Vallanx
Get a free demo version of Cyber Security Audit Pro

Your e-mail address
CC recipients
Message
5000 Characters available
Cyber Security Audit Pro

With its flexible architecture, an extensive library of various national and international frameworks, and dedicated risk profiles, Cyber Security Audit Pro is suitable for both small and large companies.

Manage internal and external compliance audits centrally. At the same time, provide all stakeholders with a secure, protected platform for submitting data & documents. Whether for supplier audits or internal compliance monitoring.

For IT managers

Technical depth with 1,000+ automated compliance checks
Industry-specific controls (OT/ICS, cloud/SaaS, medical devices, etc.)
API-based integration into existing SIEM/GRC systems
Open source transparency for security review and customizability
Integrated vulnerability scans with automatic finding generation

For compliance managers

Central management of all compliance frameworks on one platform
Automated gap analyses with prioritized recommendations for action
Professional audit reports for management, regulators and auditors
Traceable compliance progress with historical trend analyses
Manage multiple organizations for group structures and consulting
Use our online tool to find out directly for yourself which compliance requirements & regulatory frameworks are relevant for your company.

Plugin overview

Simplify your compliance processes with the right plugin. If you are missing a particular framework or need an integration not yet listed, get in touch with us! We are happy to implement your requirements quickly.

International

FDA-21-CFR-Part-11
Framework
Global
Health
Clinical

21 CFR Part 11 is the US FDA regulation that establishes the criteria for the trustworthiness of electronic records and electronic signatures in FDA-regulated industries.

Applies to: Pharmaceutical, biotech and medical device companies as well as CROs with FDA exposure

  • Validation, audit trails and electronic signatures mandatory
  • ALCOA+ principles for data integrity
  • Complemented by EU GMP Annex 11 for European sites
  • Can be combined with ICH E6 (R2) GCP for clinical trials
FedRAMP
Framework
Global
Agencies
Regulation

FedRAMP standardizes the security assessment and authorization of cloud services for US federal agencies based on NIST SP 800-53 and enables an authorization to be reused across multiple agencies.

Applies to: Cloud Service Providers (CSPs) serving US federal agencies

  • FedRAMP Moderate baseline with approximately 325 controls
  • Authorization paths: JAB P-ATO or Agency ATO
  • Monthly Continuous Monitoring (ConMon) mandatory
  • Annual 3PAO reassessment required
HIPAA
Framework
Global
Health
Privacy

The Health Insurance Portability and Accountability Act is the US federal law protecting health data (PHI) and governs privacy, security and notification obligations for covered entities and business associates.

Applies to: US healthcare providers, health insurers and their business associates

  • 2026 Security Rule update: encryption and MFA mandatory
  • Breach notification to affected individuals and HHS within 60 days
  • 6-year retention requirement for audit logs and documentation
  • Civil penalties of up to $1.5 million per year and category
HITRUST
Framework
Global
Health
Regulation

The HITRUST Common Security Framework is a meta-framework that consolidates requirements from more than 50 standards (including HIPAA, ISO 27001, NIST, PCI DSS) and is established as a certifiable compliance benchmark in US healthcare.

Applies to: Healthcare organizations, business associates and cloud providers in US healthcare

  • Assessment types range from e1 (basic) to CSF Certified (full certification)
  • Risk-based implementation levels 1-3
  • Certificate valid for 2 years with annual surveillance
  • Frequent contractual requirement for business associates
ICH-E6-GCP
Framework
Global
Clinical
Health

ICH E6 (R2) Good Clinical Practice is the internationally recognized standard for the design, conduct and documentation of clinical trials; this plugin focuses on the IT and cybersecurity aspects of computerized trial systems.

Applies to: Pharmaceutical companies (sponsors), CROs, clinical trial sites and technology providers (EDC, eTMF)

  • Computerized Systems Validation according to GAMP 5
  • Risk-Based Quality Monitoring (RBQM) and centralized monitoring
  • ALCOA+ data integrity for clinical data
  • Can be combined with FDA 21 CFR Part 11 and GDPR
ISO-27001
Framework
Global
Regulation

ISO/IEC 27001:2022 is the world's most widely recognized standard for information security management systems (ISMS) and, with its 93 Annex A controls, forms the basis for numerous industry-specific frameworks.

