We develop and use in-house tools and methods to automate vulnerability scanning and fuzzing, saving hours on projects while providing essential security insights.
Using techniques such as threat modeling, we help you control the scope of evaluation, testing only what is relevant to your product and context.
We adapt the depth of our research to meet your project's needs efficiently and achieve optimal protection of your products at every stage of development.
Get your products market-ready with tailored security design support and ongoing compliance checks, reducing the risks of costly rework.
Focus on advancing your technology while Keysight manages the OCP S.A.F.E. evaluation requirements.
Leverage Keysight's extensive industry accreditation to combine multiple certification programs, such as SESIP, PSA, and EUCC. Benefit from a streamlined collaboration with significant time and cost savings across certification schemes.
Keysight supports your development across the product life cycle, bringing relevant project experience to all three scopes of the OCP S.A.F.E. requirements. Our team specializes in evaluating devices and components throughout the supply chain, from chip to cloud.
Every product and team is unique, which is why Keysight focuses on delivering tailored strategies to meet individual project needs. We are dedicated to fostering long-term partnerships through continuous support and guidance.
Explore how Caliptra trademark audits can support OCP S.A.F.E. assessments while also helping address relevant EU Cyber Resilience Act requirements. This webinar covers the preparation needed to verify Root of Trust implementations and navigate hyperscale and regulatory security expectations.
OCP S.A.F.E. (Security Appraisal Framework and Enablement) is an Open Compute Project program that standardizes independent security reviews of hardware and firmware used in data centers. It's designed to reduce the overhead and redundancy of repeated security audits, give device consumers assurance of security conformance, and raise the security posture of hardware and firmware across the supply chain.
No. S.A.F.E. is a review framework rather than a pass/fail certification. The deliverable is a public report explaining findings and risks. Findings are expected in every evaluation and don't constitute a failure; what matters is clarity, context, and mitigation posture, so cloud service providers can adopt components with eyes open.
Data center processing devices such as CPUs, GPUs, and FPGAs, and peripheral components including network controllers, accelerators, and storage devices — along with the updatable software, firmware, or microcode they run. Keysight has also evaluated firmware, trusted execution environments, operating systems, and applications across these platforms.
An SRP is a third-party lab approved by OCP to perform S.A.F.E. reviews and submit conformance reports. Keysight is an approved OCP S.A.F.E. SRP, delivering expert-led evaluations of firmware and hardware-level security measures — including code quality and structure, cryptographic protections, firmware update mechanisms, and supply chain integrity.
Keysight brings project experience to all three scopes.
It depends on your threat model and what your customers require. We use threat modeling to help you control the scope of evaluation, testing only what is relevant to your product and its deployment context.
Software-centric findings use CVSS. For hardware-centric findings, S.A.F.E. uses JIL-style scoring, because CVSS was built for software and doesn't model equipment, skill, and physical steps well.
Not by default. Countermeasures are evaluated through design review and, where appropriate, RTL-level analysis and simulation; costly destructive testing for every SKU is not required.
You engage Keysight as your SRP and we agree on scope. We perform the review, then submit the security conformance report to OCP. Once submitted, the device is designated an OCP S.A.F.E. approved product and listed on the OCP Marketplace, OCP issues the appropriate S.A.F.E. logos, and you can begin promoting the device as OCP S.A.F.E.
Typically source code and build artifacts, design and architecture documentation, your threat model, and representative device samples with debug access where physical testing is in scope. We'll confirm the exact evidence list during scoping.
You receive a detailed technical report for your engineering teams, plus the short-form report submitted to OCP. The short-form format is moving from JSON to CBOR, which is easier to validate at scale and better aligned with existing verifier tooling — giving more predictable ingestion by CSPs and fewer format mismatches between SRPs.
One goal of the program is to increase the number of devices whose firmware and associated updates are reviewed on a continuous basis. We size delta reviews to the change, so an incremental firmware release doesn't mean starting over. Aligning your attestation records with runtime measurements helps here: S.A.F.E. is shifting emphasis from on-disk file hashes to runtime measurements, so integrity checks survive repacking and layout changes.
Yes. Keysight's accreditations let you bundle multiple programs such as SESIP, PSA, and EUCC, sharing evidence across schemes for meaningful time and cost savings rather than running each evaluation in isolation.
Yes. We offer security advisory, design support, and pre-assessment to find issues while they're still cheap to fix, reducing the risk of costly rework.
Both depend on scope, product complexity, and the maturity of your documentation and threat model. Contact us for a scoped quote.
Our experts regularly share practical insights in our blog. Explore the latest developments in hyperscale security.
Keysight’s structured approach, responsiveness, and technical rigor played a key role in our successful evaluation. Their deep expertise and close collaboration with our developers ensured a smooth process from start to finish.
VP of eSSD Firmware & Product Engineering, SK hynix
What are you looking for?