<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/every-new-compliance-framework-restarts-the-same-fire-drill-it-doesn-t-have-to--9vl0zsoiy" -->

---
title: Every New Compliance Framework Restarts the Same Fire...
description: JFrog announces Out-of-the-Box Compliance Frameworks in AppTrust, starting with NIST SSDF and EU Cyber Resilience Act (CRA), pre-mapping legal controls to...
canonical: https://daily.dev/posts/every-new-compliance-framework-restarts-the-same-fire-drill-it-doesn-t-have-to--9vl0zsoiy
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Every New Compliance Framework Restarts the Same Fire Drill. It Doesn’t Have To. | daily.dev
og:description: JFrog announces Out-of-the-Box Compliance Frameworks in AppTrust, starting with NIST SSDF and EU Cyber Resilience Act (CRA), pre-mapping legal controls to...
og:url: https://daily.dev/posts/every-new-compliance-framework-restarts-the-same-fire-drill-it-doesn-t-have-to--9vl0zsoiy
og:image: https://api.daily.dev/og/posts/9VL0zSOIY.png
og:image:alt: Every New Compliance Framework Restarts the Same Fire Drill. It Doesn’t Have To.
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Every New Compliance Framework Restarts the Same Fire Drill. It Doesn’t Have To.

**[JFrog](https://daily.dev/sources/jfrog)** · 6 min read · 0 upvotes · 0 comments

## Summary

JFrog announces Out-of-the-Box Compliance Frameworks in AppTrust, starting with NIST SSDF and EU Cyber Resilience Act (CRA), pre-mapping legal controls to Policy-as-Code rules so AppSec teams no longer need to manually write Rego policies for every new regulation. The frameworks are part of the Ultimate Security Bundle, generally available this month, and combine coverage scoring with full SDLC traceability, including AI agent activity, Git commits, PRs, and Jira tickets, to give continuous audit-ready evidence instead of point-in-time compliance checks.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://jfrog.com/blog/jfrog-apptrust-enforces-compliance>

## Questions this post answers

### What new feature did JFrog AppTrust add for compliance with EU CRA and NIST SSDF?

JFrog AppTrust now ships Out-of-the-Box Compliance Frameworks that pre-map NIST SSDF and EU CRA controls to Policy-as-Code rules, eliminating the need to manually write Rego policies for each regulation. Teams select a framework and enforcement starts at release gates immediately; uncovered controls are flagged and covered ones are marked by default. It ships as part of the Ultimate Security Bundle, generally available this month.

_Teams tracking CRA or NIST SSDF deadlines can follow platform updates like this via daily.dev._

### What is the penalty for a compliance gap under the EU Cyber Resilience Act?

A documented compliance gap under the EU Cyber Resilience Act (CRA) carries a penalty of up to $17 million, or 2.5% of global annual revenue. The CRA also introduces personal liability for security leaders, and it comes into enforcement this September, making evidence collection an urgent concern for CISOs.

_Security leaders weighing CRA exposure can track enforcement news like this on daily.dev._

## Similar posts on daily.dev

- [Automate NIST SSDF Compliance: A Technical Guide to Policy as Code in JFrog AppTrust](https://daily.dev/posts/automate-nist-ssdf-compliance-a-technical-guide-to-policy-as-code-in-jfrog-apptrust-u3kyedcxx) · JFrog · 0 upvotes · 0 comments
- [GitLab compliance frameworks: Adhere to SOC 2 in minutes](https://daily.dev/posts/gitlab-compliance-frameworks-adhere-to-soc-2-in-minutes-5b3wqsxuc) · GitLab · 0 upvotes · 0 comments
- [The Cyber Resilience Act and SaaS: Why Compliance is Only Half the Battle](https://daily.dev/posts/the-cyber-resilience-act-and-saas-why-compliance-is-only-half-the-battle-l7kcacs4t) · Security Boulevard · 0 upvotes · 0 comments
- [Announcing JFrog AppTrust: Building Unshakeable Trust in Every Application You Deliver](https://daily.dev/posts/announcing-jfrog-apptrust-building-unshakeable-trust-in-every-application-you-deliver-czk8yrnsc) · JFrog · 1 upvotes · 0 comments
- [Cyber Resilience Act Compliance \(CRA\) with Aikido Security](https://daily.dev/posts/cyber-resilience-act-compliance-cra-with-aikido-security-0yzywsub3) · Aikido Security · 0 upvotes · 0 comments

---

Tags: [#compliance](https://daily.dev/tags/compliance), [#devsecops](https://daily.dev/tags/devsecops), [#policy-as-code](https://daily.dev/tags/policy-as-code)

[View this post on daily.dev](https://daily.dev/posts/every-new-compliance-framework-restarts-the-same-fire-drill-it-doesn-t-have-to--9vl0zsoiy)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Every New Compliance Framework Restarts the Same Fire Drill. It Doesn’t Have To.","url":"https://daily.dev/posts/every-new-compliance-framework-restarts-the-same-fire-drill-it-doesn-t-have-to--9vl0zsoiy","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/every-new-compliance-framework-restarts-the-same-fire-drill-it-doesn-t-have-to--9vl0zsoiy"},"datePublished":"2026-09-02T11:59:58.622Z","dateModified":"2026-09-03T15:20:54.770Z","description":"JFrog announces Out-of-the-Box Compliance Frameworks in AppTrust, starting with NIST SSDF and EU Cyber Resilience Act (CRA), pre-mapping legal controls to...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1890b36b6fc0f7a65159fbdc5d89aa60?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/1890b36b6fc0f7a65159fbdc5d89aa60?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"JFrog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"JFrog","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/b11bf37102384ac9983be701b2cf7cd5","url":"https://daily.dev/sources/jfrog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/every-new-compliance-framework-restarts-the-same-fire-drill-it-doesn-t-have-to--9vl0zsoiy","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"compliance,devsecops,policy-as-code","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"JFrog","item":"https://daily.dev/sources/jfrog"},{"@type":"ListItem","position":3,"name":"Every New Compliance Framework Restarts the Same Fire Drill. It Doesn’t Have To."}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/every-new-compliance-framework-restarts-the-same-fire-drill-it-doesn-t-have-to--9vl0zsoiy#faq","mainEntity":[{"@type":"Question","name":"What new feature did JFrog AppTrust add for compliance with EU CRA and NIST SSDF?","acceptedAnswer":{"@type":"Answer","text":"JFrog AppTrust now ships Out-of-the-Box Compliance Frameworks that pre-map NIST SSDF and EU CRA controls to Policy-as-Code rules, eliminating the need to manually write Rego policies for each regulation. Teams select a framework and enforcement starts at release gates immediately; uncovered controls are flagged and covered ones are marked by default. It ships as part of the Ultimate Security Bundle, generally available this month. Teams tracking CRA or NIST SSDF deadlines can follow platform updates like this via daily.dev."}},{"@type":"Question","name":"What is the penalty for a compliance gap under the EU Cyber Resilience Act?","acceptedAnswer":{"@type":"Answer","text":"A documented compliance gap under the EU Cyber Resilience Act (CRA) carries a penalty of up to $17 million, or 2.5% of global annual revenue. The CRA also introduces personal liability for security leaders, and it comes into enforcement this September, making evidence collection an urgent concern for CISOs. Security leaders weighing CRA exposure can track enforcement news like this on daily.dev."}}]}
```

