A current SBOM for every product — generated, imported, and centrally managed
Generation with the open-source Kunnus scanner, CycloneDX and SPDX import, automatic format detection, and vulnerability correlation
Annex I Part II No. 1 of the EU Cyber Resilience Act requires manufacturers to create and maintain a Software Bill of Materials for every product. Kunnus covers both paths: generate SBOMs with the open-source Kunnus scanner directly from source code, containers, or firmware — or import existing CycloneDX and SPDX files via drag-and-drop. All SBOMs live centrally, versioned and correlated with vulnerabilities.
SBOM Explorer
CycloneDXVulnerability Summary
Licenses
Key Benefits
Generate with the Kunnus Scanner
The open-source kunnus-scanner generates SBOMs from source code, container images, OS and firmware images — locally or directly in your CI/CD pipeline.
Import via Drag-and-Drop
Upload CycloneDX and SPDX files with automatic format detection. Client-side validation, version labeling, and current-SBOM flagging.
Central SBOM Repository
Central archive for all SBOMs. View, download, archive, and mark as current. Stats: total SBOMs, components indexed, coverage.
SBOM-to-Product Mapping
Manage links between SBOMs and products or components. Clear assignment of which SBOM belongs to which product and version.
Capabilities
Automatic Format Detection
Annex I Part II No. 1On upload, Kunnus automatically detects whether the file is CycloneDX JSON, CycloneDX XML, or SPDX. No manual configuration required.
Versioning & Archiving
Every uploaded SBOM is versioned. Older versions remain accessible in the archive, and the current SBOM is clearly flagged.
Per-Component Vulnerability Correlation
Annex I Part IIEvery SBOM component is checked against known vulnerabilities. Severity filters enable quick prioritization.
Coverage Statistics
Dashboard with total SBOMs, indexed components, and coverage rate across your product portfolio.
Cross-Product SBOM Analysis
Identify shared components across your entire portfolio. When a new vulnerability appears, you instantly see all affected products.
Use Cases
Fulfill the SBOM Requirement
An embedded systems manufacturer generates SBOMs with the kunnus-scanner directly in the CI/CD pipeline. Kunnus auto-versions each SBOM and correlates vulnerabilities — the Annex I Part II No. 1 documentation is created as a byproduct.
Supply Chain Transparency
A device manufacturer receives SBOMs from 15 suppliers in different formats. Kunnus auto-detects all formats and shows the complete picture of all third-party components.
Zero-Day Response
When a critical vulnerability is disclosed, Kunnus identifies all affected products in the portfolio within seconds via the central SBOM repository.
Related Features
Make your software supply chain transparent
See how Kunnus connects SBOM generation, import, and vulnerability correlation. We'll walk you through the workflow in a personalized demo.