Risk Management Framework (RMF) Compliance | Sonatype Platform
Cookiebot by Usercentrics - opens in a new window
This website uses cookies
We use cookies to understand how you use our site and to improve your experience. This includes personalizing content and advertising with the use of third-party business partners. To learn more, [click here](/content/privacy-policy ""/index.html).
[#GPC_BANNER_ICON#]
[#GPC_TOAST_TEXT#]
Consent Selection
Necessary
Preferences
Statistics
Marketing
Details
- Necessary 66
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
- Amazon\ 2 [Learn more about this provider
cookies.js Determines whether the visitor has accepted the cookie consent box. This ensures that the cookie consent box will not be presented again upon re-entry.
Maximum Storage Duration: SessionType: HTTP Cookie
sp_window_session Maintains the session for the embedded Spotify player to ensure it functions correctly during the current visit.
Maximum Storage Duration: SessionType: HTTP Cookie
- Anchor FM\ 4 [Learn more about this provider
__Host-device_id Used by Spotify to identify the user’s device and enable secure authentication and playback of embedded Spotify content.
Maximum Storage Duration: SessionType: HTTP Cookie
anchor-website#local-forage-detect-blob-support Detects browser storage capabilities required for embedded Spotify podcast playback.
Maximum Storage Duration: PersistentType: IndexedDB
ES||STORAGE_ID Stores a technical identifier required to manage local storage for embedded Spotify podcast playback.
Maximum Storage Duration: PersistentType: HTML Local Storage
ES|s4p-hosted|STORAGE_ID Stores a technical identifier required to manage local storage for embedded Spotify podcast playback.
Maximum Storage Duration: PersistentType: HTML Local Storage
- BrightTalk\ 1 [Learn more about this provider
ga_clientId Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
Maximum Storage Duration: PersistentType: HTML Local Storage
- Businesswire\ 3 [Learn more about this provider
ak_bmsc This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
Maximum Storage Duration: 1 dayType: HTTP Cookie
f5avraaaaaaaaaaaaaaaa_session_ Registers the website's speed and performance. This function can be used in context with statistics and load-balancing.
Maximum Storage Duration: SessionType: HTTP Cookie
JSESSIONID Preserves users states across page requests.
Maximum Storage Duration: SessionType: HTTP Cookie
- Cookiebot\ 1 [Learn more about this provider
CookieConsent Stores the user's cookie consent state for the current domain
Maximum Storage Duration: 1 yearType: HTTP Cookie
- Github\ 2 [Learn more about this provider
_gh_sess Preserves users states across page requests.
Maximum Storage Duration: SessionType: HTTP Cookie
logged_in Registers whether the user is logged in. This allows the website owner to make parts of the website inaccessible, based on the user's log-in status.
Maximum Storage Duration: 1 yearType: HTTP Cookie
- Google\ 6 [Learn more about this provider
Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness.
_ga [x3] Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
Maximum Storage Duration: 2 yearsType: HTTP Cookie
_gid [x2] Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
Maximum Storage Duration: 1 dayType: HTTP Cookie
_GRECAPTCHA This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
Maximum Storage Duration: 180 daysType: HTTP Cookie
- HubSpot\ 6 [Learn more about this provider
rc::a This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
Maximum Storage Duration: PersistentType: HTML Local Storage
rc::b This cookie is used to distinguish between humans and bots.
Maximum Storage Duration: SessionType: HTML Local Storage
rc::c This cookie is used to distinguish between humans and bots.
Maximum Storage Duration: SessionType: HTML Local Storage
rc::f This cookie is used to distinguish between humans and bots.
Maximum Storage Duration: PersistentType: HTML Local Storage
__hs_do_not_track Stores the user's cookie consent state for the current domain
Maximum Storage Duration: 180 daysType: HTTP Cookie
cookietest This cookie is used to determine if the visitor has accepted the cookie consent box.
Maximum Storage Duration: SessionType: HTTP Cookie
- LinkedIn\ 2 [Learn more about this provider
bcookie Used in order to detect spam and improve the website's security.
Maximum Storage Duration: 1 yearType: HTTP Cookie
li_gc Stores the user's cookie consent state for the current domain
Maximum Storage Duration: 180 daysType: HTTP Cookie
- Sonatype\ 1 [Learn more about this provider
_vwo_consent Stores the user’s cookie consent preferences for VWO to ensure that testing and tracking scripts are only executed in accordance with the user’s consent choices.
Maximum Storage Duration: SessionType: HTTP Cookie
- Soundcloud\ 1 [Learn more about this provider
datadome Used in context with the website's BotManager. The BotManager detects, categorizes and compiles reports on potential bots trying to access the website.
Maximum Storage Duration: SessionType: HTTP Cookie
__cflb [x2] Registers which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.
Maximum Storage Duration: 1 dayType: HTTP Cookie
#.#-#-#-#-#.ack Used to contain user’s survey and quiz answers in Local Storage.
Maximum Storage Duration: PersistentType: HTML Local Storage
#.#-#-#-#-#.inProgress Used to contain user’s survey and quiz answers in Local Storage.
Maximum Storage Duration: PersistentType: HTML Local Storage
#.#-#-#-#-#.queue Used to contain user’s survey and quiz answers in Local Storage.
Maximum Storage Duration: PersistentType: HTML Local Storage
#.#-#-#-#-#.reclaimEnd Used to contain user’s survey and quiz answers in Local Storage.
