Automotive Penetration Testing in 2026
What vehicle pen testing covers, why regulators require it, what Pwn2Own Automotive shows about the firms doing the research, and how to evaluate a partner.
What automotive pen testing actually covers
Automotive penetration testing is the controlled, simulated attack of a vehicle and the systems around it. The scope is much wider than traditional IT pen testing. A modern car is a fleet of connected computers, and a serious automotive engagement touches most of them:
- Electronic control units (ECUs). Engine, transmission, brakes, ADAS, body, gateway. Hardware-level reverse engineering and firmware analysis.
- In-vehicle networks. CAN, CAN-FD, LIN, FlexRay, and increasingly Automotive Ethernet. Bus injection, fuzzing, gateway bypass.
- Infotainment (IVI) and telematics. Head units, modems, Bluetooth, Wi-Fi, cellular. Remote attack surface and pivoting into the rest of the vehicle.
- Over-the-air (OTA) update systems. Signing, manifest validation, rollback protection.
- V2X and EV charging. Vehicle-to-grid, ISO 15118, OCPP, and the growing attack surface of public charging networks.
- Mobile companion apps and cloud backends. The remote side of the vehicle: account takeover, API abuse, fleet-management interfaces.
Most credible engagements combine hardware lab work, firmware reverse engineering, network attacks, and remote attack-surface assessments. A pen test that only looks at the cloud APIs is fine as far as it goes, but it's not automotive pen testing in the full sense.
Why it matters: regulation and real risk
UN Regulation No 155 makes an approved cybersecurity management system (CSMS) a condition of vehicle type approval in the markets that apply it, including the EU, Japan and Korea. In the EU it has applied to new vehicle types since 6 July 2022, and since 7 July 2024 a new vehicle without it cannot be registered. UN Regulation No 156 does the same for software updates. China's GB 44495-2024 has applied to new vehicle types since 1 January 2026 and reaches vehicles already approved on 1 January 2028. A CSMS must include vulnerability management and security validation, which in practice means systematic testing, penetration testing included, across the lifecycle.
ISO/SAE 21434, the international standard for cybersecurity engineering of road vehicles, prescribes verification activities and explicitly calls out penetration testing as a method. ASPICE and TISAX layer on process and supply-chain assurance.
Beyond compliance, the real-world consequences are well documented. PCA Cyber Security disclosed nine vulnerabilities in the MIB3 infotainment unit used in Škoda and Volkswagen vehicles and in Škoda's cloud backend in November 2023, then 12 more in the MIB3 unit of the Škoda Superb III at Black Hat Europe in December 2024. Older industry-shaping research includes Miller and Valasek's 2015 remote takeover of a Jeep Cherokee, which led to a 1.4M-vehicle recall and effectively launched the modern automotive cybersecurity industry.
Pwn2Own Automotive: a live signal of who can hack what
Pwn2Own Automotive is Trend Micro's Zero Day Initiative competition focused on connected-vehicle hardware and software. It launched in Tokyo in January 2024 and has run every January since. Targets have included:
- Infotainment head units from Sony, Alpine, Pioneer and Kenwood
- EV chargers from Tesla, JuiceBox, ChargePoint, Phoenix Contact and others
- Automotive Grade Linux and various in-vehicle operating systems
Because results are publicly disclosed with cash awards attached, Pwn2Own Automotive is the clearest available signal of which firms can find serious vulnerabilities under live conditions. PCA Cyber Security competed in 2024 and 2025. In 2024 the team exploited the Alpine Halo9 head unit through a use-after-free for $40,000. In 2025 it gained code execution on the Alpine iLX-507 with a stack-based buffer overflow ($20,000), chained three bugs into a zero-click exploit of the Sony XAV-AX8500 ($10,000), and exploited the Tesla Wall Connector with a bug the vendor already knew about, which still earned $22,500. The 2025 event awarded $886,250 for 49 zero-days. The 2026 event, in January, awarded $1,047,000 for 76, and the Fuzzware.io team was named Master of Pwn.
Firms in this directory offering automotive pen testing
Three of the firms in our automotive cybersecurity guide document penetration testing as a service. They're listed alphabetically. These are factual listings, not editorial picks. The full guide also covers in-vehicle protection, cloud vehicle SOC monitoring, threat intelligence and compliance tooling.
PCA Cyber Security
Munich and Budapest · Services-led · TISAX Assessment Level 3
An offensive-security and threat-intelligence specialist with dedicated CyberLab and CyberGarage hardware facilities. Repeat Pwn2Own Automotive contestants with disclosed research on Skoda, Volkswagen, Nissan, and Tesla hardware. Documented engagements span penetration testing, TARA, V&V, and managed Product SOC monitoring.
PCA Cyber Security profile →VicOne
Tokyo · Trend Micro subsidiary
xScope penetration testing is part of a lifecycle portfolio that also covers in-vehicle IDPS, VSOC, threat intelligence, and SBOM. Backed by the same Zero Day Initiative engine that runs Pwn2Own Automotive.
VicOne profile →VxLabs
Regensburg · Platform and engineering services
Engineering services cover penetration testing, AUTOSAR ECU development, CSMS consulting and R155 type approval support, alongside ThreatZ, a TARA, SBOM and compliance evidence platform launched in October 2025.
VxLabs profile →How to evaluate an automotive pen testing partner
The market has more “automotive cybersecurity” vendors than actually have deep automotive offensive capability. A few signals separate the credible from the adjacent:
- Hardware and firmware capability. Can they reverse engineer an ECU and an IVI module, not just attack the cloud API? Ask about lab facilities and example hardware they have worked on.
- Disclosed research and conference presence. Public CVEs, coordinated-disclosure track record, and talks at escar, Black Hat, Hexacon, or Hacktivity are the strongest evidence.
- Standards expertise. ISO/SAE 21434, UNECE R155/R156, ASPICE, and TISAX accreditation. Helpful if the deliverables map directly to your CSMS.
- Methodology that includes TARA. Threat analysis and risk assessment, attack-surface mapping, and threat modelling produce better tests than a checklist sweep.
- Coverage scope.In-vehicle, fleet/cloud, EV charging, mobile, and backend each need different specialisms. Map the partner's strengths to the parts of your stack that matter most.
Sources
- Zero Day Initiative: Pwn2Own Automotive 2024, day one results (January 2024)
- Zero Day Initiative: Pwn2Own Automotive 2025, day one results (January 2025)
- Zero Day Initiative: Pwn2Own Automotive 2025, day two results (January 2025)
- Zero Day Initiative: Pwn2Own Automotive 2025, day three and final results (January 2025)
- Zero Day Initiative: Pwn2Own Automotive 2026, day three results and the Master of Pwn (January 2026)
- PCA Cyber Security: vulnerabilities in Škoda and Volkswagen vehicles (November 2023)
- TechCrunch: researchers find security flaws in Skoda cars (12 December 2024)
- Regulation (EU) 2019/2144, Annex II
- TÜV SÜD: China implements vehicle cybersecurity technical requirements (GB 44495-2024) (January 2026)