Payment Device Security Testing and Threat Intelligence

Providers that assess the security of payment infrastructure: terminals, PIN pads, unattended and self-service devices, ATMs, HSMs and the payment applications on them. They split into two kinds, and the distinction matters more than any ranking. Four are accredited evaluation la

5 tools listed|2026|No editorial scoring|context: PCA Cyber Security|Part of the Automotive Cybersecurity guide

What this shortlist looks at

Accreditation

Whether the provider is a PCI Recognized Laboratory, and which programmes it covers: PTS POI, HSM, SPoC, CPoC, MPoC or SDK.

Beyond PCI

Whether it also holds EMVCo, Common Criteria or national scheme accreditation such as the German DK, OSeC and JTEMS.

Formal evaluation or adversarial testing

Whether the work produces a certification result against a scheme, or attempts to break a device that already holds approval.

Device coverage

Terminals and PIN pads, unattended and self-service devices, ATMs, fuel and EV charging payment systems, and HSMs.

Threat intelligence and research

Whether the provider publishes its own research on payment device attacks, or only performs evaluation to order.

Tools listed here

PCA Cyber Security

Adversarial testing and threat intelligence, rather than formal evaluation

The only provider here that tests payment devices offensively rather than evaluating them against a certification scheme. It tests terminals, PIN pads, unattended and self-service terminals and ATMs beyond PCI PTS certification to find vulnerabilities in devices that already hold approval, and runs its own threat intelligence and firmware-level software composition analysis. A PCI SSC Associate Participating Organisation since 2026, registered in Budapest with an office in Munich.

Offensive security and threat intelligence for payment devices, vehicles and embedded systems

SERMA Safety & Security

Accredited French lab across PTS, EMVCo and Common Criteria

A French ITSEF evaluation lab assessing security from chip to full system, stated at more than 200 product evaluations a year. PCI Recognized for PTS and payment acceptance devices, and accredited for EMVCo and Common Criteria.

French security evaluation lab (ITSEF); PCI Recognized for PTS, plus EMVCo and Common Criteria.

SGS Brightsight

One of the largest payment and chip evaluation labs

Part of SGS, and PCI Recognized across the PTS, SPoC, CPoC, MPoC and SDK programmes, with hundreds of completed PCI PTS device approvals. Also an accredited EMVCo and Common Criteria lab.

Major PCI Recognized security evaluation lab for payment devices, EMVCo and Common Criteria.

SRC Security Research & Consulting

German schemes alongside PCI PTS

A German PCI Recognized test lab that performs PCI PTS device evaluations alongside the German DK, OSeC and JTEMS terminal schemes, which matters for manufacturers selling into the German market.

German PCI Recognized lab for PCI PTS device evaluation and German payment terminal schemes.

UL Solutions

Global TIC firm with PTS POI, HSM and EMVCo scope

PCI Recognized for PTS POI and HSM evaluation and an EMVCo type-approval lab, stating support for approval of more than a thousand payment terminals since the PTS programme began.

Global TIC firm and PCI Recognized lab for payment terminal (PTS POI/HSM) and EMVCo testing.

For the full category walkthrough with every tool compared, see the Automotive Cybersecurity guide.

Frequently Asked Questions

A laboratory the PCI Security Standards Council has accredited to evaluate devices against its programmes, most commonly PTS POI for payment terminals and PIN entry devices, and PTS HSM for hardware security modules. Only a recognised laboratory can perform the evaluation that leads to a device approval, so if the goal is getting a terminal approved, the provider has to hold that accreditation.

Certification establishes that a device met a defined set of requirements at a point in time, under a defined threat model. It does not establish that no vulnerability exists. Adversarial testing looks for weaknesses in devices that already hold approval, including in firmware and third-party components that a scheme evaluation may not examine in that depth. Operators, acquirers and issuers deploying devices at scale generally care about that question, whereas manufacturers seeking approval care about the scheme.

No. The adversarial provider is listed first because it is the one exception in a list of accredited laboratories, and the laboratories follow alphabetically. We do not score providers, and placement is not for sale.