Maximum Storage Duration: PersistentType: HTML Local Storage
#.#-#-#-#-#.reclaimStart Used to contain user’s survey and quiz answers in Local Storage.
Maximum Storage Duration: PersistentType: HTML Local Storage
test_rudder_cookie This cookie determines whether the browser accepts cookies.
Maximum Storage Duration: 1 yearType: HTTP Cookie
__cf_bm [x19] This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
Maximum Storage Duration: 1 dayType: HTTP Cookie
__q_state_f3KQDBMfpPYzsDQe Stores session state required for embedded Qualified chat functionality.
Maximum Storage Duration: 10 yearsType: HTTP Cookie
_cq_s CHEQ cookies are used to protect websites, applications, and online services from bots, automated abuse, fraud, and other invalid or malicious activity.
Maximum Storage Duration: 7 daysType: HTTP Cookie
_cq_session CHEQ cookies are used to protect websites, applications, and online services from bots, automated abuse, fraud, and other invalid or malicious activity.
Maximum Storage Duration: 2 yearsType: HTTP Cookie
_cq_suid This cookie is used to distinguish between humans and bots.
Maximum Storage Duration: SessionType: HTTP Cookie
_cq_check Determines whether the user has accepted the cookie consent box.
Maximum Storage Duration: SessionType: HTTP Cookie
cg_uuid Necessary for the website security.
Maximum Storage Duration: 11 monthsType: HTTP Cookie
sc_anonymous_id Used in context with the 3D-view-function on the website.
Maximum Storage Duration: 10 yearsType: HTTP Cookie
visitorId Preserves users states across page requests.
Maximum Storage Duration: 1 yearType: HTTP Cookie
_cfuvid [x2] This cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators.
Maximum Storage Duration: SessionType: HTTP Cookie
- Preferences 10
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
- Amazon\ 3 [Learn more about this provider
reduxPersist%3AlocalStorage Stores application state locally to ensure the proper functioning of embedded Spotify podcast playback.
Maximum Storage Duration: 7 daysType: HTTP Cookie
reduxPersist%3Atutorial Stores user interface state related to tutorial or guidance features for embedded Spotify podcast content.
Maximum Storage Duration: 7 daysType: HTTP Cookie
reduxPersistIndex Maintains website settings across multiple visits.
Maximum Storage Duration: 7 daysType: HTTP Cookie
- Anchor FM\ 2 [Learn more about this provider
anchor-website#keyvaluepairs Stores configuration and state information to enable and manage embedded Spotify podcast playback.
Maximum Storage Duration: PersistentType: IndexedDB
com.spotify.single.item.cache:anchor-public-website Caches podcast content data to enable reliable loading and playback of embedded Spotify episodes.
Maximum Storage Duration: PersistentType: HTML Local Storage
- HubSpot\ 1 [Learn more about this provider
hubspot-modern-theme Stores the user's HubSpot interface theme preference to provide a consistent visual experience across sessions.
Maximum Storage Duration: PersistentType: HTML Local Storage
- LinkedIn\ 1 [Learn more about this provider
lidc Registers which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.
Maximum Storage Duration: 1 dayType: HTTP Cookie
nv_visitor_consent Stores whether a visitor has already provided consent or identification information so they aren't repeatedly prompted. It supports the user experience rather than analytics or advertising. Navattic describes visitor cookies as enabling previously identified visitors to skip subsequent form fills when this optional feature is enabled.
Maximum Storage Duration: 180 daysType: HTTP Cookie
theme-ui-color-mode Remembers the user's preferences in terms of font size and colours on the website.
Maximum Storage Duration: PersistentType: HTML Local Storage
__q_local_form_debug Supports debugging and proper operation of embedded Qualified chat and form features.
Maximum Storage Duration: PersistentType: HTML Local Storage
- Statistics 24
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
- Amazon\ 1 [Learn more about this provider
sp_t Collects anonymized usage data to measure performance and interactions with embedded Spotify podcast content.
Maximum Storage Duration: SessionType: HTTP Cookie
- Anchor FM\ 2 [Learn more about this provider
ES||INSTALLATION_ID Assigns an installation identifier to support aggregated usage measurement for embedded Spotify podcast content.
Maximum Storage Duration: PersistentType: HTML Local Storage
ES|s4p-hosted|INSTALLATION_ID Assigns an installation identifier to support aggregated usage measurement for embedded Spotify podcast content.
Maximum Storage Duration: PersistentType: HTML Local Storage
- Github\ 1 [Learn more about this provider
_octo Pending
Maximum Storage Duration: 1 yearType: HTTP Cookie
- Google\ 1 [Learn more about this provider
Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness.
_ga_# Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels.
Maximum Storage Duration: 2 yearsType: HTTP Cookie
- HubSpot\ 5 [Learn more about this provider
__hssc Identifies if the cookie data needs to be updated in the visitor's browser.
Maximum Storage Duration: 1 dayType: HTTP Cookie
__hssrc Used to recognise the visitor's browser upon reentry on the website.
Maximum Storage Duration: SessionType: HTTP Cookie
__hstc Sets a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes.
Maximum Storage Duration: 180 daysType: HTTP Cookie
hubspotutk Sets a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes.
