Every New Compliance Framework Restarts the Same Fire Drill. It Doesn’t Have To.

JFrog AppTrust_ Secure Compliance_863x300

Every compliance audit starts the same way: Someone flags a deadline, the team scrambles to pull evidence, map controls, and prove that the policies running in production actually match what the framework requires. They make it through. They exhale. Six months later, a new framework arrives, and the fire drill starts all over again.

Most teams walk away from an audit believing they are compliant. The 59% of organizations that claim full provenance visibility into their software supply chains probably felt the same way. But when JFrog surveyed them, 48% needed more than a week to produce proof of compliance when auditors actually asked. Point-in-time checks create the feeling of compliance, but they don’t actually ensure compliance.

The pace is only accelerating. NIST SSDF already gates federal procurement, while the EU Cyber Resilience Act (CRA) comes into enforcement this September. For the first time, personal liability for security leaders is written into the regulation. More frameworks are under preparation, and each one requires your team to start the mapping and policy work from scratch.

At the same time, the software those frameworks need to govern is changing faster than any manual process can track. AI agents are now writing code, reviewing PRs, and pushing changes at a volume no compliance review was built to handle. The software your team ships today looks nothing like what it looked like two years ago. The frameworks trying to govern software, and even more so AI development, are still being written. You’re using 2025’s practices to face a 2027 threat model.

A year ago at swampUP, we launched JFrog AppTrust to bring continuous governance to your software supply chain. Governance that runs with every release, not before every audit.

Over the past year, one thing became clear: Continuous governance only works if you can actually enforce policy according to the frameworks for which your organization is held accountable. Right now, converting these frameworks into enforceable policies is still a manual job that starts again from scratch every time a new regulation is introduced.

That is the DevGovOps dilemma. DevGovOps is the practice of making governance and compliance a continuous output of your software development operations, not a point-in-time exercise before every audit. AppTrust is how to run it.

Bridging the Gap Between Requirements and Enforcement

The gap sits between understanding what a framework requires and building a workable system of enforcement around it. Translating a legal control into enforceable Policy-as-Code (PaC) rules takes someone who deeply understands both regulations and how they can be enforced on a platform.

Take CRA’s requirement to “follow all secure coding practices appropriate to development languages and environments.” What policy does that become? Which pipeline stage enforces it? The answer has to be written in Rego, the policy language behind OPA (Open Policy Agent), tested, and scoped to the right applications. That takes time most teams don’t have every time a new regulation lands.

And that is only the first problem. Even after the policies exist, there is still no way to see how much of the framework they actually cover. AI-generated code still has to comply with CRA and NIST SSDF, but the policies governing it often don’t exist yet. Gaps go undetected until an auditor pulls 20 random commits from your production history and starts asking questions.

The challenge does not end with enforcement. It ends with the audit.

What do Out-of-the-Box Compliance Frameworks actually mean for your AppSec team?

This week at swampUP 2026, JFrog shipped Out-of-the-Box Compliance Frameworks in AppTrust, starting with NIST SSDF and EU CRA. The controls your team was mapping manually are now pre-mapped to Policy-as-Code rules in AppTrust. All you need to do is select the framework, and enforcement starts.

Screenshot of the JFrog Platform Compliance Catalog interface featuring EU CRA and NIST SSDF frameworks.
AppTrust ships NIST SSDF and EU CRA as ready-to-enforce frameworks. More frameworks are in active development.

JFrog AppTrust ships with a compliance catalog. AppSec teams select a framework and see every control already translated into plain requirements, each mapped to specific Policy-as-Code rules that place policy enforcement at your release gates. There is no Rego to write and no manual mapping required. Controls that AppTrust does not cover are clearly flagged. Controls already satisfied by running AppTrust are shown as covered by default.

Because AppTrust governance co-exists on the same system of record as your artifacts, the coverage score always reflects the actual state of production, not a policy document last updated before the last sprint.

Out-of-the-Box Compliance Frameworks handle the policy side. But enforcement is only as strong as the data behind it. Today, that data includes more than Git commits, pull requests, and Jira tickets. AI agents are writing code, making decisions, and pushing changes autonomously. Without visibility into what an agent did and why, it is impossible to govern what actually ships.

That is why AppTrust also brings full traceability across every stage of your SDLC, capturing agent intent sessions, Git commits, pull requests, and Jira tickets, all connected to the artifacts that ship. The framework tells your policies what to check, while the traceability data gives them real data to check against.

Dev managers control the rollout; AppSec controls the rules

Framework configuration and rollout are separated by design. AppSec owns which controls apply, which rules are active, and which policies enforce them. Development managers own the rollout, including which applications fall under the framework, which rules run as warnings versus hard failures, and how long teams have before a warning converts to a blocked package.

Screenshot of the Edit NIST SSDF interface showing security controls and automated requirements.
   NIST SSDF controls mapped to plain requirements inside AppTrust.

CISOs want answers, not spreadsheets

The question an auditor asks is not which policies you have, it is whether you can prove they ran, on every release, across every application. CRA makes that question personal: CISOs now carry personal liability for the answer. Documented proof needs to be available in hours, not assembled in weeks.

According to The CISO Society’s 2025 The State of Continuous Controls Monitoring survey, 48% of CISOs name evidence collection as one of their top operational challenges. Under CRA, a documented compliance gap carries a penalty of up to $17M, or 2.5% of global annual revenue.

Out-of-the-Box Compliance Frameworks Are Available Now

Out-of-the-Box Compliance Frameworks ship in JFrog AppTrust as part of the Ultimate Security Bundle, generally available this month. The CRA and NIST SSDF frameworks are already live. Additional frameworks are in active development.

If your organization is tracking CRA, NIST SSDF, or any regulation with an SDLC component, JFrog AppTrust removes the translation layer between what the regulation requires and what your release gates enforce. The result: simpler enforcement, full traceability, continuous governance, and auditability by default.

See JFrog AppTrust in action. Schedule a demo or take an online tour.