Accredited Software Factory
Discussion
An Accredited Software Factory is a Software Factory that operates within an approved Accreditation Boundary under an Operational Approval issued by an Authorizing Authority.
The accreditation applies to the factory configuration, implemented controls, operating processes, supporting Evidence, and operational context included within the approved boundary.
Crucible supports the construction and reproduction of a Software Factory through controlled baselines, hardened machine images, traceable dependencies, reproducible deployments, and compliance evidence. Crucible does not grant accreditation or operational approval.
Definition
software factory that operates within an approved accreditation boundary under an operational approval issued by an authorizing authority
Source
Generalised from software-factory, security-accreditation, and risk-management usage and specialized for the Crucible architecture and operational model.
Note
Accreditation applies to the approved boundary, configuration, controls, operating processes, and operational context. Accreditation of the Software Factory does not automatically establish accreditation of every product produced by the factory or every environment into which a product is deployed.
A Software Factory that implements security controls or produces compliance evidence does not become an Accredited Software Factory until an Authorizing Authority issues the applicable Operational Approval.
Example
An organization uses Crucible to reproduce a Software Factory from pinned source repositories, hardened machine images, controlled infrastructure baselines, captured dependencies, and traceable evidence of compliance. An Authorizing Authority evaluates the defined Accreditation Boundary and issues an Operational Approval for the factory.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.