Maximum Storage Duration: 180 daysType: HTTP Cookie
hs-cta-interactions#cta Tracks interactions with call-to-action elements to measure engagement through HubSpot.
Maximum Storage Duration: PersistentType: IndexedDB
- Sonatype\ 1 [Learn more about this provider
_vis_opt_exp_#_combi Used by Visual Website Optimizer to ensure that the same user interface variant is displayed for each visit, if the user is participating in a design experiment.
Maximum Storage Duration: 100 daysType: HTTP Cookie
- Soundcloud\ 1 [Learn more about this provider
number(#) Used to track user’s interaction with embedded content.
Maximum Storage Duration: SessionType: HTML Local Storage
- VWO\ 3 [Learn more about this provider
analyze This cookie is used by the website’s operator in context with multi-variate testing. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.
Maximum Storage Duration: SessionType: Pixel Tracker
collect/v.gif Pending
Maximum Storage Duration: SessionType: Pixel Tracker
l.gif This cookie is used by the website’s operator in context with multi-variate testing. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.
Maximum Storage Duration: SessionType: Pixel Tracker
rl_anonymous_id Registers a unique ID for the visitor in order for the website to recognize the visitor upon re-entry.
Maximum Storage Duration: 1 yearType: HTTP Cookie
rl_page_init_referring_domain Stores the domain of the website that originally referred the visitor. Used for analytics and attribution to understand how visitors arrive at the site and measure traffic sources.
Maximum Storage Duration: 1 yearType: HTTP Cookie
rl_session Sets a unique ID for the session. This allows the website to obtain data on visitor behaviour for statistical purposes.
Maximum Storage Duration: 1 yearType: HTTP Cookie
Zotahoma, geneva, sans-seriftahoma, geneva, sans-serifmozilla/5.0 (windows nt 10.0; win64; x64) applewebkit/537.36 (khtml, like gecko) chrome/141.0.7390.37 safari/537.36 Stores browser characteristics to support visitor identification and analytics, including browser and device attributes used to improve measurement and distinguish unique visitors.
Maximum Storage Duration: PersistentType: HTML Local Storage
nv_uid Assigns a pseudonymous identifier to measure engagement with interactive product walkthroughs via Navattic.
Maximum Storage Duration: 1 yearType: HTTP Cookie
__q_domainTest Used in context with Account-Based-Marketing (ABM). The cookie registers data such as IP-addresses, time spent on the website and page requests for the visit. This is used for retargeting of multiple users rooting from the same IP-addresses. ABM usually facilitates B2B marketing purposes.
Maximum Storage Duration: SessionType: HTTP Cookie
tracker/tc_imp.gif Collects data on the user’s navigation and behavior on the website. This is used to compile statistical reports and heatmaps for the website owner.
Maximum Storage Duration: SessionType: Pixel Tracker
ziwsSession Collects statistics on the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.
Maximum Storage Duration: SessionType: HTML Local Storage
ziwsSessionId Collects statistics on the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.
Maximum Storage Duration: SessionType: HTML Local Storage
- Marketing 60
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
- Meta Platforms, Inc.\ 3 [Learn more about this provider
lastExternalReferrer Detects how the user reached the website by registering their last URL-address.
Maximum Storage Duration: PersistentType: HTML Local Storage
lastExternalReferrerTime Detects how the user reached the website by registering their last URL-address.
Maximum Storage Duration: PersistentType: HTML Local Storage
_fbp Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers.
Maximum Storage Duration: 3 monthsType: HTTP Cookie
6suuid Registers user behaviour and navigation on the website, and any interaction with active campaigns. This is used for optimizing advertisement and for efficient retargeting.
Maximum Storage Duration: 400 daysType: HTTP Cookie
- Anchor FM\ 1 [Learn more about this provider
sp_tr Tracks user interactions across Spotify services to support advertising measurement and campaign attribution.
Maximum Storage Duration: SessionType: HTTP Cookie
- Google\ 6 [Learn more about this provider
Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness.
IDE Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.
Maximum Storage Duration: 400 daysType: HTTP Cookie
test_cookie Pending
Maximum Storage Duration: 1 dayType: HTTP Cookie
pagead/1p-conversion/#/ Tracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.
Maximum Storage Duration: SessionType: Pixel Tracker
pagead/1p-user-list/# Tracks if the user has shown interest in specific products or events across multiple websites and detects how the user navigates between sites. This is used for measurement of advertisement efforts and facilitates payment of referral-fees between websites.
Maximum Storage Duration: SessionType: Pixel Tracker
_gcl_au Used to measure the efficiency of the website’s advertisement efforts, by collecting data on the conversion rate of the website’s ads across multiple websites.
Maximum Storage Duration: 3 monthsType: HTTP Cookie
_gcl_ls Tracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.
Maximum Storage Duration: PersistentType: HTML Local Storage
- HubSpot\ 4 [Learn more about this provider
__hmpl Collects information on user preferences and/or interaction with web-campaign content - This is used on CRM-campaign-platform used by website owners for promoting events or products.
Maximum Storage Duration: SessionType: HTML Local Storage
__ptq.gif Sends data to the marketing platform Hubspot about the visitor's device and behaviour. Tracks the visitor across devices and marketing channels.
Maximum Storage Duration: SessionType: Pixel Tracker
HUBLYTICS_EVENTS_53 [x2] Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that they are shown the same advertisement.
