ComparisonApplication security posture management

ArmorCode vs CVD Portal

AI-powered ASPM that aggregates findings across the security stack and tracks CRA reporting clocks as data. How does ArmorCode compare to CVD Portal for an EU manufacturer subject to the Cyber Resilience Act?

Headquarters
Palo Alto, United States
Category
Application security posture management
Pricing model
Annual subscription priced on request. No published rate card.

How they compare on CRA-critical features

Five differences between an engineering-side security platform and a product conformity workspace under Regulation (EU) 2024/2847. The first row is where ArmorCode is stronger.

Feature
ArmorCode
CVD Portal
SBOM generation and component vulnerability tracking
Core strength. Usually deeper than ours
Supported, and linked to the Annex I Part II duty it evidences. Import an existing SBOM rather than duplicating the scanner
Annex III / Annex IV classification and the Article 32 route
Not advertised
Free classifier. The result decides which requirements apply and whether the product can self-assess
Annex I Part I applicability table with justifications
Not advertised
Every essential requirement marked applicable with a reference or not applicable with a justification that has to survive review
Annex VII technical documentation, EU Declaration of Conformity, CE marking
Evidence for the file. Not the file itself
Generated per product and versioned with the record
Article 13 CVD policy and whitelabel single point of contact
Not advertised
Included on the Free tier, under the manufacturer's own domain

Where ArmorCode is strong

  • +The only platform in this category whose published CRA material addresses the reporting clocks directly, describing disclosure workflows wired to ENISA timelines that track the 24-hour, 72-hour and 14-day deadlines as data.
  • +Tamper-resistant SBOM and VEX disclosures from one platform, which covers the Annex I Part II(1) duty and the VEX layer that keeps a long component list manageable.
  • +Unified vulnerability management across a large integration surface, giving one prioritised view of risk rather than a finding backlog per scanner.
  • +Exploit-aware prioritisation, which matters because the Article 14 clock starts on active exploitation rather than on discovery.

Where it is not a CRA fit

  • !The published CRA material does not address Annex III or Annex IV classification, so the decision that determines which requirements apply and which Article 32 route the product takes sits outside it.
  • !No published Annex I Part I essential requirements applicability table. The claims cover the Part II vulnerability handling duties.
  • !No published EU Declaration of Conformity, Annex VI simplified declaration or CE marking workflow.
  • !No published Article 13 whitelabel intake portal or CVD policy under the manufacturer's own domain, which is the single point of contact obligation rather than the reporting one.
  • !The unit is the finding and the organisation's stack. CRA obligations attach to each product with digital elements, which is where the technical file and the declared support period live.

The CRA gap

ArmorCode goes further into the CRA than most of this category, and tracking the 24-hour, 72-hour and 14-day clocks as data is the right instinct. The gap is what the clock is attached to. Article 14 reporting is one duty in a product conformity regime: before it comes classification against Annex III and Annex IV, the Annex I Part I applicability decision with a justification on everything marked not applicable, the Annex VII technical documentation and a signed EU Declaration of Conformity, and alongside it sits the Article 13 published policy and single point of contact. Aggregating findings across the stack is a different unit of work from carrying one product to a CE mark.

Why teams pick CVD Portal for CRA

Five things a conformity workspace adds on top of an ASPM platform. Most manufacturers that need both run both.

  1. 1

    The product is the unit, so the reporting clock hangs off a specific product with a classification, a technical file and a declared support period behind it.

  2. 2

    Classification decides the requirement set and the Article 32 conformity route, which is upstream of any finding.

  3. 3

    The Article 14 package is a submission, not a timer. Guided reporting on every plan and an SRP-ready package for one-step manual filing on Enterprise.

  4. 4

    Article 13 is covered as well as Article 14. A whitelabel intake portal and published CVD policy at €0/month, which is the obligation that starts on the same date.

  5. 5

    Produces the conformity artifacts themselves: Annex I applicability table, Annex VII documentation index, EU Declaration of Conformity, Annex VI simplified form and the CE marking checklist.

Frequently asked

Does ArmorCode handle CRA Article 14 reporting?
Its published CRA material describes disclosure workflows wired to ENISA timelines and tracking the 24-hour, 72-hour and 14-day clocks as data, which is more than most platforms in its category claim. What the page does not describe is the product conformity work the report sits inside: Annex III classification, the Annex I Part I applicability table, the technical documentation, the Declaration of Conformity and CE marking.
How is tracking a reporting clock different from filing the report?
A timer tells you the deadline. A filing needs the content: which product, its classification, the vulnerability detail, the corrective measures and the affected component list. From 11 September 2026 that goes to ENISA and the coordinating national CSIRT through the single reporting platform. CVD Portal drafts the submission package from the product record ahead of the clock, so the 24-hour early warning is a review rather than a scramble.
Does Article 13 have a deadline too?
Yes, the same one. From 11 September 2026 a manufacturer has to have a published coordinated vulnerability disclosure policy and a single point of contact for reports, and acknowledge reports it receives. It is a smaller obligation than Article 14 and it is often the one that gets missed, because it needs a public page rather than an internal workflow. CVD Portal includes it on the Free tier.
Can we run both?
Yes, and it is the common shape. ArmorCode aggregates and prioritises findings across the security stack. CVD Portal is the per-product conformity record those findings feed, and it accepts imported SBOM and vulnerability evidence against specific Annex I requirements.
Where does CVD Portal stop?
It prepares and maintains the conformity file. It does not act as a conformity assessment body. Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

Attach the reporting clock to a product file

Classification, Annex I, the technical documentation and the Article 14 submission package in one product record. The Article 13 baseline is €0/month.