ComparisonProduct security and Cyber Digital Twins

Cybellum vs CVD Portal

Product security platform powered by Cyber Digital Twins for automotive, medical, and IoT devices. How does Cybellum compare to CVD Portal for an EU manufacturer subject to the Cyber Resilience Act?

Headquarters
Tel Aviv, Israel
Category
Product security and Cyber Digital Twins
Pricing model
Enterprise annual subscription priced on request based on monitored assets.

How they compare on CRA-critical features

Five differences between a Cyber Digital Twin product security platform and a CRA conformity workspace under Regulation (EU) 2024/2847. The first row is where Cybellum is stronger.

Feature
Cybellum
CVD Portal
Binary firmware decomposition and HBOM/SBOM extraction
Core strength. Native binary extraction without source code
Supported via SBOM import (SPDX / CycloneDX). Imports existing scanner output to attach to the Annex I Part II evidence record
Annex III / Annex IV product classification and Article 32 route
Not advertised or manual mapping
Free interactive classifier deciding Article 32 conformity route and applicable essential requirements
Article 13 whitelabel CVD intake portal and public SPOC
Not advertised
Included on Free tier with branded domain, PGP encryption, and 48-hour acknowledgment SLA
Article 14 ENISA SRP 24h / 72h / final reporting cascade
Vulnerability alerting without SRP-ready export packages
Built in with in-product countdown timers and SRP-ready manual filing packages
Annex VII Technical Documentation and EU Declaration of Conformity
Firmware scan evidence for the file, not the legal declaration
Generated per product version with 10-year audit trail and CE marking checklist

Where Cybellum is strong

  • +Binary-to-SBOM decomposition producing Cyber Digital Twins without source code.
  • +Deep mapping to automotive (ISO/SAE 21434), medical device, and industrial security standards.
  • +Automated reachability analysis and continuous vulnerability monitoring.
  • +Built-in PSIRT incident response and vulnerability investigation suite.

Where it is not a CRA fit

  • !High-budget enterprise positioning focused on Tier-1 automotive and industrial manufacturers.
  • !No published free or low-tier plan for EU SME manufacturers seeking to fulfill Article 13 baselines.
  • !Does not provide a public whitelabel vulnerability intake portal (RFC 9116 SPOC) for external researchers.
  • !Compliance outputs provide technical evidence packs rather than self-contained Module A conformity documentation for general PDEs.

The CRA gap

Cybellum generates Cyber Digital Twins and SBOMs for complex embedded systems. The CRA places horizontal legal obligations on every product: operating a public Article 13 single point of contact, executing the 24-hour Article 14 reporting cascade to ENISA, and compiling the Annex VII technical file and EU Declaration of Conformity.

Why teams pick CVD Portal for CRA

Five capabilities a CRA conformity workspace provides alongside a product security platform. Most manufacturers keep both.

  1. 1

    Generates the complete Annex VII Technical File, EU Declaration of Conformity, and CE marking checklist.

  2. 2

    Free whitelabel Article 13 intake portal with hosted RFC 9116 security.txt under your brand.

  3. 3

    First-class Article 14 reporting engine with 24h/72h timers and SRP-ready manual filing dossiers.

  4. 4

    Imports SBOM and vulnerability evidence from Cybellum rather than duplicating security testing.

  5. 5

    Accessible, published pricing with a €0/month Free tier for SME manufacturers.

Frequently asked

Does Cybellum support CRA compliance?
Cybellum supports the product security and vulnerability handling requirements in CRA Annex I Part II through automated SBOM generation and binary analysis. It does not provide the public Article 13 disclosure portal or the complete Annex VII legal declaration.
Can CVD Portal ingest Cybellum data?
Yes. Cybellum exports standard CycloneDX and SPDX SBOMs alongside VEX vulnerability assessments. CVD Portal ingests these machine-readable artifacts and attaches them to the relevant CRA Annex I evidence requirements.
What is the difference between a Cyber Digital Twin and a CRA technical file?
A Cyber Digital Twin is an engineering representation of a device's software architecture and dependencies for vulnerability analysis. An Annex VII technical file is the legal compliance dossier required under EU law to support the CE marking and Declaration of Conformity.
Do we need both Cybellum and CVD Portal?
Manufacturers of complex connected hardware often use Cybellum for deep firmware decomposition and PSIRT investigation, while using CVD Portal to manage the public Article 13 intake portal, Article 14 regulatory reporting, and legal conformity documentation.
Where is CVD Portal data hosted?
All CVD Portal data is hosted within the European Union by default with EU-resident analytics and logging.

Connect Cyber Digital Twins to EU CRA conformity

Import your Cybellum SBOM and vulnerability findings, and complete your Annex VII documentation and Article 14 filing workflows in CVD Portal. The Article 13 baseline is €0/month.