Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Craftifact serves as a European SaaS platform designed for software teams that require dependable package distribution alongside enhanced supply-chain transparency. It offers various repository types including hosted, proxy, and group repositories for technologies such as Maven, npm, Python, OCI/Docker, and Go, all accompanied by a user-friendly browser interface for managing artifact metadata and repositories. Users can upload CycloneDX SBOMs and, for certain hosted items, generate them to be associated with specific artifacts or OCI digests. Teams have the capability to scrutinize dependencies and assess vulnerability, licensing, exposed-secret, and policy alerts in close proximity to the associated artifact. Access management is facilitated through OIDC, RBAC, group configurations, robot accounts, and scoped tokens, all supported by APIs designed for CI/CD and evidence workflows. Operated by a German firm under EU jurisdiction, Craftifact includes features such as managed updates, monitoring, and backups within the plan’s scope, ensuring predictable pricing that does not rely on seat counts. While it aids teams in fulfilling CRA-relevant technical preparations, it is important to note that it does not serve as a substitute for legal advice or conformity assessments. This combination of features makes Craftifact an essential tool for teams focused on both efficiency and compliance in their software development processes.
Description
Investing time and resources to prepare for the Cybersecurity Maturity Model Certification (CMMC) assessment is a significant undertaking for organizations. Those managing Controlled Unclassified Information (CUI) in the defense industrial sector should anticipate a certification from an authorized CMMC 3rd Party Assessment Organization (C3PAO) to validate their adherence to NIST SP 800-171 security standards. Assessors will scrutinize how contractors fulfill each of the 320 objectives related to all relevant assets, which encompass personnel, facilities, and technologies. The evaluation process is likely to include artifact reviews, interviews with essential staff, and examinations of technical, administrative, and physical controls. As they compile their evidence, organizations must create clear connections between the artifacts, the security requirement objectives, and the assets under consideration. This comprehensive approach will not only aid in meeting certification criteria but also enhance overall security posture.
API Access
Has API
No
API Access
Has API
Yes
Integrations
Amazon Web Services (AWS)
No
Mercury One Plus
No
Pricing Details
€99/month
Optional add-ons and annual discount available.
Free Trial
Yes
Free Version
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
Yes
In Person
Yes
Vendor Details
Company Name
SoluForge
Founded
2025
Country
Germany
Website
craftifact.com
Vendor Details
Company Name
Etactics
Country
United States
Website
etactics.com/cmmc