Free · no signup · nothing stored

Generate an SBOM from your manifest. Signed.

Drop a dependency file, get a CycloneDX 1.6 and SPDX 2.3 software bill of materials plus an attestation signed with post-quantum ML-DSA-65 — the "ingredients label" the EU Cyber Resilience Act requires (Annex I Part II(1)). Lockfiles give you the full resolved tree; manifests give you direct dependencies.

Drop a file here or click to choose

package.json · package-lock.json · yarn.lock · requirements.txt · pyproject.toml · Pipfile.lock · go.mod · go.sum · Cargo.toml · Cargo.lock · pom.xml · Gemfile.lock · composer.json · composer.lock

or paste
Processed in memory, never stored. We count only which ecosystem was used.

Verify any CRA Label attestation, any time, with the public key at /cralabel-signing-key.pem or the verifier below. Format note: the EU has not yet fixed an official SBOM format (Art. 13(24)); both candidate formats are provided.

That's the label. The CRA also wants the rest of the file. Technical documentation (Annex VII), a documented vulnerability-handling process, a support-period statement, and a rehearsed 24-hour incident-report workflow (Art. 14 — binding since 11 Sept 2026). CRA Label generates all of it for small manufacturers, €490/year, first 50 companies onboarding now.

Get early access   See the clause-by-clause mapping →
Verify an attestation

Upload an attestation.json produced here (optionally also drop the matching cyclonedx.json / spdx.json to check their hashes).