Software delivery across the Department of War (DoW) depends on speed, but growing use of open source, third-party components, and AI-assisted development makes the software supply chain harder to control. DoW teams need to identify and address risk early without introducing manual gates that slow mission delivery.
Sonatype's Nexus One platform solution has been assessed as "Awardable" and is now available in the Department of Defense's Platform One (P1) Solutions MarketPlace.
The P1 Solutions MarketPlace is a digital repository of post-competition, readily awardable vendors addressing significant government challenges across hardware, software, and services. Solutions listed as Awardable have been evaluated through the MarketPlace's competitive procedures and scoring process. Government customers with a MarketPlace account can review these solutions and use the established pathway when pursuing a capability.
By applying intelligence and automated controls before risky components become embedded in applications and pipelines, teams can reduce downstream remediation and rework while continuing to deliver at mission speed.
Awardable status does not constitute a contract award, Authorization to Operate, authorization to deploy, or security accreditation. Those requirements remain subject to each customer's applicable acquisition and authorization processes. Instead, this milestone gives eligible DoW organizations a more streamlined way to evaluate and pursue Sonatype's capabilities once they have identified the need.
"DoW development teams should not have to choose between delivering mission capabilities quickly and maintaining control over the software entering their environments," said Christopher Weber, Sonatype's Vice President of Public Sector. "Sonatype's Awardable status gives government customers another path to put automated software supply chain governance into practice and address risk earlier in development."
This designation builds on Sonatype's existing history with the Platform One.
In 2020, hardened versions of Sonatype Lifecycle and Sonatype Nexus Repository were accepted into Platform One's approved application portal and received Certification to Field. That milestone centered on making hardened Sonatype capabilities technically available through Platform One's container ecosystem.
The new Awardable designation addresses a different part of the process: acquisition. Sonatype's presence in the P1 Solutions MarketPlace provides an established pathway through which eligible DoW organizations can pursue its assessed software supply chain capability.
Together, these milestones reflect both the operational and acquisition considerations involved in bringing software supply chain controls into government development environments.
Effective software supply chain governance starts before risk becomes embedded in an application. Sonatype helps development, security, and platform teams apply intelligence and automated controls as components enter and move through development.
This enables teams to:
Know what is coming in: Gain visibility into open source and third-party components across applications, repositories, and development workflows.
Stop what should not enter: Prevent malicious, vulnerable, or noncompliant components from progressing through development.
Guide developers forward: Provide remediation guidance and safer component or version choices.
Produce auditable evidence: Track component usage, policy decisions, vulnerabilities, and remediation activity.
Together, these capabilities support a prevent, govern, prove approach: prevent avoidable risk, govern components consistently, and produce evidence that controls are working.
Software factories, DevSecOps teams, platform engineering groups, application security teams, and mission development organizations all face the same underlying scaling problem: software volume is increasing faster than manual review capacity.
Security teams cannot individually inspect every component request or development decision. Developers also cannot be expected to research the security, license, quality, and policy implications of every dependency on their own.
Automated controls make it possible to apply organizational standards consistently while keeping development moving. Policies become part of the workflow rather than a separate review at the end. Developers receive relevant guidance when they can still act on it, and security teams gain visibility without becoming the bottleneck for every decision.
The result is a safer path to production that supports both development speed and organizational accountability.
Being listed in another marketplace is not the ultimate goal. What matters is reducing the distance between recognizing a software supply chain problem and putting the appropriate capability to work.
As software development accelerates across the DoW, organizations need stronger control over the components entering their environments. They also need to apply that control without introducing delays that work against the mission.
Sonatype’s Awardable status on the P1 Solutions MarketPlace provides another path for DoW organizations to move from identifying that need toward putting those capabilities to work.
Learn more about Sonatype's government software development solutions or connect with our Public Sector team.