Article 14 reporting applies from 11 September 2026
Menu
Article 14 reporting applies from 11 September 2026

PartsProof vs FOSSA

Both come up when a small maker searches for SBOM help. FOSSA scans code and generates an SBOM as one output of a broader license-and-vulnerability platform, billed monthly per project. PartsProof writes the disclosure policy, the SBOM and the 24-hour reporting runbook the CRA's reporting duties assume you already have, for a flat fee, once.

Last verified September 4, 2026

What each one actually is

FOSSA, read live on 4 September 2026, is a software composition analysis platform. Its Business tier is “$20 per project per month, billed annually”, for 10 projects with automated license and vulnerability scanning across the full dependency tree. An SBOM import is one line item among several; the platform is built to run continuously against a codebase, not to produce a one-time readiness pack for a reporting deadline.

PartsProof is a flat-fee pack: $79 for the Readiness Pack (a published disclosure policy, an SBOM for the product shipped, and the 24-hour incident reporting runbook with the deadlines written in), $149 for Readiness Plus, $299 for Readiness + Retainer. There is no scanning platform and no recurring seat. You publish and sign; PartsProof prepares.

What you compare onPartsProofFOSSA
Price$79 / $149 / $299, one-time$20/project/month, billed annually (Business)
What it isA CRA reporting-readiness document packA continuous dependency-scanning platform
SBOMPrepared once for the product describedGenerated on every scan, across the dependency tree
Disclosure policyPrepared as part of the packNot a stated feature
24-hour incident runbookPrepared as part of the packNot a stated feature
RenewalNone. The pack is delivered and the files are yoursMonthly, per project, to keep scanning active

Which one is the right buy

A team already running continuous dependency scanning, or one that wants ongoing license and vulnerability coverage as code ships, gets real value from FOSSA at a published per-project price. It generates an SBOM as part of that, but the reporting clock the Cyber Resilience Act starts on 11 September 2026 also requires a disclosure channel and a runbook with the actual deadlines in it, neither of which a scanning platform states as a deliverable.

PartsProof is for the maker who needs those three specific documents done once, sized to the reporting duty rather than to a recurring seat count. Who can actually prepare this documentation goes through the roles in full.

PartsProof is not a dependency-scanning platform and does not run continuous scans. The FOSSA figures above are what its own pricing page stated on 4 September 2026 and are linked so they can be checked directly; they change without notice.