FedRAMP Authorized — Moderate Impact

JFrog Government Cloud by JFrog. 6 compliance features verified.

DevOps & Development

JFrog Government Cloud

by JFrog

Moderate ImpactAuthorized

Impact Level

Moderate

Status

Authorized

Pricing

mid market

Authorization Date: July 20, 2022 | Sponsoring Agency: GSA

Overview

JFrog Government Cloud provides FedRAMP Moderate authorized software supply chain management including artifact management, container registry, and security scanning. It serves as a universal artifact repository supporting all major package formats. The platform enables secure software distribution and DevSecOps automation.

Key Features

FedRAMP Moderate baseline controls
Universal artifact repository
Container registry and scanning
Build info and provenance
Xray security scanning
Software distribution automation

Certifications & Authorizations

FedRAMP Moderate Authorization (3PAO assessed)SOC 2 Type IIISO 27001:2013FIPS 140-2 Level 1 (cryptographic modules)NIST 800-53 Rev 4 controls implementationDoD SRG IL2 compatibleAWS GovCloud FedRAMP High infrastructure inheritance

Deployment Options

AWS GovCloud (US-East) — FedRAMP Moderate authorized infrastructure
AWS GovCloud (US-West) — FedRAMP Moderate authorized infrastructure
Multi-region deployment across AWS GovCloud regions for high availability
Dedicated tenant isolation within AWS GovCloud infrastructure
API-based integration with existing CI/CD pipelines in government cloud environments
Hybrid connectivity to on-premises development environments via AWS Direct Connect

NIST 800-171 Compliance Coverage

88% of controls covered

How to Procure JFrog Government Cloud for Defense Contracts

JFrog Government Cloud is available through GSA Multiple Award Schedule (MAS) under SIN 518210C (IT Professional Services) and SIN 132-51 (IT Software). The product is also procurable via SEWP V contracts and CIO-SP3 OASIS. Government pricing includes significant discounts from commercial rates, typically 15-25% below standard enterprise pricing. The authorization boundary encompasses the complete JFrog Artifactory, Xray security scanning, and Distribution services within AWS GovCloud infrastructure. Contracting officers must approve the Software Supply Chain Management categorization and validate that artifact storage meets organizational data classification requirements. The SSP clearly defines the tenant isolation model and data residency within AWS GovCloud regions. Procurement timeline typically spans 60-90 days including technical evaluation, security review, and contract negotiation. For CMMC assessments, include JFrog Government Cloud within your assessment boundary as a cloud service provider, documenting the shared responsibility model for security controls. The FedRAMP authorization provides significant control inheritance, reducing assessment scope. Ensure your CMMC assessment includes artifact integrity verification processes and supply chain risk management controls implemented through JFrog's security scanning capabilities.

Compliance Cross-References

JFrog Government Cloud directly supports DFARS 252.204-7012 compliance through comprehensive artifact scanning and vulnerability management capabilities, addressing covered defense information protection requirements. For DFARS 252.239-7010 cloud services clause, the FedRAMP Moderate authorization satisfies government-approved cloud service requirements. The platform supports multiple NIST 800-171 control families: Access Control (AC) through role-based permissions and authentication integration, System and Communications Protection (SC) via encrypted artifact storage and transmission, and Audit and Accountability (AU) through comprehensive logging of all artifact operations. For CMMC Level 2, JFrog Government Cloud addresses Asset Management (AM), Access Control (AC), and System and Information Integrity (SI) domains through centralized artifact governance, fine-grained access controls, and continuous security scanning. The DoD Cloud Computing SRG IL2 requirements are met through the AWS GovCloud infrastructure and additional JFrog security controls for software supply chain protection. The service's artifact integrity verification and provenance tracking directly support supply chain risk management requirements across all compliance frameworks.

Defense Contractor Use Case

Defense contractors use JFrog Government for managing build artifacts, securing their software supply chain, and ensuring only approved components are used in government deliverables.

Frequently Asked Questions

What is the FedRAMP authorization level for JFrog Government Cloud?

JFrog Government Cloud is authorized at the FedRAMP Moderate impact level, with authorization granted on 2022-07-20 sponsored by GSA. The FedRAMP Moderate baseline includes approximately 325 security controls covering confidentiality, integrity, and availability.

Can defense contractors use JFrog Government Cloud for CUI?

JFrog Government Cloud is authorized at the FedRAMP Moderate baseline. While FedRAMP Moderate covers a broad range of government data, defense contractors handling CUI should carefully evaluate whether Moderate controls meet their specific DFARS 252.204-7012 and NIST 800-171 requirements. Some CUI categories may require FedRAMP High authorization depending on the sensitivity of the data and contract requirements.

How does JFrog Government Cloud pricing compare to commercial?

JFrog Government Cloud government pricing is generally competitive with commercial pricing, though the government edition may carry a premium of 10-20% to cover FedRAMP compliance and dedicated infrastructure costs. Mid-market organizations can often access government pricing through GSA Schedule contracts or reseller partners. Contact JFrog for a quote tailored to your organization size and requirements.

Browse All FedRAMP Authorized Tools

Search and filter 80+ FedRAMP authorized products for your defense contracting needs.

Open FedRAMP Finder

Get a defensible CUI architecture

This JFrog Government Cloud FedRAMP profile flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures