Developer docs
API playgroundTry for free, no card

Search company profiles

ONEKEY

Full company profile

uuid0007krk

Namestring
ONEKEY
Legal namestring
ONEKEY GmbH
Websiteurl
onekey.com
Company typeenum
Private
Founded yearint
2020
Descriptiontext

ONEKEY GmbH is a Düsseldorf-based product cybersecurity and compliance company founded in 2020 that builds an automated platform for manufacturers and operators of connected IoT/OT devices. Its core technology performs binary firmware analysis without requiring source code or network access, automatically generating Software Bill of Materials (SBOM), identifying known and unknown vulnerabilities (including zero-days), and producing impact assessments covering certificates, attack vectors, exploitability, and dependencies. The platform's patent-pending ONEKEY Compliance Wizard integrates vulnerability detection with regulatory navigation for the EU Cyber Resilience Act, IEC 62443, and ETSI 303 645, and a digital-twin-based continuous monitoring module cross-references device components against global vulnerability databases for real-time alerting. The product is complemented by expert consulting services including penetration testing, CRA Readiness Assessment, and RED Readiness Assessment. ONEKEY monetizes through quote-based annual SaaS subscriptions plus professional services, sold via an enterprise field sales motion that leverages a "Book a Demo" funnel. Its customer base spans automotive (ETAS), medical technology (Richard Wolf, Wiedemann), industrial automation (Kistler, MURR, r.stahl), telecom (Swisscom), IT services (ATOS, Kudelski IoT), and consumer electronics (Snap One, Trimble). The company is privately held, ISO/IEC 27001:2022 certified, and counts PwC Germany as a minority investor since December 2023.

Short descriptiontext

ONEKEY is a Düsseldorf-based product cybersecurity and compliance platform that automates binary firmware analysis, SBOM generation, vulnerability detection, and EU Cyber Resilience Act compliance for manufacturers of connected IoT/OT devices across automotive, medical, industrial, telecom, and consumer-electronics verticals.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
11–50
akta.pro rankint
HeadquartersDüsseldorf, Germany
HQ citystring
Düsseldorf
HQ countrystring
Germany
HQ regionstring
Europe
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
product cybersecurity platform, firmware vulnerability analysis, SBOM management software, IoT compliance management, binary firmware analysis
Industry2 codes
1Endpoint Security for End Users (EDR/XDR, Patch/Vuln, Zero Trust Endpoint)
CodeBPAEAIAGPrimaryYes
2App Security, Compliance & Review Automation Platforms
CodeBPAMADAJPrimaryNo
NAICS code3 codes
  • Other Computer Related Services541519
  • Computer Systems Design and Related Services54151
  • Computer Systems Design Services541512
SIC code2 codes
  • Services-Prepackaged Software7372
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
IoT Product Cybersecurity Software
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model2 records
1ONEKEY Platform Subscription
TypeSubscription Recurring
Description

SaaS-based platform subscription providing access to automated product cybersecurity and compliance tools including SBOM management, vulnerability detection, and compliance wizard. Pricing is quote-based for enterprise customers.

onekey.com
2Expert Consulting Services
TypeProfessional Services
Description

Professional services including penetration testing, CRA Readiness Assessment, and RED Readiness Assessment delivered by cybersecurity and compliance experts.

onekey.com
Marketing channels9 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels3 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Technology or R&D, Personnel, Marketing or Sales, Operations
Pricing details1 tier
1Enterprise platform subscription with quote-based pricing
ModelSubscriptionBilling cadenceAnnual
Notes

No public pricing available; sales team engages through demo booking process. Platform access includes SBOM management, vulnerability detection, compliance wizard, and monitoring capabilities.

onekey.com
GTM typeB2B
B2B
Offering typeSoftware
Software
Core offering1 text field

ONEKEY provides an automated product cybersecurity and compliance platform for manufacturers and operators of IoT/OT connected devices. The platform performs binary firmware analysis without requiring source code or network access, generating Software Bills of Materials (SBOM), detecting known and zero-day vulnerabilities, and providing a patent-pending Compliance Wizard that maps findings to regulations such as the EU Cyber Resilience Act, IEC 62443, and ETSI 303 645. ONEKEY complements the platform with expert consulting services including penetration testing, CRA Readiness Assessment, and RED Readiness Assessment.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • 40% faster SBOM generation
+3 more records
Product overview1 text field

