---
title: "Software supply chain security for MAPFRE"
description: "ee how Cloudsmith helps globally distributed engineering teams control open-source dependencies, enforce centralized security policy, and meet EU Cyber Resilience Act requirements – built for enterprises migrating to cloud."
canonical_url: "https://cloudsmith.com/loves/mapfre"
last_updated: "2026-04-14T14:39:32Z"
---
# Software supply chain security for MAPFRE

Cloudsmith x Mapfre

## Your pipelines are secured. What about everything upstream?

Cloudsmith governs what enters your cloud platform – so every dependency meets your security and compliance standards before a developer touches it.

[See how Cloudsmith works](https://www.cloudsmith.com)

## The Cloudsmith difference

Your security investment is real. But every tool in your stack operates after a dependency has already entered your environment. Cloudsmith governs what enters – so the rest of your controls work on a cleaner foundation.

| Your current solution | With Cloudsmith |

| --- | --- |

| Dependencies enter your environment before your scanning tools see them. | Cloudsmith scans and blocks at the entry point – before a build runs. |

| Security policy varies across teams and regions. | One policy, defined centrally, applies across every team, format, and pipeline. |

| No automated SBOM generation ahead of the CRA reporting deadline. | Cloudsmith generates SBOMs and maintains the audit trails the CRA requires. |

| AI-recommended dependencies enter your supply chain unverified. | Every AI-recommended package passes through the same governance controls as any other artifact. |

## Don't just identify threats. Block them.

SAST scanning, dynamic testing, hard gating on CVEs – these are the right controls. But they all operate inside the pipeline. They catch problems after a dependency has already entered your environment.
The gap is upstream. Every open-source package, third-party artifact, and AI-recommended dependency that enters your development environment is a potential risk – before your scanning tools ever see it. Across 2,000+ cloud accounts and 30+ countries, that adds up fast.
Cloudsmith sits at the entry point. It governs what enters, enforces policy before a build runs, and gives your central architecture team control – regardless of where the consuming team is based.

- Scan every upstream dependency for malware and CVEs before it reaches your developers
- Quarantine or block non-compliant packages before a build runs
- Enforce policy at the point of entry, not after the fact
- Gives your central team control over what enters across every format and region

[Learn more about software supply chain security](/product/software-supply-chain-security)

## AI is accelerating your development. It's also accelerating your attack surface.

MAPFRE uses generative AI at scale – from AI-assisted development tooling to an internal platform serving developers across 25 countries. That introduces a category of supply chain risk most organizations haven't yet addressed. The answer isn't to slow AI adoption. Cloudsmith makes sure it doesn't come at the cost of supply chain security

### Upstream dependency scanning

Cloudsmith scans every AI-recommended package for malware and CVEs before it reaches your developers.

### Policy-based blocking

Packages that don't meet your standards get blocked before a build runs – regardless of how they were recommended.

### Consistent governance

The same rules apply to AI-generated dependencies as any other artifact entering your supply chain.

### AI tooling visibility

See what your AI development tools pull into your environment, where it comes from, and whether it meets your policy.

## Five capabilities. One platform.

Cloudsmith gives your architecture team control over what enters your supply chain, how it's governed, what's in it, and how it gets to people.

### Centralize policy enforcement across distributed teams

MAPFRE is moving toward centralized security services and an "insurance platform as a service" model – where the central team defines the platform and country teams consume from it. Cloudsmith's Enterprise Policy Manager is built for this model.
Define your vulnerability policies, license restrictions, and compliance rules once. Cloudsmith enforces them across every team, every format, every pipeline. Update a policy once. It applies everywhere.

### A dependency firewall for your supply chain

Cloudsmith proxies all upstream open-source consumption through a governed layer. It scans every package for malware and CVEs before it reaches your developers. Non-compliant, vulnerable, or suspicious artifacts get quarantined or blocked before a build runs – not flagged after the fact.
As your migration accelerates and AI-assisted development scales, the attack surface grows. Cloudsmith gives your InfoSec and architecture teams a governed entry point – and control over what passes through it.

### Supply chain visibility and SBOM generation

Cloudsmith gives you a view of every artifact in your supply chain: what it is, where it came from, which projects depend on it, and whether it meets your current policy standards.
Cloudsmith signs artifacts and traces every dependency. It generates Software Bill of Materials (SBOM) reports – giving your compliance and governance teams the evidence chain they need for audits, regulatory submissions, and incident response.

### Global distribution without the overhead

Cloudsmith replicates artifacts across regions automatically. Teams in the US, Spain, Latin America, and beyond get fast, reliable access to the packages they need – without anyone configuring infrastructure or managing availability.
For an organization operating across 30+ countries, that matters. Your developers get consistent performance wherever they are. Your architecture team doesn't manage the infrastructure that delivers it.

### Multi-format artifact management

Cloudsmith supports npm, Helm, Maven, Python, NuGet, Docker, and more – all within a single platform. Teams stop juggling fragmented repositories across formats and get a consistent, governed experience regardless of what they're building with.
For a development organization operating across multiple languages, frameworks, and geographies, that consistency matters. One set of policies. One source of truth. Every format covered.

## The CRA reporting window opens in September 2026. The migration is happening now.

The EU Cyber Resilience Act entered into force in December 2024. Reporting obligations apply from 11 September 2026 – six months away. Main compliance obligations follow in December 2027.
For an organization like MAPFRE, with software development operations across the EU and a central architecture function in Spain, the CRA creates specific obligations: demonstrable software supply chain controls, SBOM generation, vulnerability disclosure processes, and evidence of security practices throughout the development lifecycle.
MAPFRE is migrating to the cloud right now. The controls you put in place during this migration will serve as your compliance posture for years to come. Build artifact governance in now. Retrofitting it later costs more – in time and in risk.
Cloudsmith supports CRA compliance: SBOM generation, policy enforcement with audit trails, vulnerability management with documented remediation, and package provenance tracking – all native to the platform.

- Fully managed architecture
- Globally-distributed content delivery
- Highly-available

## Customers love Cloudsmith

[Read reviews](https://www.g2.com/products/cloudsmith/reviews)
