OTNOS SBOM 360

APIyesOSS—FREEyesDOCS4/5
OS7.3#6 of 22
outWeb—Windows—Mac—Linux—Android—iOS

Ranked in SBOM Management Software ·Free plan

About

OTNOS SBOM 360 helps OT manufacturers assess, monitor and report software products in response to the Cyber Resilience Act. It consumes CycloneDX and SPDX SBOMs and produces CycloneDX VEX, OpenVEX and SBOMs with embedded VEX. A read-only GitHub app maps repositories to products and updates SBOMs after default-branch pushes and nightly checks. Its locally queried vulnerability intelligence mirrors more than 400,000 advisories, synced daily, without sending component names outside the tenant. Findings show severity, EPSS, installed and fixed versions, CISA KEV status and EUVD identifiers. Teams can record VEX decisions, justifications, workarounds and history; the platform drafts all 39 ENISA Single Reporting Platform fields for Article 14 reporting. Configurable alerts cover new advisories, fixes, KEV listings and rising EPSS scores. Integrations include REST API, webhooks and MCP, among other sources. It is cloud-hosted, with application and database data in Germany and files and backups in EU regions. The Free plan is $0/forever; Professional and Enterprise are custom-priced.

Who it is for

It suits OT security, PSIRT and vulnerability-management teams, consultants and MSSPs working with software product security and CRA reporting. Teams can connect GitHub repositories and use APIs or webhooks as part of their workflow.

What is good

  • Consumes CycloneDX and SPDX SBOMs
  • Mirrors over 400,000 advisories daily
  • Locally queries component names within the tenant
  • Drafts all 39 Article 14 reporting fields
  • Free plan listed

What to know first

  • Free plan limits monitoring to 50 assets
  • Free plan allows one user
  • Free CSV imports are limited to two monthly

Verdict

SBOM 360 combines SBOM workflows, vulnerability context and CRA reporting for OT products. Its free tier has clear asset, user and import limits; larger plans have custom pricing.

Compared on SBOM management software

Free plan
Yesotnos.com
SBOM standard support
bothotnos.com
Deployment model
cloudotnos.com
Vulnerability analysis
Yesotnos.com
Policy enforcement
Yesotnos.com
SBOM exchange
Yesotnos.com
Release monitoring
Yesotnos.com

Facts

Purpose
SBOM 360 ingests, analyzes, assesses, monitors and reports software products for OT manufacturers responding to the Cyber Resilience Act.otnos.com · 1 Oct 2026
SBOM formats
The platform consumes CycloneDX and SPDX SBOMs and produces CycloneDX VEX, OpenVEX and SBOMs with embedded VEX.otnos.com · 1 Oct 2026
GitHub connector
A read-only GitHub app maps repositories to products and updates SBOMs on default-branch pushes and nightly checks.otnos.com · 1 Oct 2026
Vulnerability intelligence
OTNOS mirrors more than 400,000 advisories across ecosystems, synced daily and queried locally without sending component names outside the tenant.otnos.com · 1 Oct 2026
Risk analysis
Findings show EPSS beside severity, installed versions beside fixed versions, CISA KEV status and EUVD identifiers.otnos.com · 1 Oct 2026
VEX workflow
Users can mark findings affected, not affected, fixed or under investigation with justifications, workarounds and decision history.otnos.com · 1 Oct 2026
CRA reporting
OTNOS drafts all 39 ENISA Single Reporting Platform fields for 24-hour, 72-hour and final Article 14 reports.otnos.com · 1 Oct 2026
Monitoring alerts
Configurable triggers cover new affecting advisories, newly available fixes, KEV listings and rising EPSS scores, with deduplicated email digests.otnos.com · 1 Oct 2026
Integrations
Listed integrations and data sources include GitHub, OSV, GitHub Advisories, CISA KEV, FIRST EPSS, ENISA EUVD, endoflife.date, Microsoft Power Automate, webhooks, REST API and MCP for AI agents.otnos.com · 1 Oct 2026
Security hosting
Application and database data run in Germany, files and backups stay in EU regions, and data is encrypted in transit and at rest.otnos.com · 1 Oct 2026
Compliance posture
OTNOS is CSA STAR Level 1 listed, GDPR-aligned with a DPA available, and operates an ISO/IEC 27001:2022 ISMS while formal certification is planned.otnos.com · 1 Oct 2026
Audience
OTNOS says it works with OT security engineers, PSIRT and vulnerability-management teams, consultants and MSSPs across energy, manufacturing, water and building technology.otnos.com · 1 Oct 2026

Best OTNOS SBOM 360 alternatives

See all 20

Where it ranks on Inferse

Sources