ONEKEY offers a unified platform architecture centered on the ONEKEY Platform, an all-in-one product cybersecurity and compliance solution. The platform integrates multiple functional modules including SBOM Management, Vulnerability Management, ONEKEY Compliance Wizard (patent-pending), Automated Impact Assessment, Zero-Day Detection, Monitoring, License Detection, and Custom Analysis Profiles. These modules work together to provide end-to-end coverage from firmware analysis through compliance documentation. The company also offers consulting services including Penetration Testing, CRA Readiness Assessment, and RED Readiness Assessment to complement the automated platform capabilities. The CRA Fast Start program provides a structured entry point for manufacturers preparing for EU Cyber Resilience Act compliance. The ONEKEY Research Lab supports the platform through continuous security research and vulnerability pattern discovery.

Product and service5 records
1ONEKEY Platform
CategoryCybersecurity SaaS Platform
Description

All-in-one SaaS platform that automates product cybersecurity and compliance for manufacturers of connected IoT/OT devices, including SBOM generation, vulnerability management, compliance guidance, and continuous firmware monitoring.

2CRA Fast Start
CategoryCompliance Readiness Program
Description

Structured program helping manufacturers prepare for EU Cyber Resilience Act compliance through three pillars: CRA Readiness Assessment, systematic vulnerability management, and continuous monitoring.

3CRA Readiness Assessment
CategoryCompliance Consulting Service
Description

Expert consulting engagement providing gap analysis and an actionable roadmap for EU Cyber Resilience Act compliance, including introductory workshop, process review, and documentation assessment.

4RED Readiness Assessment
CategoryCompliance Consulting Service
Description

Expert consulting service for assessing manufacturer readiness against Radio Equipment Directive (RED) security requirements.

5Penetration Testing
CategorySecurity Consulting Service
Description

Manual security testing service delivered by ONEKEY's cybersecurity specialists, complementing the automated platform analysis.

Scale indicator4 records

Each record includes

Type, Value, Description, Source

Partnership1 partner
1EU-funded CRACoWi Project Partners
Strategic tierCoreTypeStrategic or Co-development Partner
Description

ONEKEY collaborates with 13 European partners on the EU-funded CRACoWi project to develop AI-assisted tools for Cyber Resilience Act compliance. This EU-supported initiative focuses on creating automated tools to help manufacturers meet CRA requirements using AI capabilities.

finanznachrichten.de
Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Nozomi Networks delivers OT and IoT visibility, vulnerability detection, and compliance monitoring for industrial control systems. It competes with OneKEY in securing connected operational devices across manufacturing, energy, and critical infrastructure verticals.

TypeDirect peer
Description

Sonatype provides software supply chain security, including SBOM management, dependency analysis, and vulnerability intelligence. It is a direct peer to OneKEY's SBOM and software supply chain security modules for connected-device manufacturers.

TypeDirect peer
Description

Claroty provides cybersecurity for operational technology and industrial IoT environments, including asset discovery, vulnerability management, and threat detection. It is directly comparable to OneKEY in targeting OT/connected-device cybersecurity for industrial, healthcare, and critical infrastructure operators.

TypeEmerging player
Description

Sternum provides runtime security and observability for embedded/IoT devices, complementing build-time analysis. It overlaps with OneKEY on connected-device security but emphasizes runtime protection rather than SBOM/compliance automation.

TypeDirect peer
Description

Cybellum offers product security and SBOM management for automotive and connected devices, including binary-level analysis and vulnerability management. It is a direct peer in the automotive/industrial product cybersecurity space that ONEKEY addresses.

TypeDirect peer
Description

Forescout offers device visibility and security for IT, IoT, and OT environments, including continuous monitoring and compliance reporting. It overlaps with OneKEY's connected-device monitoring and vulnerability management capabilities.

TypeBroad incumbent
Description

Tenable is an established vulnerability management and exposure platform (Nessus, Tenable.io) that has expanded into OT/IoT and SBOM offerings. It represents a broad incumbent alternative to OneKEY for vulnerability and compliance workflows.

TypeEmerging player
Description

RunSafe Security focuses on firmware and embedded system protection, including vulnerability mitigation and software supply chain hardening. It is an adjacent peer working on connected-device security for industrial and critical infrastructure customers.

TypeDirect peer
Description

Mend offers open source security, license compliance, and SBOM management for enterprise software development. It competes with OneKEY on SBOM generation and license detection for manufacturers developing connected products.

TypeDirect peer
Description

Finite State focuses on firmware and embedded device security, including automated binary analysis, SBOM generation, and vulnerability detection for connected products. It is one of the closest direct competitors to OneKEY's binary firmware analysis approach.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers12 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment6 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile1 record

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

AI capability3 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature8 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles2 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance1 record

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds1 record

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors1 record

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

ONEKEY

IoT Product Cybersecurity Softwareonekey.com

ONEKEY is a Düsseldorf-based product cybersecurity and compliance platform that automates binary firmware analysis, SBOM generation, vulnerability detection, and EU Cyber Resilience Act compliance for manufacturers of connected IoT/OT devices across automotive, medical, industrial, telecom, and consumer-electronics verticals.

What ONEKEY does

ONEKEY GmbH is a Düsseldorf-based product cybersecurity and compliance company founded in 2020 that builds an automated platform for manufacturers and operators of connected IoT/OT devices. Its core technology performs binary firmware analysis without requiring source code or network access, automatically generating Software Bill of Materials (SBOM), identifying known and unknown vulnerabilities (including zero-days), and producing impact assessments covering certificates, attack vectors, exploitability, and dependencies. The platform's patent-pending ONEKEY Compliance Wizard integrates vulnerability detection with regulatory navigation for the EU Cyber Resilience Act, IEC 62443, and ETSI 303 645, and a digital-twin-based continuous monitoring module cross-references device components against global vulnerability databases for real-time alerting. The product is complemented by expert consulting services including penetration testing, CRA Readiness Assessment, and RED Readiness Assessment. ONEKEY monetizes through quote-based annual SaaS subscriptions plus professional services, sold via an enterprise field sales motion that leverages a "Book a Demo" funnel. Its customer base spans automotive (ETAS), medical technology (Richard Wolf, Wiedemann), industrial automation (Kistler, MURR, r.stahl), telecom (Swisscom), IT services (ATOS, Kudelski IoT), and consumer electronics (Snap One, Trimble). The company is privately held, ISO/IEC 27001:2022 certified, and counts PwC Germany as a minority investor since December 2023.

ONEKEY firmographics

Firmographics
Name
ONEKEY
Legal name
ONEKEY GmbH
Website
https://onekey.com
Company type
Private
Founded year
2020
Operating status
Operating
Headcount range
11–50 employees
Short description
ONEKEY is a Düsseldorf-based product cybersecurity and compliance platform that automates binary firmware analysis, SBOM generation, vulnerability detection, and EU Cyber Resilience Act compliance for manufacturers of connected IoT/OT devices across automotive, medical, industrial, telecom, and consumer-electronics verticals.
Ownership category
akta.pro rank

ONEKEY industry classification

Industry
Product category
IoT Product Cybersecurity Software
NAICS
Other Computer Related Services (541519), Computer Systems Design and Related Services (54151), Computer Systems Design Services (541512)
SIC
Services-Prepackaged Software (7372), Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
Endpoint Security for End Users (EDR/XDR, Patch/Vuln, Zero Trust Endpoint) (BPAEAIAG)
akta.pro secondary industry
App Security, Compliance & Review Automation Platforms (BPAMADAJ)

Keywords

  • Product cybersecurity platform
  • Firmware vulnerability analysis
  • SBOM management software
  • IoT compliance management
  • Binary firmware analysis

Where ONEKEY is headquartered

Location

Headquarters

HQ city
Düsseldorf
HQ country
Germany
HQ region
Europe

Offices1 record

Markets served

ONEKEY business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Technology or R&D, Personnel, Marketing or Sales, Operations

Revenue model

  1. ONEKEY Platform Subscription: SaaS-based platform subscription providing access to automated product cybersecurity and compliance tools including SBOM management, vulnerability detection, and compliance wizard. Pricing is quote-based for enterprise customers.
  2. Expert Consulting Services: Professional services including penetration testing, CRA Readiness Assessment, and RED Readiness Assessment delivered by cybersecurity and compliance experts.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualEnterprise platform subscription with quote-based pricing

Go-to-market motion1 record

Distribution channels3 records

Marketing channels9 records

ONEKEY product offering

Product offering

Core offering

ONEKEY provides an automated product cybersecurity and compliance platform for manufacturers and operators of IoT/OT connected devices. The platform performs binary firmware analysis without requiring source code or network access, generating Software Bills of Materials (SBOM), detecting known and zero-day vulnerabilities, and providing a patent-pending Compliance Wizard that maps findings to regulations such as the EU Cyber Resilience Act, IEC 62443, and ETSI 303 645. ONEKEY complements the platform with expert consulting services including penetration testing, CRA Readiness Assessment, and RED Readiness Assessment.

Product overview

ONEKEY offers a unified platform architecture centered on the ONEKEY Platform, an all-in-one product cybersecurity and compliance solution. The platform integrates multiple functional modules including SBOM Management, Vulnerability Management, ONEKEY Compliance Wizard (patent-pending), Automated Impact Assessment, Zero-Day Detection, Monitoring, License Detection, and Custom Analysis Profiles. These modules work together to provide end-to-end coverage from firmware analysis through compliance documentation. The company also offers consulting services including Penetration Testing, CRA Readiness Assessment, and RED Readiness Assessment to complement the automated platform capabilities. The CRA Fast Start program provides a structured entry point for manufacturers preparing for EU Cyber Resilience Act compliance. The ONEKEY Research Lab supports the platform through continuous security research and vulnerability pattern discovery.

Differentiator

Problem solved

Functional benefit

Products and services

  • ONEKEY Platform All-in-one SaaS platform that automates product cybersecurity and compliance for manufacturers of connected IoT/OT devices, including SBOM generation, vulnerability management, compliance guidance, and continuous firmware monitoring.
  • CRA Fast Start Structured program helping manufacturers prepare for EU Cyber Resilience Act compliance through three pillars: CRA Readiness Assessment, systematic vulnerability management, and continuous monitoring.
  • CRA Readiness Assessment Expert consulting engagement providing gap analysis and an actionable roadmap for EU Cyber Resilience Act compliance, including introductory workshop, process review, and documentation assessment.
  • RED Readiness Assessment Expert consulting service for assessing manufacturer readiness against Radio Equipment Directive (RED) security requirements.
  • Penetration Testing Manual security testing service delivered by ONEKEY's cybersecurity specialists, complementing the automated platform analysis.

Quantifiable outcome

  • 40% faster SBOM generation
  • +3 more outcomes

Companies that use ONEKEY

Customer profile

Named customers12 records

Segments6 records

Ideal customer profiles1 record

ONEKEY technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

AI capability3 records

Feature8 records

ONEKEY partnerships and signals

Strategic signal

Partnerships

One partnership is on record.

  • EU-funded CRACoWi Project PartnerscoreStrategic or Co-development PartnerONEKEY collaborates with 13 European partners on the EU-funded CRACoWi project to develop AI-assisted tools for Cyber Resilience Act compliance. This EU-supported initiative focuses on creating automated tools to help manufacturers meet CRA requirements using AI capabilities.

Scale indicators4 records

Recent moves6 records

Expansion highlights6 records

ONEKEY competitors and assessment

Company assessment

Direct peers

  • Nozomi Networks: Nozomi Networks delivers OT and IoT visibility, vulnerability detection, and compliance monitoring for industrial control systems. It competes with OneKEY in securing connected operational devices across manufacturing, energy, and critical infrastructure verticals.
  • Sonatype: Sonatype provides software supply chain security, including SBOM management, dependency analysis, and vulnerability intelligence. It is a direct peer to OneKEY's SBOM and software supply chain security modules for connected-device manufacturers.
  • Claroty: Claroty provides cybersecurity for operational technology and industrial IoT environments, including asset discovery, vulnerability management, and threat detection. It is directly comparable to OneKEY in targeting OT/connected-device cybersecurity for industrial, healthcare, and critical infrastructure operators.
  • Cybellum: Cybellum offers product security and SBOM management for automotive and connected devices, including binary-level analysis and vulnerability management. It is a direct peer in the automotive/industrial product cybersecurity space that ONEKEY addresses.
  • Forescout: Forescout offers device visibility and security for IT, IoT, and OT environments, including continuous monitoring and compliance reporting. It overlaps with OneKEY's connected-device monitoring and vulnerability management capabilities.
  • Mend (formerly WhiteSource): Mend offers open source security, license compliance, and SBOM management for enterprise software development. It competes with OneKEY on SBOM generation and license detection for manufacturers developing connected products.
  • Finite State: Finite State focuses on firmware and embedded device security, including automated binary analysis, SBOM generation, and vulnerability detection for connected products. It is one of the closest direct competitors to OneKEY's binary firmware analysis approach.

Emerging players

  • Sternum: Sternum provides runtime security and observability for embedded/IoT devices, complementing build-time analysis. It overlaps with OneKEY on connected-device security but emphasizes runtime protection rather than SBOM/compliance automation.
  • RunSafe Security: RunSafe Security focuses on firmware and embedded system protection, including vulnerability mitigation and software supply chain hardening. It is an adjacent peer working on connected-device security for industrial and critical infrastructure customers.

Broad incumbents

  • Tenable: Tenable is an established vulnerability management and exposure platform (Nessus, Tenable.io) that has expanded into OT/IoT and SBOM offerings. It represents a broad incumbent alternative to OneKEY for vulnerability and compliance workflows.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks6 records

Key highlights7 records

Customer concentration

ONEKEY social profiles

Digital presence

ONEKEY compliance and trust

Trust signal

Compliance1 record

ONEKEY financial estimates

Financial estimate

Revenue estimate

Valuation estimate

ONEKEY leadership team

Management profile

Number of profiles

Profiles2 records

ONEKEY funding detail

Funding detail

Funding overview

Funding rounds1 record

Investors1 record

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

ONEKEY M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about ONEKEY

What does ONEKEY do?

ONEKEY provides an automated product cybersecurity and compliance platform for manufacturers and operators of IoT/OT connected devices. The platform performs binary firmware analysis without requiring source code or network access, generating Software Bills of Materials (SBOM), detecting known and zero-day vulnerabilities, and providing a patent-pending Compliance Wizard that maps findings to regulations such as the EU Cyber Resilience Act, IEC 62443, and ETSI 303 645. ONEKEY complements the platform with expert consulting services including penetration testing, CRA Readiness Assessment, and RED Readiness Assessment.

Is ONEKEY a public or private company?

ONEKEY is a private company. It is classified as corporate owned and is currently operating.

When was ONEKEY founded?

ONEKEY was founded in 2020. It employs 11 to 50 people.

Where is ONEKEY based?

ONEKEY is headquartered in Düsseldorf, Germany, in the Europe region.

How does ONEKEY make money?

Two revenue lines are on record. ONEKEY Platform Subscription is the primary driver. The others are expert Consulting Services.

Who are ONEKEY's main competitors?

Direct peers on record are Nozomi Networks, Sonatype, Claroty, Cybellum, Forescout, Mend (formerly WhiteSource) and Finite State. Emerging players are Sternum and RunSafe Security. Tenable is listed as a broad incumbent.

Does ONEKEY have an API?

No public API is recorded for ONEKEY.

What industry is ONEKEY in?

