RMF was initially just intended for the DoD. the DoD developed it and implemented it prior to any other federal organization. However, once the NIST published it as a special publication in 2010, all federal agencies were required to comply with the guidelines and become authorized in order for their systems to operate. RMF authorization is especially important for the federal agencies that contain lots of information, and those with personally identifiable information or government classified information.
Although initially intended for federal agencies, RMF can be utilized in the private sector as well. The implementation process is identical in both federal organizations and private ones, the only difference is that a private organization can decide whether or not they want to reach compliance with RMF and become authorized.