101% more reported CVEs per day in 2026 than last year.

Comparison

PSIRT tools compared

A PSIRT tool has to answer one question fast: which of our products and versions contain this vulnerable component? The tools below answer it from different inputs: binary analysis of shipped firmware, SBOMs you collect, findings from other scanners, or a record of the build itself. Here is what each does, and where each one wins.

Updated

The short answer

  • Firmware from suppliers as binaries: ONEKEY, Finite State, NetRise or Cybellum. Binary analysis is the way to see inside code whose build you never run.
  • Automotive, medical or industrial devices with regulatory templates: Cybellum, with templates for FDA PMA, ISO 21434 and the EU CRA.
  • Medical devices and FDA submissions: Medcrypt, with Helm for SBOMs and vulnerabilities.
  • Many scanners into one queue, with a PSIRT advisory workflow: DefectDojo, open source with a Pro edition.
  • A system of record for SBOMs from many suppliers: Cybeats SBOM Studio.
  • Yocto or Buildroot images with curated CVE data: Timesys Vigiles.
  • Protection on the device as well: Exein.
  • A free, self-hosted place to monitor SBOMs: OWASP Dependency-Track.
  • Software you build in GitHub Actions: CRACI, which records the SBOM from each build, keeps every past build and monitors what shipped.

Who this page is for

You run or are building a product security function, and you are choosing the tooling behind it. If you are still defining the role, start with what a PSIRT does. We build CRACI, so weigh that in. Every claim about another product comes from its own site or documentation, checked in October 2026, and most vendors here have a longer CRACI vs X page.

What a PSIRT tool must do

The work follows the vulnerability management lifecycle, and a PSIRT needs support at each step:

  1. Know what ships. An SBOM per product version, including transitive dependencies and supplier components. Everything after this depends on it being complete.
  2. Notice new vulnerabilities. Continuous monitoring that matches new advisories against every released version, not only the next one.
  3. Find the affected products. Which products, versions and builds contain the component, and for how long they did.
  4. Triage and route. Decide what matters and send it to the team that owns the fix.
  5. Say what is not affected. VEX records which products a vulnerability affects and why the others are not.
  6. Take in reports and tell people. A channel for outside researchers, case tracking, and advisories, often as machine-readable CSAF.

No tool below covers all six equally. Most are strongest at the first two or three steps, and they differ most in where their inventory comes from.

How to choose

  • Do you build the software, or receive it? If much of the product arrives from chip vendors and suppliers as binaries, binary analysis is how you see inside it. If you build it yourself, the build is the most direct source of the inventory.
  • Is the product regulated? Medical devices, vehicles and industrial equipment come with submission formats and standards. Some tools ship templates for them; others leave that to your own process.
  • How many scanners do you already run? If findings arrive from many tools, an aggregator that deduplicates them may matter more than another source of findings.
  • Where do outside reports come in? Researcher submissions usually need their own channel (see below), whatever inventory tool you choose.
  • Must it be self-hosted? DefectDojo, Dependency-Track and Medcrypt Enterprise can run on your own infrastructure, and Cybellum can run in your own datacenter.

At a glance

Two tables: tools built around firmware and devices first, then vulnerability management and SBOM platforms. "Not stated" means the vendor pages we cite do not say either way. Report intake, case management and advisory publishing are covered in the text below rather than in the tables.

Firmware and devices

As of October 2026.
Capability CRACI Cybellum ONEKEY Finite State NetRise Exein Timesys Vigiles
SBOM from what the build fetched BitBake metadata
SBOM from the finished binary Cyber Digital Twins 50+ instruction sets Exein Analyzer Not stated
Imports supplier SBOMs Vendor SBOMs can be added SPDX, CycloneDX, CPE CSV SPDX and CycloneDX When no binary is available SPDX, CycloneDX, CSV
Continuous vulnerability monitoring Daily re-analysis Living SBOMs NVD, CISA KEV, threat data Not stated Daily scans
Triage Routed to owning teams AI triage assistant Not stated Jira and ServiceNow Not stated Decisions kept per release
VEX VEX/CSAF reports Not stated Not stated Not stated
Reachability or exploitability ranking EPSS Not stated CISA KEV highlighted
Findings beyond known CVEs Malware, coding weaknesses Zero-day analysis Not stated Secrets, keys, misconfigurations Not stated Not stated
Regulatory templates or mapping SBOMs in CycloneDX or SPDX, records via API; no report export FDA PMA, ISO 21434, CRA Compliance Wizard CRA control mapping CRA reporting outputs CRA evidence mapping Not stated
CRA notifications submitted for you Not stated Not stated Not stated Not stated Not stated Not stated
Runs your builds, with egress policy
CI beyond GitHub Actions GitLab CI and Jenkins GitLab, Jenkins, Bamboo Not stated Not stated Jenkins, GitLab CI
Pricing Pay per build minute, no monthly fee Not stated Not stated Not stated Not stated Not stated Not stated
  • Included
  • Partly
  • Not included
  • On the roadmap

