SBOM Analysis: 11 Tools compared
11 SBOM Analysis Tools, side by side
Featured listings are paid placements.
| Tool | Starts from | SBOM formats | Maps to | Deployment | Pricing model |
|---|---|---|---|---|---|
| PCA CervusFeatured | Supplier SBOMs and each product's components | Not stated | CRA, UNECE R155, ISO/SAE 21434, IEC 62443-4-2, RED / EN 18031, PCI PTS, PCI DSS | — | — |
| ONEKEY | Device firmware | CycloneDX, SPDX | CRA, IEC 62443-4-2, ETSI EN 303 645, RED, UNECE R155 | Cloud + Self-hosted | Platform subscription + advisory |
| PCA Cyber Security | Device firmware, by reverse engineering (a service) | Not stated | Not stated | Cloud | Project-based engagements |
| Black Duck | Source code (package, file and snippet matching) and compiled binaries | SPDX, CycloneDX | Not stated | Cloud + Self-hosted | Enterprise license (project-based) |
| CRACI | Your GitHub Actions build, with the SBOM generated from it | CycloneDX, SPDX | CRA, including vulnerability disclosure for ENISA | Cloud | Subscription by user band and monitored SBOM, plus metered build minutes |
| Finite State | Firmware, binaries and source code | Not stated | EU CRA, FDA, NIST | Cloud | Not publicly disclosed |
| NetRise | Compiled binaries and firmware, without source code | SPDX, CycloneDX (import and export) | Not stated | Cloud | Enterprise subscription |
| Trivy | Container images, file systems, repositories and IaC | CycloneDX, SPDX | Not stated | Self-hosted | Open source with commercial Aqua Platform |
| VicOne | Not stated | Not stated | Not stated | Cloud + Self-hosted | Subscription (custom) |
| Vulert | Package manifests, lockfiles and SBOMs | Reads SPDX and CycloneDX; exports CycloneDX | Not stated | Cloud | Per-tier subscription capped by number of applications and users, billed monthly or annually, with extra applications charged monthly. Add-on modules are priced per application per month, including licence compliance, SBOM, container and Docker SBOM export. |
| VxLabs | SBOMs, with CVE matching | CycloneDX, SPDX | Not stated | Cloud | Subscription for the ThreatZ platform; time and materials, fixed price or retainer for engineering services |
Starts from, SBOM formats and Maps to come from each listing's cited sources and the vendors' documentation, checked 21 September 2026. Not stated means those sources don't say, not that the product lacks it. Sources: Black Duck: building an SBOM (April 2024); NetRise: SBOM management; Trivy documentation: SBOM; PCA Cyber Security: PCA CERVUS platform; CRACI: automated cyber resilience for every build.
PCA Cervus
Device-by-device vulnerability monitoring for embedded products, from supplier SBOMs to patch validation
PCA Cervus is a device-centric vulnerability monitoring and threat intelligence platform for embedded and connected products, made by PCA Cyber Security, the Munich- and Budapest-based embedded cybersecurity firm. PCA describes the workflow in six steps: upload an SBOM, Cervus validates the software components, new vulnerabilities are detected, affected products are identified, risk is prioritised and engineering is notified. It validates supplier SBOMs or generates them, models each device from its components, and correlates vulnerability and threat intelligence with those components, so the picture is built around the product rather than around individual CVEs. Monitoring continues after a product is released or certified, and PCA supports remediation through to patch validation. Compliance reporting covers the Cyber Resilience Act, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031. Cervus imports existing SBOMs, integrates with ticketing systems and exports data, and PCA says its AI-assisted analysis uses self-hosted models so product information stays under the customer's control. It is aimed at manufacturers, importers and operators of embedded products in payment, automotive, industrial, energy, medical and consumer IoT markets. PCA says the platform was developed with its offensive security researchers. Pricing and deployment options are not published.