Maximum Storage Duration: SessionType: HTML Local Storage
- Microsoft\ 8 [Learn more about this provider
_uetsid Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.
Maximum Storage Duration: PersistentType: HTML Local Storage
_uetsid_exp Contains the expiry-date for the cookie with corresponding name.
Maximum Storage Duration: PersistentType: HTML Local Storage
_uetvid Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.
Maximum Storage Duration: PersistentType: HTML Local Storage
_uetvid_exp Contains the expiry-date for the cookie with corresponding name.
Maximum Storage Duration: PersistentType: HTML Local Storage
MR Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.
Maximum Storage Duration: 7 daysType: HTTP Cookie
MUID Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronising the ID across many Microsoft domains.
Maximum Storage Duration: 1 yearType: HTTP Cookie
_uetsid Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that they are shown the same advertisement.
Maximum Storage Duration: 1 dayType: HTTP Cookie
_uetvid Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.
Maximum Storage Duration: 1 yearType: HTTP Cookie
- Reddit\ 3 [Learn more about this provider
rp.gif Necessary for the implementation of the Reddit.com's share-button function.
Maximum Storage Duration: SessionType: Pixel Tracker
_rdt_uuid [x2] Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.
Maximum Storage Duration: 3 monthsType: HTTP Cookie
- Sonatype\ 14 [Learn more about this provider
_vis_opt_s Used by Visual Website Optimizer to determine if the visitor is participating in a design experiment.
Maximum Storage Duration: 100 daysType: HTTP Cookie
_vis_opt_test_cookie Used to check if the user's browser supports cookies.
Maximum Storage Duration: SessionType: HTTP Cookie
_vwo_ds Collects data on the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded with the purpose of generating reports for optimising the website content.
Maximum Storage Duration: 2 monthsType: HTTP Cookie
_vwo_sn Collects statistics on the visitor's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.
Maximum Storage Duration: 1 dayType: HTTP Cookie
_vwo_uuid Used by Visual Website Optimizer to ensure that the same user interface variant is displayed for each visit, if the user is participating in a design experiment.
Maximum Storage Duration: 1 yearType: HTTP Cookie
_vwo_uuid_v2 This cookie is set to make split-tests on the website, which optimizes the website's relevance towards the visitor – the cookie can also be set to improve the visitor's experience on a website.
Maximum Storage Duration: 1 yearType: HTTP Cookie
_vwo_584728_config Stores configuration settings for VWO to support website analytics and optimization testing.
Maximum Storage Duration: PersistentType: HTML Local Storage
_vwo_eventHist Stores visitor event history data used by VWO for analytics, A/B testing, and website optimization.
Maximum Storage Duration: PersistentType: HTML Local Storage
_vwo_eventHistLastSession Used by VWO to retain event interaction history from the user’s last browsing session to support analytics and experiment continuity.
Maximum Storage Duration: PersistentType: HTML Local Storage
_vwo_eventHistSession Used by VWO to track visitor interactions and experiment events within a browsing session.
Maximum Storage Duration: PersistentType: HTML Local Storage
_vwo_nls_q_# Collects data on user interactions to support website analytics and optimization testing through VWO.
Maximum Storage Duration: PersistentType: HTML Local Storage
_vwo_nlsCache Stores cached visitor session and optimization data used by VWO to improve experiment performance and reduce repeated data processing.
Maximum Storage Duration: PersistentType: HTML Local Storage
_vwo_visProps Used by VWO to retain visitor attributes and properties for analytics, A/B testing, and experiment targeting purposes.
Maximum Storage Duration: PersistentType: HTML Local Storage
vwoSn This cookie is set to make split-tests on the website, which optimizes the website's relevance towards the visitor – the cookie can also be set to improve the visitor's experience on a website.
Maximum Storage Duration: PersistentType: HTML Local Storage
- Soundcloud\ 2 [Learn more about this provider
dd_testcookie Pending
Maximum Storage Duration: SessionType: HTTP Cookie
ddSession_datadome Pending
Maximum Storage Duration: PersistentType: HTML Local Storage
- TechTarget\ 1 [Learn more about this provider
a/gif.gif Used by Informa TechTarget to measure interactions with marketing content, identify website visitors, and support campaign attribution and lead generation.
Maximum Storage Duration: SessionType: Pixel Tracker
- Twitter Inc.\ 1 [Learn more about this provider
i/jot/embeds Used by X (formerly Twitter) to support embedded content and to measure and personalize advertising and user interactions across websites.
Maximum Storage Duration: SessionType: Pixel Tracker
- VWO\ 2 [Learn more about this provider
s.gif Registers user behaviour and navigation on the website, and any interaction with active campaigns. This is used for optimizing advertisement and for efficient retargeting.
Maximum Storage Duration: SessionType: Pixel Tracker
vwo_apm_sent Used by VWO to manage application performance monitoring and prevent duplicate performance data submissions.
Maximum Storage Duration: PersistentType: HTML Local Storage
__tld__ Used to track visitors on multiple websites, in order to present relevant advertisement based on the visitor's preferences.
Maximum Storage Duration: SessionType: HTTP Cookie
rl_group_id Collects data on visitors' behaviour and interaction - This is used to optimize the website and make advertisement on the website more relevant.
Maximum Storage Duration: 1 yearType: HTTP Cookie
rl_group_trait Collects data on visitors' behaviour and interaction - This is used to optimize the website and make advertisement on the website more relevant.
Maximum Storage Duration: 1 yearType: HTTP Cookie
rl_page_init_referrer Registers how the user has reached the website to enable pay-out of referral commission fees to partners.
Maximum Storage Duration: 1 yearType: HTTP Cookie
rl_trait Collects data on visitors' behaviour and interaction - This is used to optimize the website and make advertisement on the website more relevant.
Maximum Storage Duration: 1 yearType: HTTP Cookie
rl_user_id Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers.
Maximum Storage Duration: 1 yearType: HTTP Cookie
v1/beacon/img.gif Used in context with Account-Based-Marketing (ABM). The cookie registers data such as IP-addresses, time spent on the website and page requests for the visit. This is used for retargeting of multiple users rooting from the same IP-addresses. ABM usually facilitates B2B marketing purposes.
Maximum Storage Duration: SessionType: Pixel Tracker
_6senseCompanyDetails Used in context with Account-Based-Marketing (ABM). The cookie registers data such as IP-addresses, time spent on the website and page requests for the visit. This is used for retargeting of multiple users rooting from the same IP-addresses. ABM usually facilitates B2B marketing purposes.
Maximum Storage Duration: PersistentType: HTML Local Storage
_an_uid Presents the user with relevant content and advertisement. The service is provided by third-party advertisement hubs, which facilitate real-time bidding for advertisers.
Maximum Storage Duration: 7 daysType: HTTP Cookie
_gd_session Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.
Maximum Storage Duration: 1 dayType: HTTP Cookie
_gd_svisitor Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.
Maximum Storage Duration: 2 yearsType: HTTP Cookie
_gd_visitor Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.
Maximum Storage Duration: 2 yearsType: HTTP Cookie
_cq_tuid Collects data on visitors. This information is used to assign visitors into segments, making website advertisement more efficient.
Maximum Storage Duration: SessionType: HTML Local Storage
_cq_duid Used by the website to protect against fraud in relation to its referral system.
Maximum Storage Duration: 3 monthsType: HTTP Cookie
- Unclassified 0
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
- We do not use cookies of this type.
Cross-domain consent[#BULK_CONSENT_DOMAINS_COUNT#]
[#BULK_CONSENT_TITLE#]
List of domains your consent applies to: [#BULK_CONSENT_DOMAINS#]
Cookie declaration last updated on 7/20/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_LABEL_PURPOSES#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_LABEL_FEATURES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_LABEL_PARTNERS#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.
The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of we need your permission.
This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.
You can at any time change or withdraw your consent from the Cookie Declaration on our website.
Learn more about who we are, how you can contact us and how we process personal data in our [Privacy Policy](/content/privacy-policy ""/index.html).
Do not sell or share my personal information
Allow allCustomize
Allow selectionReject Cookies
Risk Management Framework and the Sonatype Platform
DoD Implementation Guide - NIST SP 800-53 Rev 5/CNSSI 1253
Table of Contents
Detailed Mappings: Supply Chain Risk Management Controls
System and Services Acquisition (SA) Controls
Configuration Management (CM) Controls
System and Information Integrity (SI) Controls
Risk Assessment (RA) and Incident Response (IR)
Configuration Management (CM) Controls
Understanding the Framework: NIST RMF vs. DoD RMF
This document maps the Sonatype Platform to the Department of Defense (DoD) Risk Management Framework (RMF) requirements. The objective is to clarify how these two key frameworks interrelate:
NIST RMF: The seven-step cybersecurity framework by NIST for all U.S. federal agencies.
NIST SP 800-53: Catalog of security and privacy controls; RMF selects controls from this catalog.
DoD RMF: The DoD's specific RMF implementation, defined in DoDI 8510.01
CNSSI 1253: Defines mandatory NIST 800-53 control baselines for DoD and National Security Systems (NSS).
In short, the DoD RMF guides programs toward achieving an Authority to Operate (ATO), using NIST 800-53 controls with CNSSI 1253 baselines. The Sonatype platform automates and provides evidence for these controls.
Executive Summary
The Sonatype platform provides automated controls that help DoD programs achieve ATO under DoDI 8510.01. It delivers automated evidence and enforcement for mandatory controls from NIST SP 800-53 Release 5.2.0, particularly within the Supply Chain Risk Management (SR), System and Services Acquisition (SA), System and Information Integrity (SI), and Configuration Management (CM) control families.
This document references NIST SP 800-53 Release 5.2.0, published August 27, 2025, which includes enhancements to software update and patch management controls in response to Executive Order 14306. These updates strengthen requirements for software resiliency by design, developer testing, update deployment management, and software integrity validation.
As DoD systems increasingly depend on open-source and third-party components, a lack of proper supply chain management introduces mission risk. Sonatype directly addresses these SR controls, ensuring compliance and operational assurance.
More than 2,000 organizations, including 70% of the Fortune 100, and a blend of DoD/Department of War (DoW), Intelligence, and Civilian agencies, rely on Sonatype for software supply chain security.
Note: NIST RMF emphasizes automation in control assessment for speed, effectiveness, and continuous monitoring — all native capabilities of Sonatype.
Sonatype's capabilities directly address the software update security requirements emphasized in NIST SP 800-53 Release 5.2.0, which implements Executive Order 14306 guidance on strengthening the Nation's cybersecurity through improved software update practices and supply chain resilience.
