A revolution in firmware monitoring through digital twins
The Cyber Resilience Act (CRA) presents manufacturers of digital products with new challenges: security risks must be monitored not only during development but continuously across the entire product lifecycle. The Düsseldorf-based cybersecurity company Onekey has developed an innovative digital twin technology for this purpose, monitoring firmware around the clock with automated scans.
This monitoring solution re-analyses firmware daily, ensuring continuous security throughout the entire lifecycle. When new vulnerabilities emerge, the constantly updated database and improved detection capabilities issue warnings about significant developments that could compromise product security.
Firmware as a critical attack surface in modern systems
Firmware forms the fundamental software layer of many technical systems - from industrial controllers and IoT devices through to medical systems and vehicle components. Security flaws at this level are particularly critical, as they provide direct access to hardware functions and are often difficult to correct after the fact.
Modern devices contain a wide range of external software libraries, open source components and proprietary modules. Each of these components can introduce new security risks, for example when new vulnerabilities are discovered after a product has been released.
As Jan Wendenburg, CEO of Onekey, explains: "Only when manufacturers know at all times which software components are contained in their products, and which new vulnerabilities are emerging, can they react quickly and protect their systems effectively."
From one-off testing to continuous monitoring
Under modern firmware monitoring approaches, a product's firmware is not analysed just once but monitored on an ongoing basis. The aim is to automatically detect newly emerging security flaws in the software components used and to assess their impact on existing products.
The process is divided into several steps:
- Detailed analysis of the firmware to identify all software components it contains
- Creation of a structured software bill of materials (SBOM)
- Transparent presentation of dependencies within the software supply chain
- Continuous matching of the SBOM against global vulnerability databases
Digital twins enable virtual security analyses
Digital twins are an innovative method of implementing this approach. A virtual representation of the firmware is created that makes it possible to carry out security analyses independently of the physical hardware. These digital models can be monitored permanently and provide a continuous overview of a product's current security status.
Manufacturers thereby gain a central information base for identifying security risks early and addressing them in order of priority. As soon as new security flaws are published - for example in an open source library - it can be determined automatically whether an affected product contains that component.
Automated risk assessment and prioritised remediation
Another important aspect of firmware monitoring is the automated assessment of risks. Not every vulnerability automatically represents a critical threat. What matters is whether the affected software component is actually in active use in the product and which functions it influences.
Onekey's monitoring platform therefore analyses contextual information such as:
- Affected components
- Exploitability of the vulnerability
- Potential impact on the system
The result is a prioritised list of security issues that can be worked through in a targeted manner. This information feeds directly into security incident response processes and helps Product Security Incident Response Teams (PSIRTs) deliver security updates faster and more precisely.
CRA Fast Start: structured compliance testing
Continuous monitoring across the entire product lifecycle is part of Onekey's "CRA Fast Start" programme, which is designed to give manufacturers of connected devices, machinery and plant a fast, structured way to check compliance with the Cyber Resilience Act. This approach was recognised with the "Best in Show Award" at Embedded World 2026.
A paradigm shift for manufacturers of digital products
For manufacturers of digital products, the Cyber Resilience Act means a fundamental change in security strategy. In future, security analyses must be carried out across a product's entire lifespan - from development through operation to end-of-life.
Firmware monitoring provides an essential technical foundation for this. It combines automated software analysis, continuous vulnerability observation and structured security processes into integrated security management.
Future outlook: daily vulnerability checks become standard
As Jan Wendenburg emphasises: "Given the growing number of connected devices and the increasing complexity of modern software architectures, daily vulnerability checks are becoming a decisive factor for regulatory compliance and security."
The combination of digital twins, automated monitoring and intelligent risk assessment creates the technical conditions needed to meet the requirements of the CRA while sustainably improving the security of connected systems.