Capabilities
- Import of existing and supplier SBOMs, with validation of the software components
- SBOM validation and/or generation for embedded products
- Device-centric model: each product's components are correlated with vulnerability and threat intelligence
- Continuous monitoring for new vulnerabilities, exploits and threats after release or certification, identifying the affected products
- Prioritisation of exploitable vulnerabilities rather than every CVE
- Remediation support through to patch validation, with engineering notified through ticketing integrations
- Compliance reports and evidence for the CRA, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031
- AI-assisted analysis using self-hosted models, per PCA
- Monitoring of threats targeting company secrets, infrastructure and code
Black Duck
Application SecurityEnterprises needing the deepest open-source detection including undeclared components, M&A due diligence, and regulatory compliance for software supply chain
Black Duck (a Synopsys product) is an enterprise-grade software composition analysis platform that provides deep visibility into open-source risks, license compliance, and code origin analysis. Black Duck's multi-factor open-source detection uses package managers, file-level analysis, and code snippet matching to identify open-source components even when they are not declared in manifests, making it the most thorough SCA tool for auditing software acquisitions, M&A due diligence, and regulatory compliance. Black Duck is part of Synopsys's broader application security portfolio alongside Coverity (SAST) and Polaris.
CRACI
SBOM AnalysisProduct teams selling into the EU that want Cyber Resilience Act evidence produced by the build, with the SBOM and vulnerability tracking inside the CI pipeline rather than a separate scan
CRACI is a software supply chain compliance platform from CRACI Corporation Oy, a Finnish company founded in 2025. It runs as a GitHub Actions runner, so builds stay in GitHub, and generates a software bill of materials from the build itself in CycloneDX or SPDX. Alongside the SBOM it tracks vulnerabilities across dependencies, lets teams assign and follow remediation, and produces the reporting the EU Cyber Resilience Act calls for, including vulnerability disclosure to ENISA. The workspace is organised around builds, security, inventory and compliance, and the vendor says other CI systems are on its roadmap. CRACI is delivered as a service and states ISO/IEC 27001 certification, with EU data residency, SAML and single sign-on on enterprise plans. The company raised 1.4 million euro in pre-seed funding in May 2026 in a round led by Lifeline Ventures, with First Fellow Partners and Wave Ventures.
Finite State
Product Threat Intelligence ProvidersManufacturers of connected devices across IoT, automotive, medical, and industrial sectors needing firmware-level vulnerability and exploit intelligence tied to compliance evidence.
Finite State positions itself as the "Product Security OS for Connected Devices," analyzing firmware, binaries, and source code to generate SBOMs, identify vulnerabilities, and produce compliance evidence, embedded directly into release workflows. Its threat intelligence capability centers on exploitability-based prioritization and execution-aware reachability analysis, aimed at cutting through vulnerability noise to surface findings that are actually reachable and exploitable. It covers IoT and embedded systems, automotive and connected vehicles, medical devices, industrial control systems, and energy and utilities infrastructure, and supports EU Cyber Resilience Act, FDA, and NIST compliance frameworks.
NetRise
SBOM AnalysisFinancial institutions and device makers needing a binary-derived component inventory where source code is not available
NetRise analyses compiled code rather than source, building an SBOM from the binary so that a supplied manifest can be checked against the software that actually executes. The platform covers firmware and software components, with NetRise Provenance assessing open-source component and repository health, ZeroLens identifying weaknesses in compiled software, and Trace applying semantic search to code provenance and supply chain origin. Reachability analysis identifies which vulnerable code runs at startup so remediation can be prioritised. NetRise publishes a financial services solution brief covering the software supply chain of banking and trading applications, mapped to PCI DSS 4.0, NYDFS, the SEC cybersecurity rules and FFIEC. The company was founded in 2020 and is based in Austin, Texas.
ONEKEY
Cyber Resilience Act ComplianceDevice manufacturers wanting automated SBOM, vulnerability management, and CRA evidence generation across the product lifecycle
ONEKEY operates the ONEKEY Product Cybersecurity & Compliance Platform, which performs automated firmware analysis, SBOM generation, vulnerability detection, and zero-day discovery. Its Compliance Wizard maps product evidence against the CRA and other frameworks, and its CRA Fast Start program structures readiness assessment, SBOM creation, vulnerability management, and continuous monitoring. ONEKEY (formerly IoT Inspector) is part of PwC Germany's investment portfolio.