Detailed Mapping: Supply Chain Risk Management Controls
| Control ID | Control Requirement | Sonatype Platform Capability Mapping |
|---|---|---|
| SR-1 | Develop, document, and disseminate supply chain risk management policy and procedures. | Sonatype Lifecycle: Policy-as-Code engine codifies risk policies. Lifecycle Policy Management: Pre-built, tunable policy templates. Audit Trail Generation: Documents enforcement actions. Compliance Reporting: Produces compliance evidence. |
| SR-2 | Develop and maintain a supply chain risk management plan. | Sonatype Lifecycle: Continuous monitoring for real-time assessment. Sonatype SBOM Manager: Creates component inventories. Risk Dashboard: Centralized risk visibility. Automated Risk Scoring and Trend Analysis. |
| SR-3 | Establish supply chain controls and protective processes. | Sonatype Repository Firewall: Blocks malicious/vulnerable components. Lifecycle Policy Engine: Automated enforcement. Component Intelligence Database: 40+ risk data sources. License & Vulnerability Detection: Ensures compliance. |
| SR-4 | Maintain valid provenance of system components. | Sonatype Nexus Repository: Immutable storage with integrity checks. Component Signatures & Provenance Tracking. Sonatype SBOM Manager: Documents origins. Quarantine & Mirroring: Ensures the use of trusted sources. |
| SR-5 | Employ acquisition strategies, contract tools, and procurement methods to protect against supply chain risks. | System Lifecycle Procurement Guidance: Provides real-time component risk assessments to inform acquisition decisions. Vendor Risk Assessment: Evaluates publisher and maintainer security posture. Cost-Risk Analysis: Quantifies security risk cost for procurement justification. Contract Language Support: Provides measurable data to include supply chain security clauses in contracts. Supporting Products: Sonatype Lifecycle, Sonatype Nexus Repository. |
| SR-6 | Assess and review supply chain-related risks associated with suppliers or contractors. | Publisher Intelligence: Provides comprehensive insight into component publishers and maintainers. Supplier Risk Scoring: Automates assessment of supplier security practices. Community Health Metrics: Evaluates open source project activity, responsiveness, and sustainability. Maintenance Activity Tracking: Monitors frequency and quality of supplier updates. Supplier Performance Dashboard: Centralizes supplier risk data for periodic review. Supporting Products: Sonatype Lifecycle, Sonatype Repository Firewall, Intelligence Data Service, Sonatype Nexus Repository. |
| SR-7 | Employ OPSEC controls for supply chain information. | Air-Gapped Deployment (SAGE). Role-Based Access & Audit Logging.Encryption & Secure Communication. |
| SR-8 | Establish supply chain notification agreements. | Security Advisory Integration & Real-Time Alerting. Incident Response Integration & Stakeholder Notifications. Supporting Products: Sonatype Lifecycle, Sonatype Repository Firewall. |
| SR-9 | Implement tamper resistance and detection. | Sonatype Repository Firewall: Blocks tampered components. Integrity Verification & Malware Detection. Behavioral Analysis: Detects anomalous activity. |
| SR-10 | Inspect systems/components for tampering. | Continuous Monitoring & Lifecycle Scanning. Change Detection & Forensics. |
| SR-11 | Implement anti-counterfeit policy and training. | Sonatype Repository Firewall & Authenticity Verification. Digital Signature Validation & Typosquatting Detection. |
| SR-12 | Dispose of components securely. | Sonatype Lifecycle Management: Tracks component lifecycles. Deprecation Alerts, Secure Removal & Migration Planning. |
Control ID
| SR-1 |
| SR-2 |
| SR-3 |
| SR-4 |
| SR-5 |
| SR-6 |
| SR-7 |
| SR-8 |
| SR-9 |
| SR-10 |
| SR-11 |
| SR-12 |
Control Requirement
| Develop, document, and disseminate supply chain risk management policy and procedures. |
| Develop and maintain a supply chain risk management plan. |
| Establish supply chain controls and protective processes. |
| Maintain valid provenance of system components. |
| Employ acquisition strategies, contract tools, and procurement methods to protect against supply chain risks. |
| Assess and review supply chain-related risks associated with suppliers or contractors. |
| Employ OPSEC controls for supply chain information. |
| Establish supply chain notification agreements. |
| Implement tamper resistance and detection. |
| Inspect systems/components for tampering. |
| Implement anti-counterfeit policy and training. |
| Dispose of components securely. |
Sonatype Platform Capability Mapping
| Sonatype Lifecycle: Policy-as-Code engine codifies risk policies. Lifecycle Policy Management: Pre-built, tunable policy templates. Audit Trail Generation: Documents enforcement actions. Compliance Reporting: Produces compliance evidence. |
| Sonatype Lifecycle: Continuous monitoring for real-time assessment. Sonatype SBOM Manager: Creates component inventories. Risk Dashboard: Centralized risk visibility. Automated Risk Scoring and Trend Analysis. |
| Sonatype Repository Firewall: Blocks malicious/vulnerable components. Lifecycle Policy Engine: Automated enforcement. Component Intelligence Database: 40+ risk data sources. License & Vulnerability Detection: Ensures compliance. |
| Sonatype Nexus Repository: Immutable storage with integrity checks. Component Signatures & Provenance Tracking. Sonatype SBOM Manager: Documents origins. Quarantine & Mirroring: Ensures the use of trusted sources. |
