February 20, 2024

JFrog Ltd. (Nasdaq: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, and Carahsoft Technology Corp., the Trusted Government IT Solutions Provider®, today announced a partnership that empowers U.S. Government organizations to safeguard their software supply chains with automated DevSecOps workflows to secure software services consumed by citizens. Under the agreement, Carahsoft will serve as a JFrog Public Sector Distributor, making its platform solution available to the Public Sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V and Information Technology Enterprise Solutions – Software 2 (ITES-SW2) contracts.

“With the number and severity of security threats on the rise, plus increasing regulatory requirements, government organizations must ensure their software is compliant and secure, while also meeting their IT transformation goals,” said Shlomi Ziv, SVP of Americas, JFrog. “Our partnership with Carahsoft will provide public sector organizations with reliable solutions that incorporate security from the start while unburdening DevOps teams from complex and time-consuming remediation processes and ensuring compliance.”

Government agencies, like all organizations, want to release trusted software fast and on schedule to enable public servants to provide citizens with modern applications and digital services. The Secure Software Development Framework (SSDF) integrates secure development practices into the software development lifecycle, reducing vulnerabilities, mitigating potential impacts of known and unknown vulnerabilities and preventing future recurrences by addressing root causes.

Gartner predicts that 45 percent of organizations worldwide will experience a software supply chain attack by 2025 (a three-fold increase from 2021). Plus, a report by the SANS Institute showed there is a 70 percent chance a cybersecurity incident will be caused by an organization’s suppliers.

“Supply chain attacks in recent years have highlighted the importance of integrating security into each phase of software development,” said Natalie Gregory, Vice President of Open Source Solutions at Carahsoft. “JFrog’s platform provides agencies with unparalleled security, agility and peace of mind for their software supply chain. We’re excited to make these capabilities available to the Public Sector through our reseller partner network and supply Government agencies with the tools needed to enhance their security.”

Compliance with NIST SP 800-218 and the SSDF is mandatory for government organizations. The JFrog Software Supply Chain Platform is designed to assure customers that their environment complies with NIST 800-218 guidelines in accordance with the Office of Management and Budget (OMB) M-22-16 memorandum. All JFrog solutions are created using the SSDF, which is consistent with both the White House Executive Order (EO) 14028 and the White House Memorandum on Improving the Cybersecurity of National Security, Department of Defense (DoD) and Intelligence Community Systems in the NSM-8. The JFrog Platform supports on-premise, hybrid, cloud, multi-cloud or air-gapped environments and can be hosted on Amazon Web Services, Microsoft Azure or the Google Cloud Platform.