Changelog

Follow new updates and improvements to OneClickComply.

May 21st, 2026

A critical heap buffer overflow just hit every standard NGINX build. And it's been sitting there since 2008.

Active exploitation is confirmed in the wild. The public PoC came out on disclosure day.

So we stepped in and just added detection for CVE-2026-42945 to our penetration testing module. You can access it here

Donโ€™t have access to penetration testing? Drop us a message and one of our team will be happy to take you through how it can benefit and protect your business.

May 4th, 2026

Dear Customer,

We're thrilled to announce that OneClickComply has been completely rebuilt and significantly improved - and we can't wait for you to experience it.

To ensure a smooth transition to the new platform, there are two quick steps you'll need to complete:

Step 1: Reset Your Password

As part of the rebuild, existing passwords are no longer compatible with the new platform. To set a new password, visit hub.oneclickcomply.com, and use the 'Forgot Password' option on the login page and follow the link sent to your email.

Step 2: Enable Two-Factor Authentication (2FA)

We've strengthened the security of the platform by moving to two-factor authentication. Email verification is no longer supported, so you'll need to enable 2FA on your account when you first log in.

For a step-by-step guide on how to set this up, please visit our support article here: https://support.oneclickcomply.com/articles/2134428-enabling-2fa-two-factor-authentication

What You Need to Do - In Summary:

1. Visit hub.oneclickcomply.com and click โ€˜Forgot Password'

2. Check your email and follow the link to set a new password

3. Log in and enable 2FA using our guide above.

These steps should only take a few minutes, and you'll then have full access to everything the new OneClickComply has to offer.

If you run into any issues or have questions, our support team is on hand to help at support@oneclickcomply.com.ย 

Thank you for being a valued customer. We are incredibly excited for you to see what's new and improved.

Sincerely,ย 

The OneClickComply Team

April 22nd, 2026

We're excited to announce that you can now book your Audit Pre-Submission Review (Readiness Assessment) directly within the platform at app.oneclickcomply.com/pre-submission-review. Select your target framework, choose an available slot, and confirm your booking in just a few clicks. You'll receive an email confirmation along with a preparation checklist tailored to your chosen framework so you know exactly what to have ready on the day.

Important: Check your entitlement before booking. The number of Readiness Assessments included in your subscription varies depending on your agreement. Some customers have two included assessments, others may have more or fewer depending on the package agreed at the time of signing. If you are unsure how many assessments are included in your plan, or whether you have any remaining, please contact our support team at support@oneclickcomply.com or via live chat before booking. Assessments booked beyond your included entitlement will be charged at ยฃ1,000 excluding VAT per assessment, and we don't want anyone to be caught out by an unexpected invoice.

New Support Article: Understanding the Any Auditor Guarantee and Readiness Assessment Process

To help our customers better understand how the Any Auditor Guarantee works and what to expect from the Readiness Assessment process, we've published a comprehensive guide on our Help Centre: The Any Auditor Guarantee.

This article covers everything you need to know, including which frameworks are covered by the guarantee (SOC 2 Type II, ISO 27001:2022, and Cyber Essentials Plus), how to book and prepare for your Readiness Assessment, what happens on the Assessment Day, how the Readiness Report is produced and what it contains, the ten working day Report Delivery Window and why it's needed, what "Audit Ready" and "Not Audit Ready" determinations mean for your guarantee eligibility, the qualified auditor requirements your chosen certification body must meet, how we handle impartiality and conflict of interest, and frequently asked questions covering the most common scenarios our customers ask about.

We'd strongly encourage all customers to read this article before scheduling their audit, particularly if you're approaching your first certification under one of the covered frameworks. If anything is unclear, our support team is happy to walk you through it.

Reminder: Pre-Audit Requirements Under the Any Auditor Guarantee

Under Clause 21 of your customer agreement, you are required to inform OneClickComply prior to undertaking any audit covered by the Any Auditor Guarantee. OneClickComply is entitled to suspend any such audit in order to assess your current security and compliance posture and to form a professional opinion on your likelihood of success. This assessment is conducted through the Readiness Assessment process.

Customers who have not yet booked their Audit Pre-Submission Review, or who have booked but not yet undergone the review, or who have not received a formal "Audit Ready" determination within a finalised Readiness Report, should treat this as a suspension of their authority to proceed to audit under the guarantee.

You are not authorised to proceed to a covered audit under the protection of the Any Auditor Guarantee until a written "Audit Ready" determination has been delivered to you in a completed, peer-reviewed Readiness Report.

If you proceed to audit without having received this determination, you do so entirely at your own risk and outside the protection of the Any Auditor Guarantee. No refund will be payable in the event of audit failure in these circumstances, regardless of any informal or verbal indication you may have received.

To book your Audit Pre-Submission Review, visit app.oneclickcomply.com/pre-submission-review or contact your account manager.

April 8th, 2026

New

We're excited to announce that OneClickComply now supports NIST CSF 2.0 (Cybersecurity Framework 2.0).

This is a big one. NIST CSF 2.0 is one of the most widely adopted cybersecurity frameworks in the world, used by organisations of all sizes across every industry. Version 2.0 introduced a brand new sixth function, Govern, alongside the existing Identify, Protect, Detect, Respond, and Recover functions, making it the most comprehensive version of the framework to date.

What we've added

To bring NIST CSF 2.0 into OneClickComply, we've mapped 106 controls across all six core functions, backed by 1,362 remediations. That covers everything from supply chain risk management and asset governance through to incident response and recovery planning. As with all our supported standards, you get automated scanning, guided remediation steps, and compliance tracking from day one.

Want to access the new NIST CSF 2.0 standard?

If you're an existing customer and want NIST CSF 2.0 added to your account, just get in touch with our team via Live Chat or by email at support@oneclickcomply.com. Depending on your current plan and setup, an additional fee may apply, but we'll walk you through everything when you reach out.

We're always building based on what our customers need. If there's a compliance standard, framework, or feature you'd like to see in OneClickComply, head over to our feedback board and submit a request. You can also upvote existing suggestions to help us prioritise what to build next.

March 19th, 2026

We're excited to announce that the updated Linux Device Vulnerability Manager is now available in beta.

How to access: You can access the beta version from the Install pageย within the Device Vulnerabilities area.

Coming soon: Support for Windows and macOS devices will be added to this area soon.

Share your feedback: We'd love to hear your thoughts on the beta. You can share feedback with us directly via Live Chat or by email.

March 19th, 2026

We've made a number of improvements to Continuous Monitoring and On-Demand Scanning, including a refreshed UI and new functionality to give you greater visibility and control over your integrations.

Continuous Monitoring

  • Refreshed dashboard with an updated UI

  • Dedicated scan review area for each connected integration

  • On-Demand Scanning has moved - see below

On-Demand Scanning

  • Now accessible directly within the Integrations area

  • Scan frequency can now be customised, rather than simply toggled on or off

  • New Integration Management window, providing a detailed overview of each selected connection

Updated support articles are available to help you get familiar with the changes. If you have any questions, please don't hesitate to reach out to our support team.