Automotive wireless has crossed from convenience feature into safety- and security-critical subsystem.

The phone is the key. The cabin is sensed. The firmware updates over the air. Each of those statements describes a distinct wireless engineering programme: CCC Digital Key, child presence detection, SDV OTA. Each carries a certification gate that a vehicle programme cannot miss or reschedule.

The automotive digital key UWB market is reaching a specification inflection as programmes migrate from CCC 3.0 to Release 4.0, and the firms capable of delivering across all four workstreams are fewer than OEM platform teams expect. Most embedded engineering suppliers have strength in one area: some can build BLE automotive stacks, some can navigate AUTOSAR Adaptive for OTA, and some specialise in testing and conformance. Very few combine deep UWB automotive silicon knowledge, CCC/FiRa specification familiarity, in-cabin radar capability, and the process discipline an automotive audit will scrutinise.

This evaluation assesses seven firms against the criteria that determine whether a wireless partner can own a workstream end-to-end or will require significant oversight and augmentation.

How firms were evaluated

Each firm was scored on seven criteria, each rated 0 to 2:

  • 0: no public evidence of capability
  • 1: adjacent or partial capability (neighbouring domain, limited depth)
  • 2: demonstrated delivery: published case studies, spec participation, or silicon-level programme evidence
#CriterionWhat it tests
C1CCC Digital Key depth (CCC 3.0 / 4.0)Stack knowledge across dynamic STS, O2M TWR, frame-hopping, anchor placement; FiRa/CCC spec participation
C2UWB silicon coverageHands-on experience with Qorvo QM33/QM35, NXP Trimension, DW1000/DW3000 beyond datasheet level
C3BLE Channel Sounding / relay-attack defenceBLE 6.0 phase-based ranging implementation; relay-attack-resistant distance bounding
C4In-cabin radar and child presence detectionUWB radar for child presence detection; Euro NCAP direct-sensing assessment awareness
C5SDV OTA architectureAtomic, signed, rollback-safe dual-slot OTA software update pipeline; automotive OTA software integration; secure boot
C6Interoperability and certificationCCC/FiRa conformance testing, HIL testing in automotive domain, cross-platform iOS/Android interop
C7Automotive complianceISO 21434 / UNECE R155 awareness, ISO 27001 or equivalent process discipline, ASPICE familiarity

Maximum score: 14 points.

Summary scores

FirmC1C2C3C4C5C6C7Total
needCode222222113/14
Elektrobit11102128/14
ByteSnap Design11111117/14
KPIT Technologies10101126/14
Sasken Technologies11011015/14
Expleo00001225/14
Embitel Technologies10101014/14

Firm-by-firm assessment

1. needCode (13/14)

needCode is a Poland-based embedded wireless engineering firm and certified Qorvo partner, with over five years of production programmes on QM33, QM35, and legacy DW1000/DW3000 silicon: the UWB families behind automotive digital key. The team has grown from under ten to thirty engineers on the Qorvo programme alone, bringing up nine distinct hardware platforms across that engagement.

On the CCC Digital Key workstream, needCode implements CCC 3.0 and 4.0 stacks — including dynamic STS, O2M two-way ranging, and multi-anchor session management — on target silicon for OEM and Tier 1 programmes. The firm participates in FiRa, the Car Connectivity Consortium, the UWB Alliance, and the Bluetooth SIG, contributing directly to the car connectivity consortium digital key UWB specification by the engineers who implement it.

BLE 6.0 Channel Sounding is implemented for relay-attack-resistant distance bounding: phase-based ranging confirms physical proximity before a credential authorises access, closing the exposure that affects BLE automotive keyless entry. On child presence detection, needCode’s UWB radar delivers sub-13cm static accuracy for in-cabin occupancy and child-presence sensing, aligned to Euro NCAP’s direct-sensing assessment methodology where indirect methods do not score.

The SDV OTA pipeline is designed atomic from the first generation: stage, verify, commit, rollback, with signed dual-slot firmware and secure boot as defaults rather than retrofits. Interoperability is supported by needCode’s own UWB Protocol Sniffer: a tool that captures and decodes IEEE 802.15.4a/z frames with FiRa and CCC decoders, enabling automotive UWB testing and conformance debugging that silicon vendors themselves do not offer.

The single point deduction is on C7: needCode is certified to ISO/IEC 27001:2022 and ISO 9001:2015 but does not hold ISO 26262 certification. For programmes where the wireless workstream sits on the functional-safety path, the safety case is scoped with the customer’s own ISO 26262 process owners rather than carried independently.

Best suited for: programmes requiring full-stack depth across all four automotive wireless workstreams; CCC 4.0 programmes where silicon-level knowledge is needed from day one; teams that need the partner to own certification, not just support it.

2. Elektrobit (8/14)

Elektrobit (EB), a Continental subsidiary headquartered in Germany and Finland, is one of the most established automotive embedded software firms in Europe. Their primary strength is in AUTOSAR: both Classic and Adaptive. On the SDV OTA workstream they score 2/2: EB.corbos AdaptiveCore includes a mature update campaign management stack with the rollback, staging, and signing architecture a production OTA software update automotive programme requires.