ONEKEY's product category is IoT Product Cybersecurity Software. Its primary akta.pro industry code is BPAEAIAG, Endpoint Security for End Users (EDR/XDR, Patch/Vuln, Zero Trust Endpoint), with a secondary code of BPAMADAJ, App Security, Compliance & Review Automation Platforms. Its NAICS code is 541519 and its SIC code is 7372.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
PresseportalONEKEY-Report: SBOM ist eine wichtige Grundlage für CRA-ComplianceONEKEY's survey of 200 German industrial firms found only 18% have created a full Software Bill of Materials (SBOM) for CRA compliance. The EU Cyber Resilience Act requires SBOMs, and new digital products must comply by December 11. The report highlights gaps in SBOM completeness and updates.FinanzNachrichten.deONEKEY setzt auf "Decision Intelligence" bei CybersicherheitONEKEY, a Düsseldorf-based product cybersecurity specialist, announced a strategic shift toward "Decision Intelligence" for product security, arguing that the industry must move beyond vulnerability analysis toward intelligent decision support. The company is developing ONEKEY VerityAI, an AI-powered assistant designed to help security professionals prioritize findings, understand complex technical contexts, and generate actionable recommendations. New EU regulations, particularly the Cyber Resilience Act, are driving demand for traceable, auditable security decision-making, which ONEKEY identifies as a key competitive differentiator.FinanzNachrichten.deKünstliche Intelligenz erfordert automatisierte Cybersicherheit für smarte ProdukteONEKEY, a Düsseldorf-based product cybersecurity specialist, published an analysis finding that AI systems are rapidly increasing the number of software vulnerabilities discovered, making automated evaluation tools essential for manufacturers of connected devices to assess relevance, derive measures, and demonstrably meet regulatory requirements such as the EU Cyber Resilience Act. The company advocates a combined approach using automated firmware analysis, vulnerability management, and AI-based support, claiming its platform can reduce efforts by over 60 percent while also building AI capabilities including machine learning components, chat functions, and an intelligent analysis assistant. ONEKEY is part of PricewaterhouseCoopers Germany's investment portfolio and collaborates with 13 European partners on the EU-funded CRACoWi project to develop AI-assisted tools for Cyber Resilience Act compliance.FinanzNachrichten.deONEKEY erhält ISO/IEC 27001-Zertifizierung und unterstreicht damit den Fokus auf CybersicherheitONEKEY, a European product cybersecurity specialist headquartered in Düsseldorf, has successfully obtained ISO/IEC 27001:2022 certification for its information security management system, covering its automated product cybersecurity and compliance platform as well as expert services including penetration testing. The certification validates the company's security practices for customers in regulated industries such as automotive, medical technology, and industrial automation at a time when regulatory requirements like the EU Cyber Resilience Act and NIS2 are increasing compliance demands. The company, which is part of PricewaterhouseCoopers Germany's investment portfolio, states the certification reinforces its commitment to meeting the highest international governance and information security standards.SecuritytodayNew Firmware Monitoring Tool Targets Cyber Resilience Act -- Security TodayONEKEY has launched a continuous firmware monitoring system utilizing digital twin technology to help manufacturers comply with the European Union's Cyber Resilience Act. The platform automatically creates Software Bill of Materials by mapping device components and cross-referencing them against global vulnerability databases, issuing alerts when new flaws affect connected products. The system also includes automated risk assessment tools to help Product Security Incident Response Teams prioritize remediation efforts across industrial control systems, medical devices, and automotive components.PresseportalONEKEY Launches “CRA Fast Start” to Help Manufacturers Prepare for EU Cyber Resilience ActONEKEY GmbH, a Düsseldorf-based product cybersecurity company, has launched the "CRA Fast Start" program to help manufacturers of networked devices, machines, and systems verify compliance with the EU Cyber Resilience Act. The program offers three pillars: CRA Readiness Assessment, systematic vulnerability management, and continuous monitoring, addressing the regulation's requirement that manufacturers identify, assess, and remedy vulnerabilities throughout product lifecycles. Starting in 2027, all affected products must meet full security requirements, with non-compliance penalties reaching up to €15 million or 2.5% of global annual turnover.DrjExpert Warns: Smart Connected Devices Must Comply With The EU’s New Cyber Resilience ActThe EU Cyber Resilience Act imposes mandatory cybersecurity compliance on manufacturers of smart connected devices, with violations potentially resulting in fines up to €15 million or 2.5% of global turnover. Jan Wendenburg, CEO of ONEKEY, warns that non-compliant products will be illegal to sell in the European Union and highlights the regulation's broad impact on international electronics suppliers.The PaypersPwC Germany invests in ONEKEYPwC Germany has made its first investment in the IoT cybersecurity firm ONEKEY, citing the rising importance of resilience against cyber attacks. ONEKEY plans to utilize the funding to accelerate product cybersecurity and compliance for manufacturers globally through its automated platform. The company's technology identifies vulnerabilities in embedded software and manages legal compliance requirements such as the EU Cyber Resilience Act.IT EuropaPwC acquires stake in key IoT security firmPwC Holdings Germany, alongside eCAPITAL, has acquired a minority stake in IoT security firm ONEKEY to finance its growth. The investment marks PwC's entry into the IoT cybersecurity sector as demand for resilience against rising cyber attacks increases. ONEKEY will utilize the funding to expand its platform's capabilities for manufacturers and automakers globally.