Source: ONEKEY GmbH
UPDATED – The Düsseldorf-based firmware security specialist will focus on compliance with the Cyber Resilience Act (CRA) at it-sa in Hall 9 (Booth 9-346)
Düsseldorf/Nuremberg, September 29, 2026 — Since September 11, manufacturers of connected devices, machines, and systems have been required to actively report vulnerabilities and serious security incidents in accordance with the Cyber Resilience Act (CRA). At the same time, pressure is mounting to comply with all CRA obligations, which will take effect on December 11 of next year. From that date on, products with digital elements may only be placed on the European Union market if they meet the essential cybersecurity requirements of the EU Regulation. This means that vulnerabilities must be addressed throughout the support period, software components must be documented, and a conformity assessment must be available.
To meet the growing demand for CRA compliance, the Düsseldorf-based cybersecurity company ONEKEY will present its “CRA Fast Start” program at it-sa 2026 (October 27-29) at booth 9-346. The program allows manufacturers to assess their products against CRA requirements in a structured manner and get started without lengthy lead times. It is estimated that the Cyber Resilience Act affects hundreds of millions, if not billions, of digital products in the EU.
The “CRA Fast Start” program is based on the following pillars: CRA Readiness Assessment; creation of software bills of materials (SBOMs) to establish a solid foundation for ongoing CRA compliance; systematic vulnerability management; and continuous monitoring. The program is suitable for companies at various stages of readiness. For manufacturers in the early stages of addressing CRA requirements, the assessment serves as a guide. Those who already understand the extent to which they are affected by the CRA and require rapid implementation can begin directly with vulnerability management and continuous monitoring. Additionally, a compliance check and a wizard assist with the initial CRA compliance review. The wizard is continuously updated to reflect future regulatory requirements and anticipated harmonized standards.
“With CRA Fast Start, we provide manufacturers with a systematic and rapidly deployable approach to meeting the CRA’s legal requirements,” explained Jan Wendenburg, ONEKEY’s CEO.
Get Started with the CRA Readiness Assessment
An initial, structured CRA Readiness Assessment is a core component of the program. This assessment analyzes a company’s level of readiness for the CRA requirements. In addition to product requirements, the assessment examines existing processes for addressing vulnerabilities, SBOM documentation and organizational responsibilities, among other things. Based on the results, compliance gaps can be identified and priority actions defined. ONEKEY particularly recommends this assessment to companies that are unsure how the CRA applies to them and which steps they need to take.
Continuous Monitoring for Potential Vulnerabilities
The next step applies to all companies, including those that have already started preparing for CRA compliance. Ongoing vulnerability management and continuous monitoring help identify existing gaps. SBOMs ensure transparency throughout the software supply chain. New vulnerabilities, affected libraries, and security-related changes are continuously tracked, ensuring ongoing transparency regarding the security status of digital products. The ONEKEY Product Cybersecurity & Compliance Platform is used for this purpose.
Launching a Long-Term Security Strategy
“Our platform, combined with the CRA Readiness Assessment, unites our expertise in consulting with the extensive analytical capabilities of the ONEKEY platform. This enables us to take immediate action while simultaneously paving the way for a long-term strategy to ensure compliance,” Jan Wendenburg said. He also clarified: “Ultimately, for manufacturers, this is about more than meeting mandatory legal requirements. They also need to effectively protect their product portfolios against cyberattacks. Any vulnerability that is successfully exploited can create both legal and reputational risks.”
ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.
Critical vulnerabilities and compliance violations in device firmware are automatically identified in binary code by AI-based technology in minutes – without source code, device, or network access. Proactively audit software supply chains with integrated Software Bills of Materials (SBOMs) generation. “Digital Cyber Twins” enable automated 24/7 post-release cybersecurity monitoring throughout the product lifecycle.
The integrated ONEKEY Compliance Wizard already supports compliance with requirements from IEC 62443-4-2, ETSI EN 303 645, UNECE R155, and many other standards and regulations.
As part of the EU-funded CRACoWi (Cyber Resilience Act Compliance Wizard) project, ONEKEY is collaborating with 13 European partners to develop an AI-powered assistant for the automated implementation of the EU Cyber Resilience Act (CRA).
The solution will guide companies through the entire compliance process–from the initial CRA scope assessment to the generation of the required Declaration of Conformity.
The Product Security Incident Response Team (PSIRT) is effectively supported by the integrated automatic prioritization of vulnerabilities, significantly reducing the time to remediation.
Leading international companies in Asia, Europe and the Americas already benefit from the ONEKEY Product Cybersecurity & Compliance Platform (OCP) and ONEKEY Cybersecurity Experts.
