ComparisonApplication security posture management

Cycode vs CVD Portal

Complete ASPM with SBOM generation, supply chain risk and audit-ready evidence collection. How does Cycode compare to CVD Portal for an EU manufacturer subject to the Cyber Resilience Act?

Headquarters
Tel Aviv, Israel
Category
Application security posture management
Pricing model
Annual subscription priced on request. No published rate card.

How they compare on CRA-critical features

Five differences between an engineering-side security platform and a product conformity workspace under Regulation (EU) 2024/2847. The first row is where Cycode is stronger.

Feature
Cycode
CVD Portal
SBOM generation and component vulnerability tracking
Core strength. Usually deeper than ours
Supported, and linked to the Annex I Part II duty it evidences. Import an existing SBOM rather than duplicating the scanner
Annex III / Annex IV classification and the Article 32 route
Not advertised
Free classifier. The result decides which requirements apply and whether the product can self-assess
Annex I Part I applicability table with justifications
Not advertised
Every essential requirement marked applicable with a reference or not applicable with a justification that has to survive review
Annex VII technical documentation, EU Declaration of Conformity, CE marking
Evidence for the file. Not the file itself
Generated per product and versioned with the record
Article 13 CVD policy and whitelabel single point of contact
Not advertised
Included on the Free tier, under the manufacturer's own domain

Where Cycode is strong

  • +Automated SBOM generation across the software supply chain, in machine-readable formats, which is the Annex I Part II(1) duty and the hardest one to do by hand.
  • +Real-time visibility into open source, supply chain and code risk with prioritised remediation, covering the continuous vulnerability handling duties in Annex I Part II.
  • +Centralises SBOMs and audit-ready evidence so conformity can be demonstrated across products and releases, which is genuine input into the technical file.
  • +Deep integration into the development toolchain, so evidence is produced where the work happens instead of being collected at audit time.

Where it is not a CRA fit

  • !The published CRA material does not claim Article 14 reporting to ENISA or the national CSIRT, which is the obligation with a 24-hour clock on it from 11 September 2026.
  • !No published feature for Annex III and Annex IV classification, which is the decision that determines which requirements apply and which Article 32 route the product takes.
  • !No published Annex I Part I applicability table. Part II vulnerability handling is well covered, and Part I is the other half of the essential requirements.
  • !No published EU Declaration of Conformity, Annex VI simplified declaration or CE marking workflow. The page describes evidence for the technical file rather than the file and the declaration themselves.
  • !No whitelabel Article 13 intake portal or published CVD policy under the manufacturer's own domain.

The CRA gap

Cycode is strong on the engineering half of Annex I Part II, and the SBOM and vulnerability evidence it produces is exactly what a technical file needs underneath it. What it does not do, on its published material as of August 2026, is the conformity work either side. A manufacturer still has to classify each product against Annex III and Annex IV, decide every Annex I Part I essential requirement and justify the ones marked not applicable, assemble the Annex VII documentation, sign an EU Declaration of Conformity, affix the CE marking, run an Article 13 single point of contact, and file the Article 14 cascade inside 24 hours of learning a vulnerability is being actively exploited.

Why teams pick CVD Portal for CRA

Five things a conformity workspace adds on top of a scanner. Most manufacturers that need both run both.

  1. 1

    Classification first. Annex III and Annex IV decide which requirements apply and whether the product can self-assess at all, and everything downstream depends on that answer.

  2. 2

    Produces the conformity artifacts, not only the evidence for them. Annex I applicability table, Annex VII documentation index, EU Declaration of Conformity, Annex VI simplified form and CE marking checklist.

  3. 3

    Article 14 reporting is first-class, with 24h, 72h and final-report timers and an SRP-ready submission package on Enterprise.

  4. 4

    Article 13 baseline is free. Whitelabel intake, published CVD policy and acknowledgment tracking at €0/month.

  5. 5

    Accepts an existing SBOM rather than competing with the scanner that produced it, so the two stack instead of overlapping.

Frequently asked

Does Cycode cover the Cyber Resilience Act?
It covers part of it well. Its published CRA material claims automated SBOM generation, vulnerability tracking and evidence collection for technical files and CE marking, which maps onto the Annex I Part II vulnerability handling duties. It does not claim Annex III classification, the Annex I Part I applicability decision, the EU Declaration of Conformity, or Article 14 reporting to ENISA and the national CSIRT. Those remain with the manufacturer.
We already generate SBOMs with Cycode. Do we need a second tool?
Not a second scanner. What is missing is the conformity layer the SBOM feeds. The CRA requires the SBOM inside Annex VII technical documentation, alongside a classification decision, an Annex I applicability table, a signed Declaration of Conformity and a working Article 14 reporting path. CVD Portal imports the SBOM you already have and attaches it to the requirement it evidences.
Is an SBOM enough for CRA compliance?
No. The SBOM is one requirement, in Annex I Part II(1). Annex I Part I sets out the essential product requirements, Article 13 requires a published disclosure policy and a single point of contact, Article 14 requires reporting an actively exploited vulnerability within 24 hours from 11 September 2026, and Articles 27 to 32 cover the Declaration of Conformity, CE marking and the conformity assessment route.
Can CVD Portal replace Cycode?
No, and it does not try. If you need code scanning, supply chain risk detection and SBOM generation inside the development pipeline, keep the tool that does it. CVD Portal is the conformity record the output lands in.
Does CVD Portal carry out the conformity assessment itself?
It produces the file the assessment rests on, and where the route allows it, supports the self-assessment. Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

Keep the scanner, add the conformity file

Import the SBOM, map it against Annex I, and let classification, the technical documentation and Article 14 filing run from one product record. The Article 13 baseline is €0/month.