Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

Automotive Penetration Testing in 2026

What vehicle pen testing covers, why regulators require it, what Pwn2Own Automotive shows about the firms doing the research, and how to evaluate a partner.

How we work:This guide is aggregated from official company materials, regulatory texts, vendor disclosures, and reputable industry coverage. We don't do hands-on testing; we organise what's already out there. Last reviewed September 2026.

What automotive pen testing actually covers

Automotive penetration testing is the controlled, simulated attack of a vehicle and the systems around it. The scope is much wider than traditional IT pen testing. A modern car is a fleet of connected computers, and a serious automotive engagement touches most of them:

Most credible engagements combine hardware lab work, firmware reverse engineering, network attacks, and remote attack-surface assessments. A pen test that only looks at the cloud APIs is fine as far as it goes, but it's not automotive pen testing in the full sense.

Why it matters: regulation and real risk

UN Regulation No 155 makes an approved cybersecurity management system (CSMS) a condition of vehicle type approval in the markets that apply it, including the EU, Japan and Korea. In the EU it has applied to new vehicle types since 6 July 2022, and since 7 July 2024 a new vehicle without it cannot be registered. UN Regulation No 156 does the same for software updates. China's GB 44495-2024 has applied to new vehicle types since 1 January 2026 and reaches vehicles already approved on 1 January 2028. A CSMS must include vulnerability management and security validation, which in practice means systematic testing, penetration testing included, across the lifecycle.

ISO/SAE 21434, the international standard for cybersecurity engineering of road vehicles, prescribes verification activities and explicitly calls out penetration testing as a method. ASPICE and TISAX layer on process and supply-chain assurance.

Beyond compliance, the real-world consequences are well documented. PCA Cyber Security disclosed nine vulnerabilities in the MIB3 infotainment unit used in Škoda and Volkswagen vehicles and in Škoda's cloud backend in November 2023, then 12 more in the MIB3 unit of the Škoda Superb III at Black Hat Europe in December 2024. Older industry-shaping research includes Miller and Valasek's 2015 remote takeover of a Jeep Cherokee, which led to a 1.4M-vehicle recall and effectively launched the modern automotive cybersecurity industry.

Pwn2Own Automotive: a live signal of who can hack what

Pwn2Own Automotive is Trend Micro's Zero Day Initiative competition focused on connected-vehicle hardware and software. It launched in Tokyo in January 2024 and has run every January since. Targets have included:

Because results are publicly disclosed with cash awards attached, Pwn2Own Automotive is the clearest available signal of which firms can find serious vulnerabilities under live conditions. PCA Cyber Security competed in 2024 and 2025. In 2024 the team exploited the Alpine Halo9 head unit through a use-after-free for $40,000. In 2025 it gained code execution on the Alpine iLX-507 with a stack-based buffer overflow ($20,000), chained three bugs into a zero-click exploit of the Sony XAV-AX8500 ($10,000), and exploited the Tesla Wall Connector with a bug the vendor already knew about, which still earned $22,500. The 2025 event awarded $886,250 for 49 zero-days. The 2026 event, in January, awarded $1,047,000 for 76, and the Fuzzware.io team was named Master of Pwn.

Firms in this directory offering automotive pen testing

Three of the firms in our automotive cybersecurity guide document penetration testing as a service. They're listed alphabetically. These are factual listings, not editorial picks. The full guide also covers in-vehicle protection, cloud vehicle SOC monitoring, threat intelligence and compliance tooling.

PCA Cyber Security

Munich and Budapest · Services-led · TISAX Assessment Level 3

An offensive-security and threat-intelligence specialist with dedicated CyberLab and CyberGarage hardware facilities. Repeat Pwn2Own Automotive contestants with disclosed research on Skoda, Volkswagen, Nissan, and Tesla hardware. Documented engagements span penetration testing, TARA, V&V, and managed Product SOC monitoring.

PCA Cyber Security profile →

VicOne

Tokyo · Trend Micro subsidiary

xScope penetration testing is part of a lifecycle portfolio that also covers in-vehicle IDPS, VSOC, threat intelligence, and SBOM. Backed by the same Zero Day Initiative engine that runs Pwn2Own Automotive.

VicOne profile →

VxLabs

Regensburg · Platform and engineering services

Engineering services cover penetration testing, AUTOSAR ECU development, CSMS consulting and R155 type approval support, alongside ThreatZ, a TARA, SBOM and compliance evidence platform launched in October 2025.

VxLabs profile →

How to evaluate an automotive pen testing partner

The market has more “automotive cybersecurity” vendors than actually have deep automotive offensive capability. A few signals separate the credible from the adjacent:

Sources

Frequently Asked Questions

Automotive penetration testing is the controlled, simulated attack of a vehicle and its surrounding systems to find security weaknesses before adversaries do. The scope is much wider than traditional IT pen testing: electronic control units (ECUs), in-vehicle networks (CAN, CAN-FD, Automotive Ethernet), infotainment and telematics units, over-the-air update systems, V2X interfaces, EV chargers, mobile companion apps, and the cloud backends that serve them. It usually combines hardware reverse engineering, firmware analysis, network attacks, and remote attack-surface assessments.

UN Regulation No 155 makes an approved cybersecurity management system (CSMS) a condition of vehicle type approval in the markets that apply it, including the EU, Japan and Korea. In the EU it has applied to new vehicle types since 6 July 2022 and to every newly registered vehicle since 7 July 2024. China's GB 44495-2024 has applied a similar requirement to new vehicle types since 1 January 2026. ISO/SAE 21434, the international standard for cybersecurity engineering of road vehicles, prescribes verification activities such as penetration testing across the development lifecycle. Beyond compliance, vulnerabilities in vehicles can lead to theft, ransom, data exfiltration and, in the worst cases, safety incidents, which drives demand for independent testing.

Pwn2Own Automotive is Trend Micro's Zero Day Initiative competition focused on connected-vehicle hardware and software. It launched in Tokyo in January 2024 and has run every January since; the 2026 event paid $1,047,000 for 76 previously unknown vulnerabilities. Targets have included infotainment head units from Sony, Alpine, Pioneer and Kenwood; EV chargers from Tesla, JuiceBox, ChargePoint and Phoenix Contact; and Automotive Grade Linux. Results are publicly disclosed and give the clearest available signal of which firms can find serious vulnerabilities under live conditions.

Look for genuine hardware and firmware capability (not just network testing), a track record of publicly disclosed research and conference talks (escar, Black Hat, Hexacon), demonstrated standards expertise (ISO/SAE 21434, UNECE R155/R156, ASPICE, TISAX), and a methodology that covers threat analysis and risk assessment (TARA) alongside the testing itself. Coverage scope also matters: in-vehicle protection vs. fleet/cloud monitoring vs. EV charging vs. mobile and backend systems.