Cycode vs CVD Portal
Complete ASPM with SBOM generation, supply chain risk and audit-ready evidence collection. How does Cycode compare to CVD Portal for an EU manufacturer subject to the Cyber Resilience Act?
- Headquarters
- Tel Aviv, Israel
- Category
- Application security posture management
- Pricing model
- Annual subscription priced on request. No published rate card.
How they compare on CRA-critical features
Five differences between an engineering-side security platform and a product conformity workspace under Regulation (EU) 2024/2847. The first row is where Cycode is stronger.
Where Cycode is strong
- +Automated SBOM generation across the software supply chain, in machine-readable formats, which is the Annex I Part II(1) duty and the hardest one to do by hand.
- +Real-time visibility into open source, supply chain and code risk with prioritised remediation, covering the continuous vulnerability handling duties in Annex I Part II.
- +Centralises SBOMs and audit-ready evidence so conformity can be demonstrated across products and releases, which is genuine input into the technical file.
- +Deep integration into the development toolchain, so evidence is produced where the work happens instead of being collected at audit time.
Where it is not a CRA fit
- !The published CRA material does not claim Article 14 reporting to ENISA or the national CSIRT, which is the obligation with a 24-hour clock on it from 11 September 2026.
- !No published feature for Annex III and Annex IV classification, which is the decision that determines which requirements apply and which Article 32 route the product takes.
- !No published Annex I Part I applicability table. Part II vulnerability handling is well covered, and Part I is the other half of the essential requirements.
- !No published EU Declaration of Conformity, Annex VI simplified declaration or CE marking workflow. The page describes evidence for the technical file rather than the file and the declaration themselves.
- !No whitelabel Article 13 intake portal or published CVD policy under the manufacturer's own domain.
The CRA gap
Cycode is strong on the engineering half of Annex I Part II, and the SBOM and vulnerability evidence it produces is exactly what a technical file needs underneath it. What it does not do, on its published material as of August 2026, is the conformity work either side. A manufacturer still has to classify each product against Annex III and Annex IV, decide every Annex I Part I essential requirement and justify the ones marked not applicable, assemble the Annex VII documentation, sign an EU Declaration of Conformity, affix the CE marking, run an Article 13 single point of contact, and file the Article 14 cascade inside 24 hours of learning a vulnerability is being actively exploited.
Why teams pick CVD Portal for CRA
Five things a conformity workspace adds on top of a scanner. Most manufacturers that need both run both.
- 1
Classification first. Annex III and Annex IV decide which requirements apply and whether the product can self-assess at all, and everything downstream depends on that answer.
- 2
Produces the conformity artifacts, not only the evidence for them. Annex I applicability table, Annex VII documentation index, EU Declaration of Conformity, Annex VI simplified form and CE marking checklist.
- 3
Article 14 reporting is first-class, with 24h, 72h and final-report timers and an SRP-ready submission package on Enterprise.
- 4
Article 13 baseline is free. Whitelabel intake, published CVD policy and acknowledgment tracking at €0/month.
- 5
Accepts an existing SBOM rather than competing with the scanner that produced it, so the two stack instead of overlapping.
Frequently asked
Does Cycode cover the Cyber Resilience Act?
We already generate SBOMs with Cycode. Do we need a second tool?
Is an SBOM enough for CRA compliance?
Can CVD Portal replace Cycode?
Does CVD Portal carry out the conformity assessment itself?
Keep the scanner, add the conformity file
Import the SBOM, map it against Annex I, and let classification, the technical documentation and Article 14 filing run from one product record. The Article 13 baseline is €0/month.