Vulnerability management and SBOM platforms

Pricing as of October 2026.
Capability CRACI DefectDojo Medcrypt Helm Cybeats Dependency-Track
Produces the SBOM Recorded during the build Imports SBOMs Generation tool on request Via Marketplace vendors Analyzes uploads
Aggregates findings from other scanners 500+ supported tools Not stated Not stated Analyzes SBOMs
Imports supplier SBOMs Vendor SBOMs can be added CycloneDX and SPDX (Pro) CycloneDX or SPDX CycloneDX
Continuous vulnerability monitoring Advisory feeds matched to SBOMs (Pro)
Triage and ownership Routed to owning teams Cases, owners, SLAs, Jira Rescoring and remediation Across the portfolio
VEX Pro CycloneDX VEX, VDR CycloneDX VEX
Exploitability ranking CVSS, EPSS, KEV EPSS, KEV, exploit data RAVEN add-on Not stated
CRA notifications Submitted on your behalf Article 14 reporting interface (Pro) Not stated Not stated Not stated
Runs your builds, with egress policy
Self-hosted Customer-hosted runners, Enterprise Community; Pro optional Enterprise Not stated
Pricing Pay per build minute, no monthly fee Community free; Pro $100/mo plus $0.15 per finding MSI $35,000 per product line per year Not stated Free, Apache 2.0
  • Included
  • Partly
  • Not included
  • On the roadmap

CRACI

The CRACI homepage
craci.com

CRACI is a GitHub Actions runner. You change runs-on to craci, and while each job runs, a package-aware proxy records what it fetches, including packages restored from CI caches and dependencies no lockfile lists. The SBOM, in CycloneDX or SPDX, carries a completeness state per job and per cache. CRACI keeps every past build with its SBOM, so when an advisory lands you can see which builds contained the vulnerable dependency, direct or transitive, and for how long, within your retention period. Its inventory view shows exactly which software versions are deployed to which products, globally.

After the build, CRACI re-evaluates monitored SBOMs continuously, lets security teams triage findings and route each one to the team that owns the fix, and supports VEX. Policy gates can block a build that contains a specific CVE, and an egress policy limits what the build can reach. You can add vendor SBOMs, so bought-in components are monitored next to your own builds. For actively exploited vulnerabilities, CRACI submits the CRA notifications on your behalf. For Yocto, a side-by-side build of core-image-sato gave an SBOM with every component in Yocto's own SBOM plus 88 it missed. Pricing is build minutes only: $0.004 per 2 vCPU minute, metered per second, with no monthly fee and no per-SBOM charge. Best for: PSIRTs whose products are built in GitHub Actions. Watch out: it does not analyze binaries, so firmware you did not build needs a vendor SBOM or a binary analysis tool; it has no reachability analysis and no report export; and it supports GitHub Actions today, with GitLab CI and Jenkins on the roadmap. See CRACI for PSIRT teams.

Firmware and device platforms

Cybellum

The Cybellum homepage
cybellum.com

Cybellum is a product security platform for device makers in automotive, medical and industrial markets, majority owned by LG Electronics since 2021. Its Cyber Digital Twins are built from firmware binaries, and it merges them with source code and supplier SBOMs in SPDX, CycloneDX or CPE CSV. It monitors post-production versions, triages with an AI assistant, the VM CoPilot, offers "a workbench for creating and managing investigations" with tickets, and shares vulnerability status through VEX and CSAF reports. Regulatory templates cover FDA PMA, ISO 21434, the EU CRA and more than 50 standards. It runs in public clouds or your own datacenter. Best for: device makers who need binary analysis and regulatory evidence in one platform. Watch out: pricing is not published, and it works from artifacts rather than running your build. CRACI vs Cybellum and Cybellum alternatives

ONEKEY

The ONEKEY homepage
onekey.com

ONEKEY analyzes compiled firmware with "no source code or network access needed." It generates an SBOM from the binary, imports supplier SBOMs, looks for likely zero days such as hardcoded credentials, and re-analyzes firmware daily. Its Compliance Wizard walks teams through the CRA, IEC 62443-4-2, ETSI EN 303 645 and the Radio Equipment Directive. Best for: teams that integrate a lot of supplier firmware. Watch out: it works on the image after the build, so it does not record what the build fetched. CRACI vs ONEKEY and ONEKEY alternatives

Finite State

The Finite State homepage
finitestate.io

Finite State analyzes firmware, binaries, source code and supplier SBOMs, with support for more than 50 binary instruction set architectures, and brings them into one record of shipped software with post-market monitoring. It ranks findings by reachability and exploit intelligence, records VEX decisions, and maps controls to the CRA and FDA requirements. Best for: PSIRTs that need to prioritize a long list of findings across many suppliers. Watch out: it starts from artifacts, so controlling what your own build could reach is outside its scope. CRACI vs Finite State and Finite State alternatives