| System Lifecycle Procurement Guidance: Provides real-time component risk assessments to inform acquisition decisions. Vendor Risk Assessment: Evaluates publisher and maintainer security posture. Cost-Risk Analysis: Quantifies security risk cost for procurement justification. Contract Language Support: Provides measurable data to include supply chain security clauses in contracts. Supporting Products: Sonatype Lifecycle, Sonatype Nexus Repository. |
| Publisher Intelligence: Provides comprehensive insight into component publishers and maintainers. Supplier Risk Scoring: Automates assessment of supplier security practices. Community Health Metrics: Evaluates open source project activity, responsiveness, and sustainability. Maintenance Activity Tracking: Monitors frequency and quality of supplier updates. Supplier Performance Dashboard: Centralizes supplier risk data for periodic review. Supporting Products: Sonatype Lifecycle, Sonatype Repository Firewall, Intelligence Data Service, Sonatype Nexus Repository. |
| Air-Gapped Deployment (SAGE). Role-Based Access & Audit Logging.Encryption & Secure Communication. |
| Security Advisory Integration & Real-Time Alerting. Incident Response Integration & Stakeholder Notifications. Supporting Products: Sonatype Lifecycle, Sonatype Repository Firewall. |
| Sonatype Repository Firewall: Blocks tampered components. Integrity Verification & Malware Detection. Behavioral Analysis: Detects anomalous activity. |
| Continuous Monitoring & Lifecycle Scanning. Change Detection & Forensics. |
| Sonatype Repository Firewall & Authenticity Verification. Digital Signature Validation & Typosquatting Detection. |
| Sonatype Lifecycle Management: Tracks component lifecycles. Deprecation Alerts, Secure Removal & Migration Planning. |
System and Services Acquisition (SA) Controls
NIST SP 800-53 Release 5.2.0 introduces enhanced controls in the SA family specifically addressing software development security and update management in response to Executive Order 14306.
| Control ID | Control Requirement | Sonatype Platform Capability Mapping |
|---|---|---|
| SA-15(13) | Developer testing and evaluation plans for updates. | Sonatype Lifecycle: Continuous Integration/Continuous Deployment (CI/CD) integration provides automated testing and evaluation of components during updates. Policy Engine: Enforces quality and security gates before updates proceed. Continuous Monitoring: Validates updates against organizational security policies throughout the development lifecycle. Note: This control was added in Release 5.2.0 to address Executive Order 14306 requirements. |
| SA-24 | Software and system resiliency by design. | Sonatype Repository Firewall: Blocks known malicious updates and compromised components before they enter the software supply chain. Policy-Compliant Component Selection: Automatically filters update requests to prevent selection of versions that violate security policies. Release Integrity: Machine learning-based detection identifies suspicious or unusual software releases with pending or suspicious integrity ratings. Note: This control was added in Release 5.2.0 to address Executive Order 14306 requirements. |
Control ID
| SA-15(13) |
| SA-24 |
Control Requirement
| Developer testing and evaluation plans for updates. |
| Software and system resiliency by design. |
Sonatype Platform Capability Mapping
| Sonatype Lifecycle: Continuous Integration/Continuous Deployment (CI/CD) integration provides automated testing and evaluation of components during updates. Policy Engine: Enforces quality and security gates before updates proceed. Continuous Monitoring: Validates updates against organizational security policies throughout the development lifecycle. Note: This control was added in Release 5.2.0 to address Executive Order 14306 requirements. |
| Sonatype Repository Firewall: Blocks known malicious updates and compromised components before they enter the software supply chain. Policy-Compliant Component Selection: Automatically filters update requests to prevent selection of versions that violate security policies. Release Integrity: Machine learning-based detection identifies suspicious or unusual software releases with pending or suspicious integrity ratings. Note: This control was added in Release 5.2.0 to address Executive Order 14306 requirements. |
Configuration Management (CM) Controls
| Control ID | Control Requirement | Sonatype Platform Capability Mapping |
|---|---|---|
| CM-8 | Maintain an accurate inventory of components. | Sonatype Lifecycle + Sonatype SBOM Manager: Centralized inventory and SBOM generation, ingestion, and continuous monitoring. Dependency Mapping & Enterprise Dashboard. |
| CM-10 | Ensure software usage complies with DoD licensing. | Sonatype Lifecycle + Advanced Legal Pack: License analysis and policy enforcement. Conflict Detection & Compliance Reporting. |
| CM-5 | Restrict access to change libraries. | Sonatype Nexus Repository: Controlled repositories. Change Control Logs & Approval Workflows. |
Control ID
| CM-8 |
| CM-10 |
| CM-5 |
Control Requirement
| Maintain an accurate inventory of components. |
| Ensure software usage complies with DoD licensing. |
| Restrict access to change libraries. |
Sonatype Platform Capability Mapping
| Sonatype Lifecycle + Sonatype SBOM Manager: Centralized inventory and SBOM generation, ingestion, and continuous monitoring. Dependency Mapping & Enterprise Dashboard. |
