Anchore vs CVD Portal
SBOM generation, storage and policy enforcement, and the maintainer of the open-source Syft and Grype tools. How does Anchore compare to CVD Portal for an EU manufacturer subject to the Cyber Resilience Act?
- Headquarters
- Santa Barbara, United States
- Category
- SBOM and software supply chain security
- Pricing model
- Commercial products priced on request. Syft and Grype are free and open source.
How they compare on CRA-critical features
Five differences between an SBOM platform and a product conformity workspace under Regulation (EU) 2024/2847. The first row is where Anchore is stronger.
Where Anchore is strong
- +SBOM depth. Generation and management in commonly used machine-readable formats is the core of the product rather than a feature bolted onto something else.
- +Continuous scanning of the components listed in an SBOM against known vulnerabilities, which is the Annex I Part II(2) duty to address vulnerabilities without delay.
- +A policy engine that automates compliance policy enforcement, so a rule about what may ship is checked rather than remembered.
- +Syft and Grype are free and open source, which makes the SBOM starting point genuinely accessible to an SME with no budget line for it.
Where it is not a CRA fit
- !The published CRA material does not claim Article 14 reporting to ENISA or the national CSIRT.
- !No published feature for Annex III and Annex IV classification, so which requirements apply to a given product is decided elsewhere.
- !No published Annex I Part I applicability table. Coverage is the SBOM and vulnerability duties in Part II.
- !No published EU Declaration of Conformity, Annex VI simplified declaration or CE marking workflow. The claim is that the SBOM is included in the product's technical documentation, which is a component of the file rather than the file.
- !No Article 13 whitelabel intake portal or published CVD policy under the manufacturer's own domain.
The CRA gap
The SBOM is one line of Annex I Part II, and Anchore does that line as well as anyone. The CRA asks for a good deal more. Annex I Part I sets essential requirements the product itself has to meet, Annex VII sets out what the technical documentation contains, Articles 27 to 32 cover the Declaration of Conformity, CE marking and which conformity route the product takes, Article 13 requires a published disclosure policy and a single point of contact, and Article 14 requires reporting an actively exploited vulnerability within 24 hours. An excellent SBOM does not answer any of those.
Why teams pick CVD Portal for CRA
Five things a conformity workspace adds on top of an SBOM tool. Keep the SBOM tool.
- 1
Imports the SBOM rather than regenerating it, and attaches it to the Annex I Part II requirement it evidences so it counts toward the file.
- 2
Classification against Annex III and Annex IV, which decides the requirement set and the Article 32 route before any component list matters.
- 3
Annex I Part I applicability table with a mandatory justification on every requirement marked not applicable.
- 4
Annex VII technical documentation, EU Declaration of Conformity, Annex VI simplified form and CE marking checklist generated from the product record.
- 5
Article 13 and Article 14 both covered, with a free whitelabel intake portal and 24h, 72h and final reporting timers.
Frequently asked
Does an SBOM make a product CRA compliant?
When is the SBOM actually required?
Can we use Syft and Grype instead of a commercial tool?
Can CVD Portal replace Anchore?
Does CVD Portal carry out the conformity assessment itself?
Put the SBOM inside a technical file
Import what Syft or Anchore already produces, map it against Annex I, and add the classification, documentation and Article 14 filing the CRA asks for around it. The Article 13 baseline is €0/month.