ONEKEY Compliance Wizard

Reduce complexity, costs, and time for your product compliance

Discover the brand new, patent-pending ONEKEY Compliance Wizard feature in our platform. This interactive assistant guides you through the complex process of assessing your product security—with simple questions. For standards such as the upcoming EU Cyber Resilience Act (CRA), RED, IEC 62443-4-2, ETSI 303 645, and more.

ONEKEY Compliance Wizard

Simplify your compliance management

With our automated, constantly updated platform solution, you can easily meet the increasing cybersecurity requirements and standards.

All in One

Everything at a glance in a central interface

Let the ONEKEY Compliance Wizard guide you through all technical requirements and self-assessments for regulatory compliance. An easy-to-understand traffic light system provides clear compliance status and change tracking. Access product information, questionnaires, and requirements from a single dashboard. Get a comprehensive overview of ongoing compliance for all products and regulations.

Everything at a glance in a central interface
Flexibel

Automated, customizable documentation

Integrate product data automatically to ensure accuracy, and manually track or override checks as needed. Stay up to date with detailed audit trails and change logs. Easily view regulatory requirements and compliance levels at a glance. Analyze and document technical and organizational compliance in a dialog format. Customize requirements with editable panels and conditional questionnaires.

Automated, customizable documentation
self-audit

Generate detailed reports with just one click

Receive a detailed report describing the level of compliance and areas for improvement. Users can export all key information in a structured format for self-certification, external certification, and compliance documentation. ONEKEY also enables the streamlined export of comprehensive compliance packages and the creation of official statements of compliance for regulations such as CRA. Complete with a signature line.

Generate detailed reports with just one click

Comply with ease

Your new compliance cycle

With our advanced ONEKEY Compliance Wizard as part of our platform, you can continuously develop, comply, resist, and repeat.

Step 1

Upload your firmware to our platform to detect all security vulnerabilities and verify technical compliance within minutes, and select the security standard relevant to your product, e.g., the EU Cyber Resilience Act, RED, IEC62443-4-2, ISO/IEC 27400:2022, RED - Radio Equipment Directive, or another.

Step 2

Let the wizard guide you through technical and organizational questions according to your selected standard. Reduce the time and money you spend on compliance by using suggested solutions, automatic detection of security gaps, and comparison of compliance rules.

Step 3

Generate your individual self-declaration or export the results for third-party certification in seconds. For internationally recognized certification bodies such as Bureau Veritas, TÜV, DEKRA, FM Approved, and more.

Step 4

Repeat this process for each build. You don't need to re-enter all your information. Simply upload the new software version and the platform will detect the differences and highlight them for your review.

Step 5

Step 6

Experience the ONEKEY Compliance Wizard Feature in action

Discover the power of our patent-pending automatic assistant and evaluation in one platform.

onekey users

FAQs

Find answers to common questions about product cybersecurity, compliance, regulatory requirements, and security throughout the product lifecycle.

onekey users

How can ONEKEY’s Compliance Wizard help ensure compliance across your company?

The Compliance Wizard covers 15 guidelines, including the EU Cyber Resilience Act, IEC 62443-4-2, ETSI EN 303 645, EN 18031-1, NIST IR 8259A, the UK PSTI Act and UN Regulation No. 155. It walks provision by provision, proposes a verdict, and lets you apply it or override it with your own claim.

Does ONEKEY offer an all-in-one solution for all compliance needs?

One platform: firmware extraction, component detection, SBOM management, CVE matching, zero-day analysis, license detection, monitoring and compliance assessment against 15 guidelines. Compliance Overview visualizes status across several standards in a single diagram. Compliance topics without a product dimension – ISMS certification, data privacy – are deliberately out of scope.

How does ONEKEY’s Compliance Wizard help manage product compliance?

Provisions are colour-coded – red violated, green not violated, blue manual check, grey not applicable – and sorted by state into Not Filled, Up to Date, Outdated Same and Outdated Changed. When the firmware changes or a contributing CVE's status changes, affected provisions move to Outdated automatically, so what needs rechecking stays visible.

What is the ONEKEY Compliance Wizard?

The ONEKEY Compliance Wizard is a patent-pending assistant that checks firmware against cybersecurity guidelines like the CRA or IEC 62443-4-2. It goes through each requirement and suggests a verdict based on the analysis data. A colour-coded system shows gaps at a glance. The output is a report, a compliance bundle or a statement of compliance for self- or third-party certification.

How does the Compliance Wizard support Cyber Resilience Act (CRA) compliance?

The EU Cyber Resilience Act is one of the guidelines in the Compliance Wizard. Each CRA provision is checked against the firmware analysis. For “Violated” verdicts, supporting materials list the underlying CVEs and issues. Teams can upload their own evidence and override verdicts with a justification. One click generates an official CRA statement of compliance with a signature line.

One Solution, Many Benefits

Automated SBOM Generation from the Binary
SBOM Management

Automated SBOM Generation from the Binary

ONEKEY generates SBOM data directly from firmware binaries, identifying packages, versions, and dependencies even when supplier data is incomplete. This gives your team a reliable basis for release reviews, customer requests, and regulatory documentation.

CVE Prioritization Based on Your Actual Firmware – Not Generic Component Lists
Automated Impact Assessment

CVE Prioritization Based on Your Actual Firmware – Not Generic Component Lists

ONEKEY checks whether each CVE actually matters in your firmware and filters out findings that are irrelevant, mitigated, or not exploitable. This removes more than 60% of false positives, so your team focuses only on vulnerabilities with real product impact.

Binary-Level Vulnerability Detection
Vulnerability Management

Binary-Level Vulnerability Detection

ONEKEY analyzes the firmware binaries directly without source code, generating a detailed SBOM and uncovering vulnerabilities.

Get Started Fast

icon of a conversation
Step 1

Talk to an expert for an initial assessment.

icon of a laptop
Step 2

Benefit from a personalized demo with real data.

icon of a document
Step 3

Receive a quote with all your requirements to start.

Tanja Sommer onekey
Tanja Sommer
tanja.sommer@onekey.com

Discover how our solution
fits your needs