ONEKEY
Commercial · SBOM analysis
ONEKEY analyses device firmware to generate and validate SBOMs, then manages the vulnerabilities in them over the product's life. It is aimed squarely at manufacturers of connected devices, with compliance mapping to the Cyber Resilience Act, IEC 62443-4-2, ETSI EN 303 645 and UNECE R155. The company was previously IoT Inspector.
Key facts
| Vendor | ONEKEY |
|---|---|
| Licence | Commercial |
| Company founded | 2020 |
| Does | SBOM generation, SBOM validation, Firmware analysis, Vulnerability management, Compliance mapping |
| Reads | Firmware images |
| Formats | CycloneDX, SPDX |
| Website | www.onekey.com |
Sources
Checked 21 Sept 2026. Spotted something out of date? Tell us.
Other SBOM analysis tools
Need the product tested as well? See Cyber Resilience Act compliance testing providers.