Applies to: Organizations of all industries and sizes that want to build or certify an ISMS

  • 93 controls across 4 categories (Organizational, People, Physical, Technological)
  • Certification by accredited bodies, valid for 3 years
  • Statement of Applicability (SoA) as a mandatory document
  • Basis for, among others, BAIT, MaRisk AT9, NIS-2 and DORA evidence
ISO-27799
Framework
Global
Health
Regulation

ISO/IEC 27799:2016 is not a standalone control list but rather the sector-specific interpretation guide for ISO 27001/27002 in healthcare, including controls for emergency access and medical device security.

Applies to: Hospitals, clinics, medical practices and health IT providers internationally

  • Break-the-glass emergency access to patient data as a core control
  • Medical device security and IoMT-specific requirements
  • Health Information Exchange (HL7 FHIR, IHE) security
  • Internationally recognized alternative to HIPAA outside the US
NERC-CIP
Framework
Global
Energy
Agencies

NERC CIP is the mandatory cybersecurity standards framework for the North American power sector (Bulk Electric System), developed by the North American Electric Reliability Corporation and enforced by FERC.

Applies to: Operators and owners of the North American transmission and generation grid (US, Canada, Mexico)

  • 11 standards CIP-002 through CIP-013 with strict deadlines (15/35/90 days)
  • Categorization by High/Medium/Low Impact BES Cyber Systems
  • Supply chain risk management (CIP-013) mandatory
  • Fines of up to $1 million per day and violation
NIST-CSF
Framework
Global
Regulation

The NIST Cybersecurity Framework 2.0 provides an internationally recognized taxonomy for managing cybersecurity risk with the six core functions Govern, Identify, Protect, Detect, Respond and Recover.

Applies to: Organizations of all industries and sizes, usable internationally

  • New GOVERN function since version 2.0 (2024)
  • Four implementation tiers for maturity measurement
  • Basis for CMMC and numerous sector-specific frameworks
  • Official mappings to ISO 27001, CIS Controls and NIST 800-53
NIST-SSDF-FOSS
Framework
Global
Product

This plugin implements the NIST Secure Software Development Framework (SP 800-218) with a particular focus on secure open-source software development, supply chain security and OpenSSF best practices.

Applies to: Software developers, open-source projects and DevSecOps teams

  • SBOM and SCA requirements for dependency management
  • Branch protection, signed commits and secure CI/CD
  • OpenSSF Scorecard and SLSA compliance as a maturity goal
  • Basis for Executive Order 14028 and CISA attestation
PCI-DSS
Framework
Global
Payment
Regulation

PCI DSS v4.0 is the global security standard of the Payment Card Industry for all organizations that store, process or transmit credit card data.

Applies to: Merchants, payment service providers and financial institutions handling card payment processing

  • 12 requirements across 6 categories, fully mandatory from March 31, 2025
  • MFA required for all access to the Cardholder Data Environment
  • Quarterly ASV scans and annual penetration tests
  • Fines of up to $100,000 per month plus loss of card acceptance
SLSA
Framework
Global
Product

SLSA (Supply-chain Levels for Software Artifacts) is a progressive framework backed by OpenSSF for securing the software supply chain through cryptographically verifiable build provenance.

Applies to: Software developers, open-source projects and cloud-native organizations

  • Four maturity levels for the build and source track (Level 0-3)
  • Provenance generation and verification via Sigstore/Cosign
  • Complementary to NIST SSDF, SOC 2 and ISO 27001
  • Broad industry adoption by Google, GitHub, GitLab, Microsoft
SOC-2
Framework
Global
Regulation

SOC 2 is based on the AICPA's Trust Services Criteria and is the de facto compliance standard for SaaS and cloud providers to demonstrate security, availability, confidentiality and privacy.

Applies to: SaaS providers, cloud providers and technology-based service providers

  • Type I (point in time) vs. Type II (6-12 months of operating effectiveness evidence)
  • Security (Common Criteria) as a mandatory category
  • Audited exclusively by independent CPA firms
  • Frequent contractual requirement for enterprise customers
SWIFT-CSP
Framework
Global
Finance
Payment

The SWIFT Customer Security Programme requires all institutions connected to the SWIFT network to implement and annually self-attest to the security controls of the Customer Security Controls Framework (CSCF).

Applies to: Banks and financial institutions connected to the SWIFT payment network

  • 25 mandatory and 7 advisory controls across 7 principles
  • MFA mandatory for all SWIFT operator access since 2020
  • Annual attestation via the KYC-SA portal
  • 24-hour reporting obligation for cyber incidents to the SWIFT ISAC

Industry-specific

Chemicals & Raw Materials
Sector
Global
Product

The Chemicals & Raw Materials Sector Plugin addresses the unique cybersecurity requirements of the chemical industry, in particular process safety, Safety Instrumented Systems (SIS) and REACH/Seveso III compliance.

