ONEKEY vs TUV SUD

ONEKEY

ONEKEY operates the ONEKEY Product Cybersecurity & Compliance Platform, which performs automated firmware analysis, SBOM generation, vulnerability detection, and zero-day discovery. Its Compliance Wizard maps product evidence against the CRA and other frameworks, and its CRA Fast Start program structures readiness assessment, SBOM creation, vulnerability management, and continuous monitoring. ONEKEY (formerly IoT Inspector) is part of PwC Germany's investment portfolio.

Pros
  • Automated, platform-driven firmware/binary analysis rather than purely manual consulting
  • Purpose-built CRA Compliance Wizard covering multiple product-security regulations in one tool
  • Strong European product-security positioning, backed by PwC Germany investment
  • Continuous monitoring across the product lifecycle, not a one-time audit
Cons
  • Software/platform-led: provides tooling and evidence, not formal conformity assessment or CE certification (not a notified body)
  • No public pricing
  • Technical product analysis focus; legal/organizational process consulting lighter than at full TIC firms

Pricing: Custom (contact sales)

TUV SUD

TUV SUD is a global testing, inspection, and certification organization with a dedicated CRA practice in its product-testing and cybersecurity divisions. It helps manufacturers interpret CRA obligations, run gap assessments, set up vulnerability management and incident reporting, and obtain third-party assessment for higher-risk products. It also runs RED cybersecurity testing against the EN 18031 series.

Pros
  • Long-established, globally accredited certification body (25,000+ employees, 1,000+ locations)
  • Established Notified Body for RED cybersecurity under EN 18031 (a strong precedent for CRA conformity work)
  • Combines testing labs, certification, and structured training under one roof
  • Deep cross-sector regulatory experience across CE marking directives
Cons
  • Large enterprise TIC firm — engagements tend to be formal and process-heavy
  • No public pricing
  • Certification/assessment-led rather than hands-on engineering remediation

Pricing: Custom (contact sales)