NetRise

The NetRise homepage
netrise.io

NetRise Turbine produces "a complete, binary-derived SBOM from the software itself," including statically linked and embedded code, for software you build, buy and run. It imports SPDX and CycloneDX SBOMs, continuously checks the NVD, CISA KEV and threat actor data, ranks findings by execution-path reachability, and reports secrets, keys and misconfigurations inside the artifact, and it connects to Jira and ServiceNow. Dragos announced on September 21, 2026 that it had acquired NetRise. Best for: operational technology and device fleets whose software comes from many vendors. Watch out: its pages do not describe VEX, case management or advisory publishing, and pricing is not published. CRACI vs NetRise and NetRise alternatives

Exein

The Exein homepage
exein.io

Exein works on the device as well as before release. Exein Runtime uses eBPF to monitor and block malicious behavior on embedded Linux, and the open-source meta-exein Yocto layer puts its Pulsar agent into your image. Exein Analyzer scans firmware, or your SBOM when the binary is not available, prioritizes with reachability scoring, and maps findings to CRA requirements. Best for: embedded Linux products that need protection in the field. Watch out: the Yocto layer changes what runs on the device; it does not run or record your build. CRACI vs Exein

Timesys Vigiles

The Timesys Vigiles homepage
lynx.com

Vigiles, now sold by Lynx Software Technologies, turns the metadata of a Yocto, Buildroot or OpenWrt build into an SBOM and matches it against a curated CVE database. Kernel and U-Boot configuration filters remove CVEs in features you do not build, triage decisions (affected, fixed, deferred, not exploitable) are kept per release, CISA KEV entries are highlighted, and it exports SBOMs, VEX and vulnerability reports. Best for: embedded Linux teams who want less CVE noise. Watch out: its SBOM reflects what BitBake's metadata says goes into the image, not everything the build fetched. CRACI vs Timesys Vigiles

Vulnerability management and SBOM platforms

DefectDojo

The DefectDojo homepage
defectdojo.com

DefectDojo is an OWASP Flagship project with a commercial Pro edition. The free Community Edition deduplicates findings from the scanners you already run, more than 500 supported tools by its own count, into one queue with owners, SLAs and Jira tickets. Pro adds SBOM import in CycloneDX and SPDX, CycloneDX VEX export, and a PSIRT Advisory Engine that takes in advisories from more than 20 feeds, matches them against SBOM data, groups them into cases with owners and publishes branded PDF advisories. Its September 2026 release added CSAF 2.0 and VEX advisory export and a CRA Article 14 reporting interface. Pro starts at $100 per month plus $0.15 per finding processed. Best for: PSIRTs that want an open-source base and an advisory workflow. Watch out: it does not generate SBOMs itself, so the inventory is only as complete as what you upload. CRACI vs DefectDojo and DefectDojo alternatives

Medcrypt

The Medcrypt homepage
medcrypt.com

Medcrypt helps medical device makers get their cybersecurity submission through FDA review, with a team that includes former FDA reviewers. Its Helm product imports CycloneDX or SPDX SBOMs by API, GitHub Action or Azure DevOps, monitors them continuously, ranks findings with EPSS, CISA KEV and exploit data, and exports CycloneDX VEX and VDR reports. MSI, which includes Helm, costs $35,000 per product line per year, and its MedISAO membership brings a coordinated vulnerability disclosure program. Best for: medical device makers preparing or maintaining FDA submissions. Watch out: it ingests SBOMs rather than producing them (a generation tool is available on request), and its pricing page says FDA is what the platform covers today. CRACI vs Medcrypt

Cybeats

The Cybeats homepage
cybeats.com

Cybeats SBOM Studio calls itself "the SBOM system of record." It stores SBOMs from your products and suppliers in SPDX 2.2 to 3.0.1 and CycloneDX 1.2 to 1.7, scores their quality before import, matches every component against vulnerability intelligence continuously, issues VEX, and shares SBOMs with customers, including over the Transparency Exchange API. Best for: product security teams in ICS, medical devices, telecom and automotive running an SBOM program across many suppliers. Watch out: for generation it points to vendors in its Marketplace, so the SBOM itself comes from another tool. CRACI vs Cybeats and Cybeats alternatives

The open-source option: Dependency-Track

The Dependency-Track homepage
dependencytrack.org

OWASP Dependency-Track is an Apache 2.0 platform that tracks components across every version of every application, pulls vulnerability data from sources including the NVD and GitHub Advisories, applies security, license and operational policies, and consumes and produces CycloneDX VEX. Pipelines upload SBOMs through its API. It is free, and you host and operate it yourself. Best for: teams that want a transparent, self-hosted analysis platform. Watch out: it does not generate SBOMs, so its results depend on the generator you run upstream. CRACI vs Dependency-Track and Dependency-Track alternatives

