Skip to content

ONEKEY

ONEKEY is a Germany-based product cybersecurity platform that automatically analyzes device firmware binaries for IoT, IIoT, and OT manufacturers to find vulnerabilities and prove regulatory compliance.

Visit Website ↗ + Add to Compare
68/100Incremental Innovator

Overview

ONEKEY (formerly IoT Inspector, founded in 2018 and rebranded in 2022) analyzes compiled firmware binaries — without needing source code — to find known and unknown vulnerabilities, hardcoded credentials, outdated third-party components, and insecure configurations in connected devices. This is effectively software composition analysis and binary security testing applied to embedded firmware, a category that traditional application security tools generally don’t reach because firmware images are compiled blobs rather than source repositories a SAST/SCA tool can scan directly.

The platform’s second major function is compliance automation: as regulations like the EU Cyber Resilience Act, UNR155 (automotive cybersecurity), IEC 62443 (industrial control systems), and the U.S. Cyber Trust Mark for IoT devices come into force, device manufacturers need a repeatable way to demonstrate their products meet baseline security requirements. ONEKEY maps its scan findings against these frameworks and continuously re-checks deployed firmware against newly disclosed CVEs, filtering out vulnerabilities that are not actually exploitable or relevant in the specific firmware context — a meaningful practical improvement over simple CVE-database matching, which tends to flood teams with irrelevant alerts.

ONEKEY has real institutional backing: it is part of PwC Germany’s investment portfolio and has raised roughly $11.9M from investors including eCAPITAL and Momenta Ventures, and industry analyst firm Omdia profiled it in an “On the Radar” report covering firmware security and compliance vendors. With around 54 employees and a Düsseldorf, Germany base, the company describes itself as the leading European specialist in this niche, a claim that is plausible given its regulatory-framework coverage and PwC relationship but is not independently ranked against competitors like Finite State or VDOO/Palo Alto’s IoT security line.

Innovation Matrix Assessment

Innovation Velocity 7/10

The platform has expanded from binary firmware vulnerability scanning into continuous monitoring, CVE relevance filtering to cut noise, and automated mapping against a growing list of regulatory frameworks (EN303645, IEC62443, NIST8259A, UNR155, the EU Cyber Resilience Act, and the U.S. Cyber Trust Mark), reflecting active and regulation-driven product development.

Operational Value 6/10

With roughly 54 employees, a Düsseldorf headquarters, and status as part of PwC Germany's investment portfolio, ONEKEY has meaningful institutional backing and operational credibility for a specialist vendor, though it remains mid-sized relative to larger application security platforms.

Market Momentum 7/10

The company's rebrand from IoT Inspector to ONEKEY alongside its PwC Germany investment and continued funding from eCAPITAL and Momenta Ventures, plus rapid alignment of its product with newly emerging regulations (Cyber Resilience Act, Cyber Trust Mark), indicates active growth tied to a favorable regulatory tailwind.

Category Disruption 7/10

Automated, source-code-free binary analysis of firmware is a meaningfully different approach from traditional SAST/SCA tools, which generally cannot analyze compiled embedded firmware directly, and its CVE-relevance filtering addresses a real pain point of alert fatigue in vulnerability management.

Real-World Efficacy 6/10

Independent analyst firm Omdia profiled ONEKEY in an 'On the Radar' report on firmware security and compliance, which is a legitimate third-party signal of credibility; however, no independently published detection-accuracy benchmark against a defined test set was found, so efficacy evidence beyond analyst coverage is limited.

Enduring Relevance 8/10

With the EU Cyber Resilience Act and similar IoT/OT security mandates coming into force globally, automated firmware compliance and vulnerability management is becoming a near-mandatory requirement for connected device manufacturers, making this category highly relevant and increasingly urgent.

Why CISOs Should Care

For CISOs or product security leads at IoT, IIoT, or OT device manufacturers, ONEKEY provides a way to scan shipped firmware for real vulnerabilities and automatically demonstrate compliance with an expanding set of regional cybersecurity regulations, rather than relying on manual audits.

What Makes It Different

Unlike source-code-dependent AppSec tools, ONEKEY analyzes compiled firmware binaries directly and pairs that with automated compliance mapping against frameworks like the EU Cyber Resilience Act, IEC 62443, and UNR155.

The Matrix Verdict

68/100 — INCREMENTAL INNOVATOR

A credible, well-capitalized specialist addressing a genuine and growing gap in embedded/firmware security and compliance, backed by PwC Germany and covered by independent analyst research; its detection efficacy claims would benefit from a published independent benchmark, but the regulatory-mapping capability alone is a strong practical differentiator.

Editorial Note: Claims vs. Verified Findings

The company's self-description as 'the leading European specialist' in product cybersecurity compliance is a vendor claim not independently benchmarked against competitors. Its PwC Germany investment, Omdia analyst coverage, funding total, and regulatory-framework support list are independently corroborated via press releases and the Omdia report.

Sources