C2A Security Acquires U.S. SBOM Specialist Vigilant Ops

7 October, 2025

The acquisition will integrate Vigilant Ops’ SBOM management technology into C2A’s Contextual AI platform, strengthening its capabilities in software security and regulatory compliance

[Pictured Above: Roy Fridman, C2A Security CEO]

Jerusalem-based cybersecurity company C2A Security announced the acquisition of Vigilant Ops, a U.S. firm specializing in Software Bill of Materials (SBOM) management. The deal is designed to combine C2A’s Contextual AI technology—used to identify security risks based on a product’s operational context—with Vigilant Ops’ expertise in component tracking and regulatory compliance. Together, the two platforms will offer customers a unified infrastructure for managing software security, transparency, and compliance. The purchase price was not disclosed.

Founded in 2019 in Pittsburgh, Pennsylvania by Ken Zawalsky, Vigilant Ops has become a recognized name in SBOM management—an increasingly vital field in an era when most software products rely on hundreds or even thousands of open-source and third-party components. Its platform enables organizations to automatically generate and maintain detailed component inventories, detect vulnerabilities, track dependencies, and securely share data with regulators and suppliers.

Despite raising less than $5 million in funding over six years and employing only 15–20 people, Vigilant Ops has built a strong foothold in the medical device and healthcare industries, offering tools that help manufacturers meet FDA and EU MDR compliance standards. Its customers include Bayer and Ascensia, and it is widely regarded as one of the pioneers in transforming SBOM into a standard governance and compliance instrument.

Founded in 2016 by Michael Dick, C2A Security develops an AI-driven Product Security Platform tailored for highly regulated sectors. At its core lies Contextual AI, a risk-assessment engine that evaluates vulnerabilities not just by their technical severity but by their real-world impact on the product’s operation. Rather than producing static lists of weaknesses, the system analyzes each software component according to its role, dependencies, runtime conditions, and potential safety implications—allowing customers to prioritize fixes based on operational significance. Its client list includes BMW Group, Daimler Truck AG, Siemens, and NVIDIA.

By integrating Vigilant Ops’ SBOM data—component inventories, version histories, VEX (Vulnerability Exploitability eXchange) declarations, and supply chain metadata—C2A’s Contextual AI engine will be able to correlate software component details with real-time threat intelligence. This allows the system to distinguish between theoretical and exploitable vulnerabilities, automate compliance evidence, and deliver precise remediation priorities.

In industries such as medical devices, this capability can dramatically reduce regulatory response times, maintain patient safety, and enable faster product release cycles. Strategically, the deal positions C2A as a leader in the shift from list-based security to context-driven security—a more intelligent approach that unifies visibility, compliance, and response into one adaptive platform.

“C2A Security is expanding globally to serve industries such as MedTech and defense at a time when cyber threats are escalating and regulations are tightening,” said Roi Friedman, CEO of C2A Security. “Integrating Vigilant Ops’ technology will enable us to give developers the tools, expertise, and partnerships they need to build secure, compliant products at scale—while demonstrating the scalability of our product security platform across diverse industries.”

Share via Whatsapp

Posted in: AI , Cyber , News

Posted in tags: C2A Security , SBOM , Vigilant Ops