SBOM checker
Drop a CycloneDX or SPDX JSON file. The checks run in your browser and the file is not uploaded. The Regulation asks for an SBOM in a commonly used, machine-readable format that covers at least the top-level dependencies (Annex I, Part II). The checks here follow the NTIA minimum elements; the Regulation does not name them, and German practice also looks at the stricter BSI TR-03183-2. Passing is not a statement of compliance.
SBOM file (CycloneDX or SPDX, JSON)
Known vulnerabilities
Pressing the button sends the package URLs (names and versions) of the components to the public OSV database at api.osv.dev, and nothing else. It is not done automatically.
Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.