PartsProof vs FOSSA
Both come up when a small maker searches for SBOM help. FOSSA scans code and generates an SBOM as one output of a broader license-and-vulnerability platform, billed monthly per project. PartsProof writes the disclosure policy, the SBOM and the 24-hour reporting runbook the CRA's reporting duties assume you already have, for a flat fee, once.
Last verified September 4, 2026
What each one actually is
FOSSA, read live on 4 September 2026, is a software composition analysis platform. Its Business tier is “$20 per project per month, billed annually”, for 10 projects with automated license and vulnerability scanning across the full dependency tree. An SBOM import is one line item among several; the platform is built to run continuously against a codebase, not to produce a one-time readiness pack for a reporting deadline.
PartsProof is a flat-fee pack: $79 for the Readiness Pack (a published disclosure policy, an SBOM for the product shipped, and the 24-hour incident reporting runbook with the deadlines written in), $149 for Readiness Plus, $299 for Readiness + Retainer. There is no scanning platform and no recurring seat. You publish and sign; PartsProof prepares.
| What you compare on | PartsProof | FOSSA |
|---|---|---|
| Price | $79 / $149 / $299, one-time | $20/project/month, billed annually (Business) |
| What it is | A CRA reporting-readiness document pack | A continuous dependency-scanning platform |
| SBOM | Prepared once for the product described | Generated on every scan, across the dependency tree |
| Disclosure policy | Prepared as part of the pack | Not a stated feature |
| 24-hour incident runbook | Prepared as part of the pack | Not a stated feature |
| Renewal | None. The pack is delivered and the files are yours | Monthly, per project, to keep scanning active |
Which one is the right buy
A team already running continuous dependency scanning, or one that wants ongoing license and vulnerability coverage as code ships, gets real value from FOSSA at a published per-project price. It generates an SBOM as part of that, but the reporting clock the Cyber Resilience Act starts on 11 September 2026 also requires a disclosure channel and a runbook with the actual deadlines in it, neither of which a scanning platform states as a deliverable.
PartsProof is for the maker who needs those three specific documents done once, sized to the reporting duty rather than to a recurring seat count. Who can actually prepare this documentation goes through the roles in full.
PartsProof is not a dependency-scanning platform and does not run continuous scans. The FOSSA figures above are what its own pricing page stated on 4 September 2026 and are linked so they can be checked directly; they change without notice.