Applies to: Basic, specialty and petrochemical, polymer, agrochemical and raw material processing companies

  • DCS and SIS security according to IEC 61511 (SIL 1-4)
  • Seveso III major accident prevention with cyber-HAZOP
  • ATEX zone classification for explosion-protected IT equipment
  • 20 controls in 11 categories, including REACH and dangerous goods transport
Cloud & SaaS
Sector
Global
Product

The Cloud, SaaS & Data Services Sector Plugin addresses the specific security requirements of multi-tenant architectures, API-first systems and cloud-native technologies such as Kubernetes and serverless.

Applies to: SaaS providers, cloud service providers, managed service providers and platform operators

  • Multi-tenancy isolation (silo/bridge/pool) and cross-tenant protection
  • API security, container and Kubernetes hardening
  • Shared responsibility model and CSPM integration
  • Alignment with CSA CCM, C5, FedRAMP, ISO 27017/27018
Energy & Renewables
Sector
Global
Energy

The Energy & Renewables Sector Plugin covers SCADA/ICS security, smart grid, wind and PV plants as well as energy trading systems for conventional and renewable energy producers.

Applies to: Energy suppliers, grid operators and operators of renewable energy facilities

  • Network segmentation according to the Purdue model for SCADA/ICS
  • Smart meter and DERMS security according to BSI TR-03109
  • Wind farm and PV inverter security
  • Energy trading security with REMIT compliance
Financial Services
Sector
Global
Finance
Payment

The Financial Services Sector Plugin covers the full spectrum from retail to investment banking, with a focus on payment security, open banking (PSD2), trading systems, fraud detection and AML.

Applies to: Banks, insurers, payment service providers and investment firms

  • 21 controls, including 7 dedicated PSD2 SCA controls
  • SWIFT CSP and trading system security (MiFID II/MAR)
  • Real-time fraud detection and AML/KYC monitoring
  • Closely interlinked with DORA, PSD2 and BaFin MaRisk
Healthcare & Medicine
Sector
Global
Health
Clinical

The Healthcare & Medicine Sector Plugin provides controls for hospital information systems, electronic health records, medical devices (IoMT), telemedicine, as well as German-specific requirements (PatRG, SGB V/Telematics Infrastructure).

Applies to: Hospitals, clinics, medical practices, telemedicine providers and pharmacies

  • 23 controls in 15 categories, including HIS, PACS, LIS, IoMT
  • Break-the-glass emergency access and medical device segmentation
  • TI connectivity (TI connector, eGK, KIM, e-prescription) under SGB V
  • Complements GDPR, EU MDR and HIPAA for healthcare specifics
Industrial Manufacturing
Sector
Global
Product

The Industrial Manufacturing Sector Plugin addresses Industry 4.0 technologies, OPC UA security, MES, robotics/cobots, CAD/PLM data protection as well as TISAX compliance for the manufacturing industry.

Applies to: Metal, electrical and mechanical engineering as well as automotive suppliers (Tier 1-3)

  • 25 controls in 12 categories according to IEC 62443 (zones & conduits)
  • OPC UA mandatory in Sign & Encrypt mode
  • TISAX prototype protection and automotive supply chain security
  • Production-first incident response (Safety > Security > Availability)
OEM & Automotive
Sector
Global
Product

The OEM Automotive Sector Plugin addresses the UN R155/R156 requirements (CSMS/SUMS) mandatory since 2024 for vehicle type approval, as well as V2X, VSOC and ECU security for vehicle manufacturers.

Applies to: Vehicle manufacturers (OEMs) of passenger cars, commercial vehicles, electric and autonomous vehicles

  • Cyber Security Management System (CSMS) under UN R155 mandatory since July 2024
  • Software Update Management System (SUMS) for OTA updates under UN R156
  • Vehicle Security Operations Center (VSOC) for fleet monitoring
  • Based on ISO/SAE 21434:2021
Online Platforms
Sector
Global
Payment
Privacy

The Online Platforms & E-Commerce Sector Plugin addresses business-specific security requirements of online retail: checkout security, fraud detection, account takeover prevention and marketplace trust systems.