| Sonatype Lifecycle + Advanced Legal Pack: License analysis and policy enforcement. Conflict Detection & Compliance Reporting. |
| Sonatype Nexus Repository: Controlled repositories. Change Control Logs & Approval Workflows. |
System and Information Integrity (SI) Controls
| Control ID | Control Requirement | Sonatype Platform Capability Mapping |
|---|---|---|
| SI-2 | Track and remediate flaws enterprise-wide. | Sonatype Lifecycle: Identifies vulnerabilities. Remediation Tracking & Risk-Based Prioritization. |
| SI-02(07) | Software update deployment and management. | Sonatype Lifecycle for SCM: Provides automated pull requests for security updates with policy-compliant version recommendations. Automated Commit Feedback: Delivers real-time policy evaluation information directly into source control commits. SBOM Manager: Tracks software composition changes across updates with continuous monitoring for newly discovered vulnerabilities. Compliance Stage Monitoring: Provides dedicated monitoring for ongoing compliance verification post-deployment. Note: This control enhancement was added in Release 5.2.0 to address Executive Order 14306 requirements for secure software update practices. |
| SI-7 | Verify software integrity. | Sonatype Nexus Repository + Sonatype Repository Firewall: Cryptographic integrity monitoring. Baseline Comparison & Integrity Alerts. |
Control ID
| SI-2 |
| SI-02(07) |
| SI-7 |
Control Requirement
| Track and remediate flaws enterprise-wide. |
| Software update deployment and management. |
| Verify software integrity. |
Sonatype Platform Capability Mapping
| Sonatype Lifecycle: Identifies vulnerabilities. Remediation Tracking & Risk-Based Prioritization. |
| Sonatype Lifecycle for SCM: Provides automated pull requests for security updates with policy-compliant version recommendations. Automated Commit Feedback: Delivers real-time policy evaluation information directly into source control commits. SBOM Manager: Tracks software composition changes across updates with continuous monitoring for newly discovered vulnerabilities. Compliance Stage Monitoring: Provides dedicated monitoring for ongoing compliance verification post-deployment. Note: This control enhancement was added in Release 5.2.0 to address Executive Order 14306 requirements for secure software update practices. |
| Sonatype Nexus Repository + Sonatype Repository Firewall: Cryptographic integrity monitoring. Baseline Comparison & Integrity Alerts. |
Risk Assessment (RA) and Incident Response (IR)
| Control ID | Control Requirement | Sonatype Platform Capability Mapping |
|---|---|---|
| RA-5 | Conduct vulnerability scanning and facilitate interoperability. | Sonatype Lifecycle: Specialized open-source scanning. Tool Integration with DISA & HBSS. |
| IR-6 | Report vulnerabilities and provide supply chain info. | Sonatype SBOM Manager + Sonatype Lifecycle: Zero-day impact analysis. Rapid Response & Automated Reporting. |
Control ID
| RA-5 |
| IR-6 |
Control Requirement
| Conduct vulnerability scanning and facilitate interoperability. |
| Report vulnerabilities and provide supply chain info. |
Sonatype Platform Capability Mapping
| Sonatype Lifecycle: Specialized open-source scanning. Tool Integration with DISA & HBSS. |
| Sonatype SBOM Manager + Sonatype Lifecycle: Zero-day impact analysis. Rapid Response & Automated Reporting. |
Configuration Management (CM) Controls
Accelerates ATO Process
- Sonatype Lifecycle and Sonatype SBOM Manager capabilities directly support the RMF process by generating a machine-readable SBOM. This SBOM file serves as the primary ‘artifact’ or evidence that is uploaded to eMASS.
- Continuous compliance with real-time monitoring.
- Audit trail generation for assessment and review.
Supports Mission Assurance
- Proactive protection against supply chain compromise.
- Zero-day response and rapid impact analysis.
- Air-gapped deployment options (SAGE) for IL6/IL6+ environments.
Enables DevSecOps Integration
- Native CI/CD Pipeline Integration.
- Seamless developer workflow alignment.
- Automation-first approach for efficiency and security.
Ensures Compliance
- Addresses CNSSI 1253 baselines for National Security Systems.
- Supports DoDI 8510.01 RMF implementation.
- Provides FISMA compliance evidence.
- FIPS 140-3 mode available for deployments requiring cryptographic module validation
Reduces Mission Risk
- AI-powered real-time protection blocks 2,100+ malicious components monthly.
- Comprehensive Threat Intelligence from 40+ data sources.
- Full Enterprise Visibility across DoD applications.
- VEX (Vulnerability Exploitability eXchange) integration for comprehensive vulnerability assessment and annotation workflows.
Meet RMF Requirements with The Sonatype Platform
Related Resources
Blog Post
[The Hidden National Security Threat Inside AI-Driven Software](/content/blog/the-hidden-national-security-threat-inside-ai-driven-software "Internal link to The Hidden National Security Threat Inside AI-Driven Software blog post"/index.html)
Read More
Whitepaper
[Global Regulations Cheat Sheet](/content/resources/whitepapers/global-regulations-cheat-sheet "Internal link to Global Regulations Cheat Sheet blog post"/index.html)
View Guide
Blog Post
[5 Steps to Turn Your RMF Backlog Into a Continuous ATO: The CSRMC Migration Playbook](/content/blog/5-steps-to-turn-your-rmf-backlog-into-a-continuous-ato-the-csrmc-migration-playbook "Internal link to 5 Steps to Turn Your RMF Backlog Into a Continuous ATO: The CSRMC Migration Playbook blog post"/index.html)
Read More