PCA Cervus
SBOM AnalysisManufacturers, importers and operators of embedded and connected products in payment, automotive, industrial and IoT markets that need to track vulnerabilities device by device against supplier SBOMs and produce evidence for regulations such as the Cyber Resilience Act, PCI PTS and UNECE R155
PCA Cervus is a device-centric vulnerability monitoring and threat intelligence platform for embedded and connected products, made by PCA Cyber Security, the Munich- and Budapest-based embedded cybersecurity firm. PCA describes the workflow in six steps: upload an SBOM, Cervus validates the software components, new vulnerabilities are detected, affected products are identified, risk is prioritised and engineering is notified. It validates supplier SBOMs or generates them, models each device from its components, and correlates vulnerability and threat intelligence with those components, so the picture is built around the product rather than around individual CVEs. Monitoring continues after a product is released or certified, and PCA supports remediation through to patch validation. Compliance reporting covers the Cyber Resilience Act, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031. Cervus imports existing SBOMs, integrates with ticketing systems and exports data, and PCA says its AI-assisted analysis uses self-hosted models so product information stays under the customer's control. It is aimed at manufacturers, importers and operators of embedded products in payment, automotive, industrial, energy, medical and consumer IoT markets. PCA says the platform was developed with its offensive security researchers. Pricing and deployment options are not published.
PCA Cyber Security
PCI PTS Compliance Testing CompaniesManufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Trivy
Application SecurityDevOps and platform engineering teams that need a fast, open-source vulnerability scanner for containers and Kubernetes environments with zero configuration overhead
Trivy is an open-source, comprehensive vulnerability scanner developed by Aqua Security that covers container images, file systems, Git repositories, Kubernetes clusters, and infrastructure-as-code configurations. Trivy stands out for its simplicity, speed, and breadth of scanning targets, requiring zero configuration to get started. It has become a widely adopted open-source scanner for container images in CI/CD pipelines and is widely adopted in Kubernetes-native environments for runtime vulnerability assessment.
VicOne
Automotive CybersecurityOEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent
VicOne is a wholly-owned subsidiary of Trend Micro dedicated exclusively to automotive cybersecurity for connected and electric vehicles. It leverages Trend Micro's 30-plus years of security expertise and the Zero Day Initiative's vulnerability research network. The same program behind Pwn2Own Automotive. To give OEMs and suppliers lifecycle protection from development and production through in-vehicle operation. Its portfolio covers an in-vehicle IDPS, a managed VSOC, threat intelligence, SBOM and vulnerability management, and penetration testing services.
Vulert
Application SecuritySmall and mid-sized teams that want continuous open-source dependency and licence monitoring without granting a scanner access to their repositories.
Vulert is a software composition analysis service that monitors an application open-source dependencies for known vulnerabilities without access to source code. Projects are added by uploading a manifest or lockfile, for example package-lock.json, yarn.lock, pom.xml, requirements.txt, go.sum, Cargo.lock, composer.lock or Gemfile.lock, or an SBOM in SPDX or CycloneDX format, which Vulert checks against its own vulnerability database. Alerts are delivered through the dashboard and email, with Jira, CI/CD, Slack or Discord and SIEM integrations listed among the platform features, and separately priced modules for Docker image scanning, open-source licence compliance and SBOM export. It is a hosted SaaS product requiring no agent, installation or repository connection, operated by Vulert LTD, a company registered in England.
VxLabs
Automotive CybersecurityOEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace, or project-based automotive security engineering.
VxLabs is an automotive cybersecurity and embedded software company founded in January 2022, registered in Regensburg, Germany (HRB 19099) with a US entity in Delaware. Its platform, ThreatZ, is an AWS-hosted SaaS launched in October 2025 that links system modelling, TARA, SBOM, vulnerability management, incident handling and compliance evidence in a single knowledge graph for ISO/SAE 21434 and UNECE R155. The company also sells engineering services covering AUTOSAR Classic and Adaptive ECU development, penetration testing, CSMS consulting and R155 type approval support. Uraeus was the earlier platform brand and uraeus.io now redirects to vxlabs.ai.
Related guides
Other categories you might be evaluating alongside sbom analysis.
About this listing
SBOM Analysis tools, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →