SBOM Analysis: 8 Tools compared
Tools and providers that build, validate or act on a software bill of materials. They differ most in what they start from: some read source code, manifests or an existing SBOM, while others reconstruct the component inventory from a…
Quick comparison
All sbom analysis tools side by side, alphabetical.
| Tool | Deployment | Pricing model | Open source | Standards / certs |
|---|---|---|---|---|
| Black Duck | Cloud + Self-hosted | Enterprise license (project-based) | — | — |
| Finite State | Cloud | Not publicly disclosed | — | — |
| ONEKEY | Cloud + Self-hosted | Platform subscription + advisory | — | EU Cyber Resilience ActIEC 62443ETSI EN 303 645 |
| PCA Cyber Security | — | Project-based engagements | — | — |
| Trivy | Self-hosted | Open source with commercial Aqua Platform | Yes | — |
| VicOne | Cloud + Self-hosted | Subscription (custom) | — | ISO/SAE 21434UNECE R155Automotive SPICE (ASPICE) Level 2 |
| Vulert | Cloud | Per-tier subscription capped by number of applications and users, billed monthly or annually, with extra applications charged monthly. Add-on modules are priced per application per month, including licence compliance, SBOM, container and Docker SBOM export. | — | — |
| VxLabs | Cloud | Subscription for the ThreatZ platform; time and materials, fixed price or retainer for engineering services | — | — |
Black Duck
Application SecurityEnterprises needing the deepest open-source detection including undeclared components, M&A due diligence, and regulatory compliance for software supply chain
Black Duck (a Synopsys product) is an enterprise-grade software composition analysis platform that provides deep visibility into open-source risks, license compliance, and code origin analysis. Black Duck's multi-factor open-source detection uses package managers, file-level analysis, and code snippet matching to identify open-source components even when they are not declared in manifests, making it the most thorough SCA tool for auditing software acquisitions, M&A due diligence, and regulatory compliance. Black Duck is part of Synopsys's broader application security portfolio alongside Coverity (SAST) and Polaris.
Finite State
Product Threat Intelligence ProvidersManufacturers of connected devices across IoT, automotive, medical, and industrial sectors needing firmware-level vulnerability and exploit intelligence tied to compliance evidence.
Finite State positions itself as the "Product Security OS for Connected Devices," analyzing firmware, binaries, and source code to generate SBOMs, identify vulnerabilities, and produce compliance evidence, embedded directly into release workflows. Its threat intelligence capability centers on exploitability-based prioritization and execution-aware reachability analysis, aimed at cutting through vulnerability noise to surface findings that are actually reachable and exploitable. It covers IoT and embedded systems, automotive and connected vehicles, medical devices, industrial control systems, and energy and utilities infrastructure, and supports EU Cyber Resilience Act, FDA, and NIST compliance frameworks.
ONEKEY
Cyber Resilience Act ComplianceDevice manufacturers wanting automated SBOM, vulnerability management, and CRA evidence generation across the product lifecycle
ONEKEY operates the ONEKEY Product Cybersecurity & Compliance Platform, which performs automated firmware analysis, SBOM generation, vulnerability detection, and zero-day discovery. Its Compliance Wizard maps product evidence against the CRA and other frameworks, and its CRA Fast Start program structures readiness assessment, SBOM creation, vulnerability management, and continuous monitoring. ONEKEY (formerly IoT Inspector) is part of PwC Germany's investment portfolio.
PCA Cyber Security
PCI PTS Compliance Testing CompaniesPayment-device makers and operators wanting offensive, real-world security testing of terminals beyond baseline PCI PTS certification
PCA Cyber Security is a Munich-based penetration-testing and security-research firm with a dedicated payment-device practice. It performs real-world security testing of payment terminals, PIN pads, unattended and self-service terminals, and fuel-pump and EV-charging payment systems, testing beyond PCI PTS certification to find vulnerabilities even in approved devices. PCA became a PCI SSC Associate Participating Organisation in 2026 and also runs a strong automotive and embedded security practice. PCA also offers software composition analysis and SBOM validation, reverse-engineering device firmware rather than relying on vendor documentation or an existing SBOM. The vendor describes reconstructing a verified component inventory from the firmware binary, mapping dependencies against runtime behaviour, surfacing undocumented components and mapping findings to CVEs, delivered as an extended bill of materials (xBOM). The service targets payment and financial devices including PTS terminals, smart POS, mPOS and ATMs, alongside automotive ECUs, kiosks, fuel pumps and EV charging interfaces.
Trivy
Application SecurityDevOps and platform engineering teams that need a fast, open-source vulnerability scanner for containers and Kubernetes environments with zero configuration overhead
Trivy is an open-source, comprehensive vulnerability scanner developed by Aqua Security that covers container images, file systems, Git repositories, Kubernetes clusters, and infrastructure-as-code configurations. Trivy stands out for its simplicity, speed, and breadth of scanning targets, requiring zero configuration to get started. It has become a widely adopted open-source scanner for container images in CI/CD pipelines and is widely adopted in Kubernetes-native environments for runtime vulnerability assessment.
VicOne
Automotive CybersecurityOEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent
VicOne is a wholly-owned subsidiary of Trend Micro dedicated exclusively to automotive cybersecurity for connected and electric vehicles. It leverages Trend Micro's 30-plus years of security expertise and the Zero Day Initiative's vulnerability research network. The same program behind Pwn2Own Automotive. To give OEMs and suppliers lifecycle protection from development and production through in-vehicle operation. Its portfolio covers an in-vehicle IDPS, a managed VSOC, threat intelligence, SBOM and vulnerability management, and penetration testing services.
Vulert
Application SecuritySmall and mid-sized teams that want continuous open-source dependency and licence monitoring without granting a scanner access to their repositories.
Vulert is a software composition analysis service that monitors an application open-source dependencies for known vulnerabilities without access to source code. Projects are added by uploading a manifest or lockfile, for example package-lock.json, yarn.lock, pom.xml, requirements.txt, go.sum, Cargo.lock, composer.lock or Gemfile.lock, or an SBOM in SPDX or CycloneDX format, which Vulert checks against its own vulnerability database. Alerts are delivered through the dashboard and email, with Jira, CI/CD, Slack or Discord and SIEM integrations listed among the platform features, and separately priced modules for Docker image scanning, open-source licence compliance and SBOM export. It is a hosted SaaS product requiring no agent, installation or repository connection, operated by Vulert LTD, a company registered in England.
VxLabs
Automotive CybersecurityOEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace, or project-based automotive security engineering.
VxLabs is an automotive cybersecurity and embedded software company founded in January 2022, registered in Regensburg, Germany (HRB 19099) with a US entity in Delaware. Its platform, ThreatZ, is an AWS-hosted SaaS launched in October 2025 that links system modelling, TARA, SBOM, vulnerability management, incident handling and compliance evidence in a single knowledge graph for ISO/SAE 21434 and UNECE R155. The company also sells engineering services covering AUTOSAR Classic and Adaptive ECU development, penetration testing, CSMS consulting and R155 type approval support. Uraeus was the earlier platform brand and uraeus.io now redirects to vxlabs.ai.
Related guides
Other categories you might be evaluating alongside sbom analysis.
About this listing
SBOM Analysis tools, listed alphabetically and compared on public information. How we work →