Applies to: B2C/B2B e-commerce, marketplaces, subscription commerce and digital goods

  • PCI DSS-compliant checkout and payment security
  • Order fraud and account takeover prevention
  • Bot detection and scraping protection for product catalogs
  • GDPR-compliant cookie consent and marketing management
Pharma & LifeScience
Sector
Global
Health
Clinical

The Pharma & Life Science Sector Plugin covers all GxP areas (GMP, GCP, GLP, GDP) as well as FDA 21 CFR Part 11, EU GMP Annex 11, ISO 13485 and EU MDR/IVDR for pharmaceutical and medical technology companies.

Applies to: Pharmaceutical manufacturers, biotech companies, CROs, medical device manufacturers and QC laboratories

  • 18 controls in 10 categories for MES, LIMS, EBR, EDC and eTMF
  • ALCOA+ data integrity as an overarching principle
  • Serialization/track-and-trace under EU FMD and US DSCSA
  • GAMP 5 validation lifecycle (IQ/OQ/PQ)
Telco Networks
Sector
Global
Regulation

The Telecommunications & Networks Sector Plugin covers 5G/4G core networks, SS7/signaling, VoIP/IMS, BSS/OSS, lawful interception and DDoS protection for telecommunications operators and ISPs.

Applies to: Mobile and fixed-line network operators, internet service providers and data center operators

  • 12 controls in 12 categories, including 5G core and SS7 security
  • Lawful interception compliance according to ETSI ES 201 671
  • Subscriber privacy under GDPR and the ePrivacy Directive
  • NIS-2 reporting deadlines of 24h/72h/30 days as a critical sector

Germany

BAIT
Framework
DE
Finance

BAIT (Bank Supervisory Requirements for IT) is a BaFin circular that specifies IT-specific requirements for German credit institutions. BAIT is the implementation and elaboration of MaRisk AT 7.2 (IT resources) and BTR 5 (operational risks) specifically for IT topics.

Applies to: German credit institutions (banks, savings banks, cooperative banks)

  • Part of MaRisk
  • Complemented by DORA (from 2025)
  • References ISO 27001 for ISMS
  • Alignment with ISO 22301
BSI-IT-Grundschutz
Framework
DE
Regulation

BSI IT-Grundschutz is the German information security management standard developed by the Federal Office for Information Security (BSI). It forms the basis for ISO 27001 certification based on IT-Grundschutz and underlies the KRITIS evidence requirement.

Applies to: German public authorities, companies of all sizes, KRITIS operators

  • Basis for ISO 27001 certification based on IT-Grundschutz
  • Complemented by BSI standards 200-1 through 200-4
  • Basis for KRITIS evidence under the IT Security Act
  • Referenced by BAIT, VAIT, ZAIT in the financial sector
KRITIS-V
Framework
DE
Energy
Agencies

The BSI-KRITIS Regulation specifies, based on Sections 8a, 8b of the BSIG, which facilities are considered critical infrastructure and governs the IT security requirements for their operators across nine sectors.

Applies to: Operators of critical infrastructure in Germany (energy, water, healthcare, finance, IT/telecom, transport, among others)

  • Security concept under Section 8a BSIG mandatory
  • Obligation to report significant disruptions to the BSI
  • Biennial audit by recognized auditing bodies
  • Complements NIS-2, does not replace it
MaRisk
Framework
DE
Finance
Agencies

MaRisk (Minimum Requirements for Risk Management) are BaFin circulars that specify the risk management requirements for German credit and financial services institutions, with a particular focus on IT security (AT 9) and outsourcing (AT 7.2).

Applies to: German credit and financial services institutions

  • AT 9: data and IT security as a core control
  • AT 7.2: outsourcing management including ZAIT reporting obligation
  • Complemented by BAIT for IT-specific requirements
  • Complemented, not replaced, by DORA from 2025

France

LPM
Framework
FR
Agencies
Law

The Loi de Programmation Militaire 2024-2030 tightens the cybersecurity requirements for French operators of vital importance (OIV) and their critical information systems (SIIV), enforced by ANSSI.

Applies to: French Opérateurs d'Importance Vitale (OIV) across 10 strategic sectors (energy, defense, finance, healthcare, among others)

  • Security homologation (homologation de sécurité) mandatory for SIIV
  • Use of ANSSI-qualified products/service providers (PDIS/PASSI/PRIS)
  • Transmission of DNS data to ANSSI in the event of incidents
  • Criminal sanctions of up to 5 years' imprisonment possible
RGS
Framework
FR
Signature
Identity

The Référentiel Général de Sécurité v2.0 is the French security framework for public authorities and public online services, structured according to the DICA principle (Disponibilité, Intégrité, Confidentialité, Authenticité).