Report intake, cases and advisories

The tables above stop at triage and VEX. The rest of a PSIRT's work, taking in reports and telling people, is covered unevenly:

  • Reports from outside researchers. These usually arrive through a vulnerability disclosure program. Many companies run one on a platform such as HackerOne Response or Bugcrowd's VDP, which give researchers a channel to submit reports and help triage them. Others publish a policy and a security contact themselves. Our coordinated vulnerability disclosure guide covers the policy, security.txt and timelines.
  • Case management. Cybellum has a workbench for investigations with tickets. DefectDojo Pro groups matched advisories into cases with owners and SLA tracking. Neither says it hosts submissions from researchers.
  • Advisories. DefectDojo Pro publishes branded PDF advisories and exports CSAF 2.0. Cybellum shares vulnerability status through VEX and CSAF reports. Medcrypt's MedISAO membership includes a coordinated vulnerability disclosure program.

How CRACI fits

The first question in every PSIRT case is which products and versions contain the vulnerable component. Binary analysis answers it from what shipped, SBOM platforms from the SBOMs you give them, and aggregators from what other scanners report. CRACI answers it from a record of what your own builds actually fetched, kept for every past build. For software you build in GitHub Actions, that covers the inventory, the monitoring, triage and VEX in one product, so a separate SBOM manager such as Dependency-Track or Cybeats is not needed for those builds.

Other tools win elsewhere. Binary analysis from Cybellum, ONEKEY, Finite State or NetRise sees inside firmware you did not build. Cybellum and Medcrypt bring regulatory templates and submission expertise. DefectDojo aggregates findings from hundreds of scanners and publishes advisories. Finite State, NetRise and Exein rank findings by reachability, which CRACI does not offer. Read what a PSIRT does and CRACI for PSIRT teams, or compare CRA compliance tools and SBOM tools.

PSIRT tools: frequently asked questions

What is a PSIRT tool?

Software that helps a product security incident response team do its job: know which components ship in every product version, notice when a new vulnerability affects them, triage it, route the fix, record which products are not affected, and tell customers and authorities. Few products cover all of it. Most PSIRTs combine an inventory and monitoring tool with a channel for outside reports and a way to publish advisories.

Which PSIRT tool is best for firmware we receive as binaries?

A binary analysis tool. Cybellum, ONEKEY, Finite State and NetRise build an SBOM from the compiled firmware itself, so they can see inside supplier code whose build you never run. Exein Analyzer also scans firmware before release. CRACI does not analyze binaries; for supplier firmware it can monitor the vendor's SBOM if the vendor provides one.

Which PSIRT tool fits software we build ourselves?

If your builds run in GitHub Actions, CRACI records the SBOM from each build as it runs, keeps every past build with its SBOM, re-evaluates monitored SBOMs as advisories appear, and shows which builds contained a vulnerable dependency and which software versions are deployed to which products. GitLab CI and Jenkins are on its roadmap. For Yocto images, Timesys Vigiles builds an SBOM from BitBake metadata instead of recording the build.

Is there a free or open-source PSIRT tool?

Two of the tools here have free editions. DefectDojo Community Edition is free under the BSD 3-Clause license and deduplicates findings from hundreds of scanners into one queue; its PSIRT Advisory Engine, SBOM import and CSAF export are in DefectDojo Pro. OWASP Dependency-Track is free under Apache 2.0 and monitors the SBOMs you upload. You host and operate both yourself.

Do PSIRT tools take in reports from outside researchers?

Reports from researchers usually arrive through a vulnerability disclosure program, often run on a platform such as HackerOne or Bugcrowd, or through a published security contact. DefectDojo Pro takes in advisories from public feeds, and Cybellum offers a workbench for investigations, but neither says it hosts researcher submissions.

Which tools publish CSAF advisories?

DefectDojo Pro added CSAF 2.0 and VEX advisory export in September 2026 and publishes branded PDF advisories. Cybellum shares vulnerability status through VEX and CSAF reports. The other vendors on this page do not describe CSAF advisory publishing on the pages we cite.

Does the CRA require a PSIRT tool?

No tool is required. The Cyber Resilience Act asks manufacturers to handle vulnerabilities through the support period, keep a coordinated vulnerability disclosure policy and a contact for reports, and, since September 11, 2026, report actively exploited vulnerabilities within 24 hours, 72 hours and 14 days. CRACI submits those notifications on the manufacturer's behalf, and DefectDojo Pro has a CRA Article 14 reporting interface. The obligation stays with the manufacturer.

See your products' exposure from the build

Book a demo and we will run one of your GitHub Actions builds on CRACI and show which builds a known CVE reached.

Book a demo