension for cloud security), and the FS AI RMF (an AI risk management framework with 230 control objectives). Supporting products include the Maturity Model (for peer benchmarking, member-exclusive), Profile Translations (Japanese, Spanish, Portuguese), and various companion guides and mapping documents. The products work together as an integrated risk management ecosystem, enabling financial institutions to assess, benchmark, and report on cybersecurity and AI risks across global regulatory jurisdictions.
Differentiator
Problem solved
Functional benefit
Brands
- CRI Profile: Cybersecurity and technology framework built by and for the financial sector, based on NIST CSF, connecting cyber best practices with regulatory expectations from around the world.
- Cloud Profile
- Financial Services AI Risk Management Framework (FS AI RMF)
- Maturity Model
Products and services
- CRI Profile A financial-sector-specific cybersecurity and technology risk management framework built on NIST Cybersecurity Framework v2.0, harmonizing 3,500+ regulatory expectations into 318 diagnostic statements with approximately 40 mappings to global standards and regulations. For financial institutions of all sizes.
- Cloud Profile An extension of the CRI Profile developed in collaboration with Cloud Service Providers and the Cloud Security Alliance, providing actionable cloud security guidance including a shared responsibility checklist implementation tool. Aligned with NIST CSF v2.0 and integrated with the CSA Cloud Control Matrix. For financial institutions implementing or strengthening cloud technologies.
- Financial Services AI Risk Management Framework (FS AI RMF) An industry-led, sector-specific AI risk management framework with 230 Control Objectives developed through public-private collaboration with 100+ financial institutions. Includes an AI Adoption Stage Questionnaire, Risk and Control Matrix, Guidebook, and Control Objective Reference Guide. For financial institutions deploying or overseeing AI systems.
- CRI Maturity Model An assessment tool aligned with the CRI Profile and NIST CSF that quantitatively scores responses at the diagnostic-statement level, enabling structured benchmarking of cybersecurity maturity across institutions. Available exclusively to CRI Full Members.
- CRI Profile Translations Translated versions of the CRI Profile and Guidebook in Japanese, Spanish, and Brazilian Portuguese to enable consistent adoption across Asia-Pacific and Latin America. Includes Japanese translation by NRI Secure Technologies and Spanish/Portuguese translations sponsored by Mastercard.
- CRI Marketplace A hub that aggregates tools, products, and services from third-party providers and consulting firms to help financial institutions adopt and implement CRI resources at every stage of their cybersecurity program. For financial institutions seeking implementation support and the partner firms that serve them.
- CRI Membership Program Annual organizational membership providing access to the Maturity Model, exclusive member workshops, participation in working groups, and member-only mappings and tools. Includes Explorer (free) and Full Member (paid) tiers. For financial institutions.
Quantifiable outcome
- 58% reduction in assessment questions for Impact Tier 4 firms compared to other widely used assessments
- +3 more outcomes
Companies that use Cyber Risk Institute
Customer profileNamed customers29 records
Segments5 records
Ideal customer profiles3 records
Cyber Risk Institute technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
Cyber Risk Institute partnerships and signals
Strategic signalPartnerships
Eleven partnerships are on record, tiered core.
- Financial Services Sector Coordinating Council (FSSCC)coreCRI developed the FS AI RMF in coordination with FSSCC as part of a larger sector-wide initiative focused on responsible AI adoption and governance. The FS AI RMF was developed through a collaborative effort by more than 100 financial institutions coordinated through FSSCC.
- Cloud Security Alliance (CSA)coreCollaboration with CSA to integrate the Cloud Security Alliance's Cloud Control Matrix (CCM) into the CRI Cloud Profile. CSA collaborated with financial institutions and major cloud service providers to develop the Cloud Profile.
- MITRE's Center for Threat-Informed Defense (CTID)coreCollaboration to develop mapping connecting CRI Profile to MITRE ATT&CK Framework, helping financial institutions bring together governance, regulatory expectations, and threat mitigations.
- EY (Ernst & Young)coreEY provided expert support in updating Profile v2.1 and developing the DORA implementation guide for CRI Profile users.
- KPMGcoreKPMG contributed to the development of the CRI Maturity Model, which provides a mechanism to quantitatively score responses at the diagnostic statement level.
- NRI Secure TechnologiescoreNRI Secure Technologies translated the CRI Profile v2.0 into Japanese, helping financial institutions in Japan leverage the benefits of the streamlined self-assessment framework.
- MastercardcoreMastercard sponsored the Spanish and Portuguese translations of the CRI Profile and Guidebook, supporting broader adoption and consistent implementation across Latin America.
- BGBGcoreBGBG, a Mexican law firm, completed the Spanish and Portuguese translations of the CRI Profile and Guidebook, released at a launch event in Mexico City.
- U.S. Department of the TreasurycoreTreasury, as Sector Risk Management Agency for financial services, collaborated with CRI on developing precision time resiliency controls into the CRI Profile to facilitate meeting requirements in Executive Order 13905. Treasury also acknowledged CRI's work in AI risk management frameworks.
- BCG PlatinioncoreCRI works with BCG Platinion to identify priority integration opportunities and map regulations and frameworks to the Profile on a rolling basis.