Applies to: French public authorities, public administrations and trust service providers

  • Security homologation in 9 steps following ANSSI methodology
  • Risk analysis mandatory via EBIOS Risk Manager
  • Three security levels (*, **, ***) depending on protection needs
  • Closely linked to eIDAS for electronic trust services

EU-wide

CRA
Framework
EU
Product
Regulation

The Cyber Resilience Act (EU 2024/2847) establishes horizontal cybersecurity requirements for products with digital elements across their entire lifecycle and is a prerequisite for CE marking.

Applies to: Manufacturers, importers and distributors of hardware and software products in the EU

  • Mandatory vulnerability and incident reporting from September 11, 2026
  • Full application from December 11, 2027
  • Security by design and SBOM requirement
  • Fines of up to €15 million or 2.5% of annual turnover
DORA
Framework
EU
Finance
Regulation

The Digital Operational Resilience Act (EU 2022/2554) requires financial entities in the EU to meet uniform requirements for ICT risk management, incident reporting, resilience testing and third-party risk management.

Applies to: EU financial entities (banks, insurers, payment service providers, crypto service providers, among others)

  • Mandatory since January 17, 2025
  • Reporting deadlines for ICT incidents: 4h/72h/1 month
  • TLPT (Threat-Led Penetration Testing) every 3 years
  • Complements national frameworks such as MaRisk and BAIT
EBA-ICT-Guidelines
Framework
EU
Finance
Agencies

The EBA ICT Guidelines Framework consolidates the European Banking Authority's requirements for ICT and security risk management into a unified control framework for financial institutions.

Applies to: Credit institutions, investment firms, payment and e-money institutions in the EU

  • Consolidates EBA/GL/2019/04, 2019/02, 2020/06, 2018/07, 2017/11
  • Three Lines of Defense model for ICT governance
  • EBA reporting deadlines of 4h/72h/30 days for major incidents
  • Preparation for DORA requirements
eIDAS
Framework
EU
Identity
Signature

The eIDAS Regulation (EU 910/2014) creates the legal framework for electronic identification and trust services in the EU single market and ensures cross-border recognition of qualified electronic signatures.

Applies to: Trust service providers (TSP/QTSP) and organizations with eIDAS-compliant systems

  • Qualified electronic signature legally equivalent to a handwritten signature
  • QTSP accreditation requires Notified Body certification
  • eIDAS 2.0 introduces the EU Digital Identity Wallet
  • Relevant, among other things, for PSD2 TPP authentication
EU-AI-Act
Framework
EU
AI
Regulation

The EU AI Act (EU 2024/1689) is the world's first comprehensive legal framework for artificial intelligence and establishes risk-based requirements for the development, placing on the market and use of AI systems.

Applies to: Providers, deployers, importers and distributors of AI systems with a connection to the EU

  • Risk-based approach: unacceptable/high/limited/minimal
  • Prohibited practices already banned as of February 2, 2025
  • Full application from August 2, 2026
  • Fines of up to €35 million or 7% of global turnover
GDPR
Framework
EU
Privacy
Regulation

The General Data Protection Regulation (EU 2016/679) is the world's most significant data protection regulation and applies to all organizations that process personal data of individuals in the EU, regardless of the organization's location.

Applies to: All organizations that process personal data of EU citizens

  • Obligation to report data breaches within 72 hours
  • DPIA mandatory for high-risk processing operations
  • DPO requirement above certain thresholds
  • Fines of up to €20 million or 4% of global annual turnover
MiCAR
Framework
EU
Crypto
Finance

The Markets in Crypto-Assets Regulation (EU 2023/1114) creates the first uniform EU legal framework for crypto-assets, Crypto-Asset Service Providers (CASPs) as well as asset-referenced and e-money tokens.

Applies to: Crypto exchanges, custodians, brokers and issuers of crypto tokens in the EU

  • Authorization requirement for Crypto-Asset Service Providers (CASPs)
  • Capital requirements depending on the service class
  • Travel Rule (EU 2023/1113) for all crypto transactions
  • Closely linked to DORA for ICT risk management
NIS-2
Framework
EU
Regulation
Agencies

The NIS-2 Directive (EU 2022/2555) extends EU-wide minimum cybersecurity requirements to 18 critical sectors and, in Germany, is implemented via the NIS2 Implementation Act.

