First obligations from September 2026
SBOMs

A current SBOM for every product — generated, imported, and centrally managed

Generation with the open-source Kunnus scanner, CycloneDX and SPDX import, automatic format detection, and vulnerability correlation

Annex I Part II No. 1 of the EU Cyber Resilience Act requires manufacturers to create and maintain a Software Bill of Materials for every product. Kunnus covers both paths: generate SBOMs with the open-source Kunnus scanner directly from source code, containers, or firmware — or import existing CycloneDX and SPDX files via drag-and-drop. All SBOMs live centrally, versioned and correlated with vulnerabilities.

Annex I Part II No. 1Legal basis
CycloneDX & SPDXFormats
Open sourceScanner
CentralRepository
app.kunnus.tech/products/smartsensor-xr/sbom

SBOM Explorer

CycloneDX
Search components...
📦smartsensor-firmware@3.2.1
├── 📦linux-kernel@5.15.94
No issues
├── 📦openssl@3.0.13
2 Critical
├── 📦libcrypto@3.0.13
CVE-2024-0727
└── 📦libssl@3.0.13
Patched
├── 📦freertos@10.6.1
No issues
├── 📦curl@8.5.0
1 High
├── 📦sqlite@3.45.0
No issues
├── 📦zlib@1.3.1
No issues
├── 📦mbedtls@3.5.1
No issues
└── 📦app-logic@3.2.1
├── 📦lwip@2.2.0
No issues
└── 📦protobuf-c@1.5.0
No issues

Key Benefits

Generate with the Kunnus Scanner

The open-source kunnus-scanner generates SBOMs from source code, container images, OS and firmware images — locally or directly in your CI/CD pipeline.

Import via Drag-and-Drop

Upload CycloneDX and SPDX files with automatic format detection. Client-side validation, version labeling, and current-SBOM flagging.

Central SBOM Repository

Central archive for all SBOMs. View, download, archive, and mark as current. Stats: total SBOMs, components indexed, coverage.

SBOM-to-Product Mapping

Manage links between SBOMs and products or components. Clear assignment of which SBOM belongs to which product and version.

Capabilities

Automatic Format Detection

Annex I Part II No. 1

On upload, Kunnus automatically detects whether the file is CycloneDX JSON, CycloneDX XML, or SPDX. No manual configuration required.

Versioning & Archiving

Every uploaded SBOM is versioned. Older versions remain accessible in the archive, and the current SBOM is clearly flagged.

Per-Component Vulnerability Correlation

Annex I Part II

Every SBOM component is checked against known vulnerabilities. Severity filters enable quick prioritization.

Coverage Statistics

Dashboard with total SBOMs, indexed components, and coverage rate across your product portfolio.

Cross-Product SBOM Analysis

Identify shared components across your entire portfolio. When a new vulnerability appears, you instantly see all affected products.

Use Cases

01

Fulfill the SBOM Requirement

An embedded systems manufacturer generates SBOMs with the kunnus-scanner directly in the CI/CD pipeline. Kunnus auto-versions each SBOM and correlates vulnerabilities — the Annex I Part II No. 1 documentation is created as a byproduct.

02

Supply Chain Transparency

A device manufacturer receives SBOMs from 15 suppliers in different formats. Kunnus auto-detects all formats and shows the complete picture of all third-party components.

03

Zero-Day Response

When a critical vulnerability is disclosed, Kunnus identifies all affected products in the portfolio within seconds via the central SBOM repository.

Make your software supply chain transparent

See how Kunnus connects SBOM generation, import, and vulnerability correlation. We'll walk you through the workflow in a personalized demo.