- U.S. Department of the TreasurycoreThe FS AI RMF was developed in coordination with U.S. Treasury, which released it as part of the President's AI Action Plan. Treasury released two AI risk management tools including the FS AI RMF developed through public-private partnership.
Scale indicators8 records
Recent moves7 records
Expansion highlights7 records
Cyber Risk Institute competitors and assessment
Company assessmentDirect peers
- PCI Security Standards Council: Nonprofit 501(c)(6)-style global standards body that develops and maintains the PCI DSS for payment security — the closest analog to CRI in business model (standards development organization governed by members), funding mechanism (membership dues + fees), and role (harmonizing regulatory and industry expectations into a single actionable framework adopted by financial-adjacent institutions).
- Cloud Security Alliance: Nonprofit organization that maintains the Cloud Controls Matrix (CCM) and STAR program; CRI's Cloud Profile was co-developed with CSA, and the two compete/collaborate in defining authoritative cloud-security control sets for regulated industries including financial services.
- Center for Internet Security (CIS): Nonprofit that publishes the CIS Critical Security Controls (now mapped into CRI Profile v2.1) and operates a community-driven model similar to CRI's 500+ contributors and working-group approach to voluntary consensus standards.
- HITRUST: Nonprofit standards and certification organization that harmonizes multiple regulatory frameworks (HIPAA, HITECH, NIST, ISO) into a single assurance framework — analogous to CRI doing the same for the financial services sector, with a similar revenue model of membership, certification, and licensing.
- FS-ISAC: Financial Services Information Sharing and Analysis Center — member-based nonprofit serving the same 130+ FI constituency as CRI on cyber threat intelligence; recent CRI Profile mapping to FS-ISAC Sector Risk Advisory signals operational collaboration around AI-enabled vulnerability scenarios.
- Shared Assessments: Member-driven nonprofit that develops third-party risk management assessment tools (SIG, AUP) widely used by financial institutions — overlapping with CRI's third-party risk and vendor assessment use cases for FI members.
Broad incumbents
- National Institute of Standards and Technology (NIST): U.S. government agency that authored the Cybersecurity Framework (the foundation on which the CRI Profile is built); CRI operates as a sector-specific overlay/customization layer above NIST CSF, complementing rather than competing but representing the most direct upstream alternative framework.
- ISACA: Global nonprofit association that publishes COBIT and related IT/governance/risk frameworks used by financial institutions; serves overlapping CISO/GRC audiences with comparable certifications (CISM, CRISC held by CRI SVP John Goodman) and competes for governance framework budget.
- ISO (International Organization for Standardization): Publisher of ISO 27001/27002 (information security) and the new ISO/IEC 42001 (AI management systems); these represent globally adopted substitutes for parts of CRI's stack and CRi publishes mappings to several ISO standards as part of the harmonization effort.
Others
- Financial Services Sector Coordinating Council (FSSCC): The industry-coordinating body from which CRI was spun off in 2022; FSSCC still coordinates sector-wide policy efforts and co-developed the FS AI RMF with CRI, providing the institutional umbrella under which CRI's standards operate.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks5 records
Key highlights7 records
Customer concentration
Cyber Risk Institute social profiles
Digital presenceCyber Risk Institute financial estimates
Financial estimateRevenue estimate
Valuation estimate
Cyber Risk Institute leadership team
Management profileNumber of profiles
Profiles6 records
Cyber Risk Institute funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Cyber Risk Institute M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Cyber Risk Institute
What does Cyber Risk Institute do?
CIRI develops and maintains cybersecurity, cloud security, and AI risk management frameworks tailored for the global financial services industry. The core CRI Profile harmonizes 3,500+ regulatory expectations into 318 diagnostic statements mapped to 40+ standards and regulations. Complementary offerings include the Cloud Profile (cloud security extension), the FS AI RMF (230 Control Objectives for AI risk), and the member-exclusive Maturity Model for peer benchmarking.
Is Cyber Risk Institute a public or private company?
Cyber Risk Institute is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Cyber Risk Institute founded?
Cyber Risk Institute was founded in 2022. It employs 1 to 10 people.
Where is Cyber Risk Institute based?
Cyber Risk Institute is headquartered in Washington, United States, in the North America region.
How does Cyber Risk Institute make money?
Three revenue lines are on record. Membership Dues are the primary driver. The others are CRI Marketplace and innovator and Affiliate Programs.
Who are Cyber Risk Institute's main competitors?
Direct peers on record are PCI Security Standards Council, Cloud Security Alliance, Center for Internet Security (CIS), HITRUST, FS-ISAC and Shared Assessments. Broad incumbents are National Institute of Standards and Technology (NIST), ISACA and ISO (International Organization for Standardization). Financial Services Sector Coordinating Council (FSSCC) is listed as an others.
Does Cyber Risk Institute have an API?
No public API is recorded for Cyber Risk Institute.
What industry is Cyber Risk Institute in?
Cyber Risk Institute's product category is Cybersecurity Risk Management Frameworks. Its primary akta.pro industry code is HDAAAMAA, AI Governance, Risk & Compliance (GRC) Platforms, with a secondary code of HDAEANAE, Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies). Its NAICS code is 561621.