ComparisonSBOM and software supply chain security

Anchore vs CVD Portal

SBOM generation, storage and policy enforcement, and the maintainer of the open-source Syft and Grype tools. How does Anchore compare to CVD Portal for an EU manufacturer subject to the Cyber Resilience Act?

Headquarters
Santa Barbara, United States
Category
SBOM and software supply chain security
Pricing model
Commercial products priced on request. Syft and Grype are free and open source.

How they compare on CRA-critical features

Five differences between an SBOM platform and a product conformity workspace under Regulation (EU) 2024/2847. The first row is where Anchore is stronger.

Feature
Anchore
CVD Portal
SBOM generation and component vulnerability tracking
Core strength. Usually deeper than ours
Supported, and linked to the Annex I Part II duty it evidences. Import an existing SBOM rather than duplicating the scanner
Annex III / Annex IV classification and the Article 32 route
Not advertised
Free classifier. The result decides which requirements apply and whether the product can self-assess
Annex I Part I applicability table with justifications
Not advertised
Every essential requirement marked applicable with a reference or not applicable with a justification that has to survive review
Annex VII technical documentation, EU Declaration of Conformity, CE marking
Evidence for the file. Not the file itself
Generated per product and versioned with the record
Article 13 CVD policy and whitelabel single point of contact
Not advertised
Included on the Free tier, under the manufacturer's own domain

Where Anchore is strong

  • +SBOM depth. Generation and management in commonly used machine-readable formats is the core of the product rather than a feature bolted onto something else.
  • +Continuous scanning of the components listed in an SBOM against known vulnerabilities, which is the Annex I Part II(2) duty to address vulnerabilities without delay.
  • +A policy engine that automates compliance policy enforcement, so a rule about what may ship is checked rather than remembered.
  • +Syft and Grype are free and open source, which makes the SBOM starting point genuinely accessible to an SME with no budget line for it.

Where it is not a CRA fit

  • !The published CRA material does not claim Article 14 reporting to ENISA or the national CSIRT.
  • !No published feature for Annex III and Annex IV classification, so which requirements apply to a given product is decided elsewhere.
  • !No published Annex I Part I applicability table. Coverage is the SBOM and vulnerability duties in Part II.
  • !No published EU Declaration of Conformity, Annex VI simplified declaration or CE marking workflow. The claim is that the SBOM is included in the product's technical documentation, which is a component of the file rather than the file.
  • !No Article 13 whitelabel intake portal or published CVD policy under the manufacturer's own domain.

The CRA gap

The SBOM is one line of Annex I Part II, and Anchore does that line as well as anyone. The CRA asks for a good deal more. Annex I Part I sets essential requirements the product itself has to meet, Annex VII sets out what the technical documentation contains, Articles 27 to 32 cover the Declaration of Conformity, CE marking and which conformity route the product takes, Article 13 requires a published disclosure policy and a single point of contact, and Article 14 requires reporting an actively exploited vulnerability within 24 hours. An excellent SBOM does not answer any of those.

Why teams pick CVD Portal for CRA

Five things a conformity workspace adds on top of an SBOM tool. Keep the SBOM tool.

  1. 1

    Imports the SBOM rather than regenerating it, and attaches it to the Annex I Part II requirement it evidences so it counts toward the file.

  2. 2

    Classification against Annex III and Annex IV, which decides the requirement set and the Article 32 route before any component list matters.

  3. 3

    Annex I Part I applicability table with a mandatory justification on every requirement marked not applicable.

  4. 4

    Annex VII technical documentation, EU Declaration of Conformity, Annex VI simplified form and CE marking checklist generated from the product record.

  5. 5

    Article 13 and Article 14 both covered, with a free whitelabel intake portal and 24h, 72h and final reporting timers.

Frequently asked

Does an SBOM make a product CRA compliant?
No. Annex I Part II(1) requires a software bill of materials in a commonly used machine-readable format covering at least the top-level dependencies, and that is one requirement among many. The product still has to meet the Annex I Part I essential requirements, carry Annex VII technical documentation, have an EU Declaration of Conformity and a CE mark, publish a disclosure policy and single point of contact under Article 13, and report actively exploited vulnerabilities under Article 14.
When is the SBOM actually required?
The SBOM sits in the Annex I Part II vulnerability handling requirements, which apply when the full regulation applies on 11 December 2027. The reporting duties under Articles 13 and 14 start earlier, on 11 September 2026. In practice the SBOM is worth having by the 2026 date anyway, because reporting an actively exploited vulnerability within 24 hours is much harder without knowing what is in the product.
Can we use Syft and Grype instead of a commercial tool?
For SBOM generation and component scanning, often yes. They are free, open source and produce machine-readable output in the formats the CRA expects. What they do not produce is the surrounding conformity file, which is where CVD Portal picks up. Importing a Syft SBOM and mapping it against the Annex I requirement it evidences works the same as importing from a commercial scanner.
Can CVD Portal replace Anchore?
No. It does not generate SBOMs from source or container images and does not try to. It stores the SBOM you already have, links it to the requirement it satisfies, and tracks it going stale against the product's declared support period.
Does CVD Portal carry out the conformity assessment itself?
It produces the file the assessment rests on, and where the route allows it, supports the self-assessment. Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

Put the SBOM inside a technical file

Import what Syft or Anchore already produces, map it against Annex I, and add the classification, documentation and Article 14 filing the CRA asks for around it. The Article 13 baseline is €0/month.