Applies to: Essential and important entities in 18 critical sectors in the EU

  • Reporting deadlines of 24h/72h/1 month for significant incidents
  • Personal liability of management (Art. 20)
  • Fines of up to €10 million or 2% of global turnover
  • MFA explicitly mandated for critical systems
REMIT
Framework
EU
Energy
Finance

The REMIT Regulation (EU 1227/2011) prevents market manipulation and insider trading in European wholesale energy markets and requires market participants to report transactions to ACER.

Applies to: Market participants in European wholesale electricity and gas trading (generators, traders, exchanges, banks)

  • T+1 reporting deadline for all wholesale transactions to ACER
  • Publication of inside information via Urgent Market Message
  • 5-year retention obligation for transaction data
  • Fines of up to €1 million or 10% of annual turnover
TIBER-EU
Framework
EU
Finance
Agencies

TIBER-EU is the framework developed by the European Central Bank for threat-led red team testing (Threat-Led Penetration Testing) in the financial sector and forms the basis for the DORA TLPT requirement.

Applies to: Financial institutions and systemically important financial market infrastructure in the EU

  • Unannounced, threat-intelligence-based red team tests
  • Implemented nationally as, among others, TIBER-DE, TIBER-NL, TIBER-BE
  • Test cycle at least every 36 months (DORA Art. 26)
  • White/Blue/Red/Purple team structure with supervisory involvement
TISAX
Framework
EU
Product
Regulation

TISAX is the Europe-wide recognized assessment standard for the automotive industry, operated by the ENX Association and based on the VDA ISA catalog, for evaluating the information security of OEMs and suppliers.

Applies to: Automotive manufacturers and suppliers (Tier 1-3) in the European supply chain

  • Assessment by ENX-certified auditors (TÜV, DEKRA, among others)
  • Assessment levels AL1-AL3 depending on protection needs
  • Prototype protection as an automotive-specific control objective
  • Label valid for 3 years, shared via the ENX portal

Scanner & integrations

Asana
Integration
Global

The Asana integration enables automatic creation of tasks from audit findings and gap analyses with bidirectional status synchronization between Asana and the audit system.

Applies to: Teams managing remediation actions and findings in Asana

  • Automatic task creation from findings, gaps and assessments
  • Bidirectional synchronization of processing status
  • Bulk operations and automatic tag management
  • Authentication via Personal Access Token
Jira
Integration
Global

The JIRA integration enables automatic creation of tickets from audit findings and gap analyses with bidirectional status synchronization between JIRA and the audit system.

Applies to: Teams managing remediation actions and findings in JIRA

  • Automatic ticket creation with effort estimation
  • Bidirectional synchronization via JQL queries
  • Bulk ticket creation and flexible issue type configuration
  • Authentication via API token
Network-Scanner
Scanner
Global
Product

The Network Scanner is an Nmap-based network security scanner for host discovery, port scanning, service and OS fingerprinting as well as vulnerability scans.

Applies to: IT infrastructure and networks that need to be checked for open ports and vulnerabilities

  • 5 scan types: Host Discovery, Port Scan, Service/OS Detection, Vulnerability Scan
  • Automatic risk assessment of open ports
  • Findings mapping to ISO 27001, TISAX, NIS-2 and PCI DSS
  • Simulation mode available if Nmap is not installed
OWASP-Dependency-Check
Scanner
Global
Product

The OWASP Dependency-Check scanner performs Software Composition Analysis (SCA) and identifies known vulnerabilities (CVEs) in project dependencies across 11 package manager ecosystems.

Applies to: Software development teams analyzing open-source dependencies

  • Supports Maven, npm, PyPI, NuGet, Go, Composer, among others
  • CVSS-based SLA monitoring (Critical 7d, High 30d, Medium 90d)
  • SBOM generation in CycloneDX format
  • Mapping to NIST SSDF FOSS, ISO 27001, TISAX and PCI DSS
SBOM-Scanner
Scanner
Global
Product

The SBOM Scanner provides complete lifecycle management for Software Bills of Materials: generation, validation, license analysis, vulnerability enrichment, version comparison and compliance checking.

Applies to: DevSecOps teams, software vendors and compliance managers

  • Supports CycloneDX, SPDX and SWID formats
  • License policy validation and copyleft risk detection
  • Compliance checks for EU CRA, NIST SSDF FOSS and ISO 27001
  • SBOM aggregation for microservices and multi-repo projects
Imprint

nsakldnalksd mlasödalsdmklasmdlasm lakms ksadm klam klasm kldmaslkd m
Contact Vallanx

Which use case do you want to implement?

Talk to us. We are happy to answer your initial questions about Cyber Security & Compliance for your company!