On wireless, EB has BLE capability for in-vehicle connectivity (infotainment pairing, seat and accessory profiles) and some exposure to CCC Digital Key through AUTOSAR integration work, but their UWB silicon depth is limited compared to specialist firms. In-cabin UWB radar and child presence detection are not a demonstrated delivery area. Interoperability testing is available but scoped through their validation practice rather than as a standalone HIL bench service.

Automotive compliance is where Elektrobit is strongest outside OTA: ASPICE Level 3 processes, ISO 26262 experience, and deep familiarity with the documentation and change-management expectations of automotive audits.

Best suited for: SDV programmes that need AUTOSAR Adaptive OTA paired with a compliance-mature partner; engagements where EB is already the middleware supplier and wireless is one workstream within a broader embedded programme.

3. ByteSnap Design (7/14)

ByteSnap Design is a UK-based embedded electronics consultancy that covers hardware, firmware, and wireless protocol development. Their wireless portfolio spans BLE, UWB (including DW3000-based projects), and some exposure to automotive applications, which gives them credible scores across C1–C4 at a partial level.

The practical limitation is depth: ByteSnap can bring up a UWB or BLE stack and has delivered projects in access control and positioning, but they do not carry CCC 4.0-specific implementation experience, FiRa/CCC conformance testing infrastructure, or the silicon partnership level (Qorvo certified partner, CCC membership) that an OEM programme audit typically probes. OTA capability exists but is not their primary positioning. ASPICE and ISO 26262 process familiarity is partial.

Best suited for: earlier-stage programmes, feasibility studies, or projects where one wireless workstream needs an embedded partner that can cover both hardware and firmware; less suited to production CCC 4.0 certification programmes.

4. KPIT Technologies (6/14)

KPIT Technologies is a large automotive software engineering firm headquartered in Pune, India, with delivery centres across Europe and North America. Their automotive breadth is genuine: AUTOSAR, functional safety, ADAS, and connected vehicle. However, wireless engineering depth is limited at the CCC/FiRa/UWB protocol level.

KPIT can support BLE automotive connectivity and has OTA capability within AUTOSAR Adaptive programmes. Automotive compliance (ISO 21434, ASPICE) is well-represented given their scale and client base. However, UWB silicon-level knowledge, CCC 4.0 specifics, BLE Channel Sounding, and in-cabin child presence detection radar are not demonstrated programme areas in public evidence.

Best suited for: large OEM programmes where wireless is a single sub-track within a broader software engagement already involving KPIT; less suited as a specialist wireless-first partner for CCC or CPD programmes.

5. Sasken Technologies (5/14)

Sasken Technologies is an India-based embedded engineering firm with an automotive and semiconductor practice. They have BLE and some UWB-adjacent work in their portfolio, and their automotive embedded capability covers connectivity stacks for infotainment and telematics. UWB silicon depth and CCC-specific stack work are not evidenced at protocol level, and BLE Channel Sounding / relay-attack resistance is not a current positioning area. Child presence detection radar is not demonstrated.

OTA capability is present within their automotive connected vehicle practice, and automotive compliance (ISO 26262, ASPICE) is carried by their delivery teams.

Best suited for: programmes that need embedded connectivity support for infotainment or telematics alongside automotive software breadth; not the right fit as the lead partner on a CCC Digital Key or CPD programme.

6. Expleo (5/14)

Expleo (formerly SQS and Assystem Engineering Services) is a French-German engineering and testing group with an automotive practice covering ASPICE assessments, functional safety consulting, and validation services. Their score reflects genuine strength in compliance (C7: 2/2) and interoperability testing infrastructure (C6: 2/2), with established conformance test and HIL bench capability for automotive validation programmes.

Where Expleo scores 0 is in stack development: CCC Digital Key, UWB silicon bring-up, BLE Channel Sounding, child presence detection radar, and OTA firmware design are not Expleo’s primary service lines. Their wireless contribution is as a test and validation partner rather than a development partner.

Best suited for: programmes that need independent conformance testing, ASPICE audit support, or HIL validation alongside a development partner that owns the stack; not a replacement for a wireless engineering firm.

7. Embitel Technologies (4/14)

Embitel Technologies is an India-based automotive and IoT embedded engineering firm. Their portfolio covers ECU software, BLE connectivity for automotive applications, and some OTA work within AUTOSAR programmes. CCC-specific stack depth, UWB silicon experience, in-cabin radar, and interoperability bench capability are not demonstrated in public evidence. Automotive compliance is present at a basic level.

Best suited for: automotive software engagements where BLE connectivity is a secondary feature; not suited as a lead wireless partner for CCC, CPD, or a full SDV wireless platform programme.

