New: the first SBOM scanner for machines.Take a look
Scanner

Scan the PLC project and get your SBOM

The first SBOM scanner for machines. It adapts to whatever you run. Point it at your project and get a CRA-ready bill of materials. B&R, Siemens, Rockwell and 40+ more vendors.

philipempl — -zsh
$ complioty scan ./APM2000
→ Project read: 128 files
✓ Vendor detected: B&R Automation Studio
plugin: br-automation-studio v2.4

Automatic vendor detection

Point at a project folder. The scanner figures out whether it's B&R, Siemens, Rockwell or another vendor on its own.

SiemensB&RRockwellBeckhoffABBSchneider ElectricMitsubishiBosch Rexroth+40 and more

40+ vendor plugins

From the major PLC market leaders to EU machine-building specialists. And if yours isn't there? We build the plugin for you.

philipempl — -zsh
$ complioty scan ./APM2000 --format cyclonedx,spdx
✓ sbom.cdx.json CycloneDX 1.5
✓ sbom.spdx.json SPDX 2.3

CycloneDX & SPDX

Standards-compliant SBOMs in CycloneDX 1.5 and SPDX 2.3, compatible with your existing toolchain.

philipempl — -zsh
✓ 42 components
! 3 flagged for review
CRA evidence complete

CRA-ready

Built for the EU Cyber Resilience Act. The generated bill of materials is the evidence you need.

philipempl — -zsh
$ complioty version
Complioty SBOM Scanner
v2026-07-28.1459-821aa3a3
no runtime dependencies
runs offline, no internet

Lean binary

No runtime dependencies, runs offline right on the engineering workstation, even with no internet on site.

philipempl — -zsh
$ complioty upload sbom.cdx.json
✓ Uploaded
CVE monitoring active

Straight into Complioty

The finished SBOM lands seamlessly in the Complioty platform. CVE monitoring takes over from there.

How it works

Three steps to your bill of materials.

01

Point it at your project

You tell the Scanner where your machine project lives. It runs right on the computer you code on.

02

It spots the vendor itself

B&R, Siemens, Rockwell or another one: the Scanner sees it in the project files. Nothing to configure.

03

Your bill of materials is ready

Every component with its version, as a CycloneDX or SPDX file. From now on each one is checked for new vulnerabilities.

supported by Observer

The difference

Count for a week.
Or just point at it.

By hand1 week

Open the project, walk through it component by component, dig out versions from libraries nobody remembers. And you still do not know whether the list is complete.

With Scanner30 seconds

One command on the project folder, no internet needed. 42 components listed cleanly, three flagged for review. Ready to export.

Cyber Resilience Act

December 11, 2027.

From then on, product security is a legal obligation. No evidence, no CE marking.

486
Days
:
11
Hrs
:
19
Min
:
36
Sec

One command. And you know what is inside.

Point the scanner at your project. The bill of materials follows.