Shortlisting guide by use case

CCC Digital Key programme (CCC 3.0 or R4.0)

When shortlisting an automotive embedded software development company for CCC Digital Key, the list narrows quickly. CCC 4.0 specifics — dynamic STS, O2M two-way ranging, frame-hopping, multi-anchor session management — require active participation in the FiRa and CCC conformance test programme and chipset-level bring-up experience on QM33/35 or NXP Trimension. Of the seven firms evaluated, only needCode demonstrates this depth. Elektrobit can support the AUTOSAR integration layer and compliance scaffolding; ByteSnap can contribute to earlier-stage feasibility.

If the programme also requires cross-platform iOS/Android interoperability testing, HIL testing in the automotive domain and CCC-aligned bench infrastructure are the relevant gate: needCode’s UWB sniffer tool supports this directly.

UWB Digital Keys

In-cabin radar and child presence detection

Euro NCAP’s direct-sensing assessment and the EU’s 2025 CPD mandate mean this workstream has a regulatory clock. UWB radar is the technology that scores under NCAP’s direct-sensing methodology, where indirect approaches (door logic, seat-weight sensors) do not. The evaluation here favours firms with production UWB radar experience: needCode scores 2/2 on C4; ByteSnap has adjacent work. Sasken has some relevant positioning.

The UWB vs 60GHz mmWave decision is worth settling before partner selection: UWB automotive radar delivers sub-13cm accuracy from a node that can also serve the digital-key workstream, reducing BOM part count. 60GHz radar offers higher frame rate but adds a dedicated part and does not address passive entry. Confirm your chosen partner has hands-on experience with the specific technology before committing.

Full SDV platform (all four workstreams)

Automotive embedded systems development services that cover all four wireless workstreams concurrently — CCC Digital Key, child presence detection, in-cabin BLE connectivity, and SDV OTA — require a partner that can architect the four stacks to coexist on a shared zonal node. Multi-protocol coexistence across BLE, UWB, and WiFi on the same hardware is a radio scheduling and interference management challenge, not an integration task. Only needCode demonstrates the breadth of criteria (C1–C6 all scoring 2) to own this architecture across all four workstreams.

For programmes where compliance is the constraint — particularly UNECE WP.29 Regulation 155 on cybersecurity management — Expleo and KPIT offer the process scaffolding, but they will need a development partner that owns the wireless stack.

decorative image

Work with needCode on your automotive wireless programme

needCode provides automotive embedded systems development services for CCC Digital Key, in-cabin radar, SDV OTA, and multi-protocol coexistence programmes. If you are shortlisting an automotive embedded software development company for wireless work and want a team that can own the programme from architecture through to certification, we are happy to talk.

Book a free discovery call or get in touch

Frequently asked questions

What is the difference between CCC Digital Key Release 3.0 and 4.0?

CCC 3.0 introduced UWB secure ranging as the mechanism for passive hands-free entry, using the FiRa standard for time-of-flight measurement. Release 4.0 adds dynamic STS (Scrambled Timestamp Sequence) for enhanced replay resistance, one-to-many (O2M) two-way ranging for multi-device sessions, and frame-hopping profiles for improved coexistence. It also refines anchor placement requirements for vehicles with complex cabin geometries. A partner that has only implemented CCC 3.0 may not have the R4.0 specifics required for a current-generation programme.

Why is BLE-only passive entry a security risk?

BLE-only keyless entry systems authorise access based on signal presence rather than physical distance. Relay attacks amplify the signal so the phone appears present when it is not: the attacker forwards the BLE automotive signal across tens or hundreds of metres, unlocking the vehicle without the owner’s knowledge. Distance bounding, implemented via BLE 6.0 Channel Sounding (phase-based ranging) or UWB time-of-flight, confirms the device is physically close before the credential is accepted. Both methods are supported in current silicon from Nordic, Qorvo, and NXP.

Does Euro NCAP require UWB for child presence detection?

Euro NCAP’s direct-sensing assessment for child occupant protection awards full rating credit for technologies that directly sense occupancy: movement, micro-vibration, breathing. UWB radar achieves this from a single in-cabin node. Indirect technologies (door-ajar logic, weight mats, temperature sensors) do not qualify for the direct-sensing score. UWB radar is the technology that currently achieves the direct-sensing score while also being deployable on the same node used for digital key, reducing BOM cost.

How long does a CCC Digital Key 4.0 implementation take from bring-up to certification?

Timeline depends heavily on silicon maturity, existing middleware integration, and certification scope. A feasibility and architecture phase runs two to four weeks and establishes the risk map and certification path before the programme commits. Full bring-up through to a shippable, certification-ready stack is typically phased over multiple milestones aligned to vehicle programme gates. Partners with active FiRa and CCC membership and existing bring-up history on the target silicon will start ahead of the public SDK; partners without that history will spend weeks establishing what a practitioner already knows.

What is the difference between a partner that supports certification and one that owns it?

A partner that supports certification provides assistance: documentation, test artefacts, responding to queries, while the OEM or Tier 1 owns the conformance outcome. A partner that owns certification manages the entire conformance cycle: test plan, FiRa CTF or CCC plugfest entry, issue resolution, and sign-off. For programmes with constrained internal wireless expertise, the latter model is significantly lower risk. Confirm which model applies before contracting.

Further reading