Automotive Cybersecurity: 5 Companies compared
Regulation drives much of this work. In the EU, a new vehicle type has needed protection against cyberattacks under UN Regulation No 155 to gain type approval since 6 July 2022, and since 7 July 2024 new vehicles without it cannot be registered. China's GB 44495-2024 has applied to new type approvals since 1 January 2026 and reaches vehicles already approved on 1 January 2028; it covers cars, buses, lorries and trailers (categories M, N and O) with at least one ECU. All five firms here frame their work around ISO/SAE 21434, the engineering standard for vehicle cybersecurity.
The attack surface keeps growing. Upstream Security, one of the firms listed here, counted 494 publicly reported automotive and smart mobility incidents in 2025: 44% were ransomware-related, more than double the 2024 volume, and 67% involved telematics and cloud systems. At Pwn2Own Automotive in January 2026, researchers were paid $1,047,000 for 76 previously unknown vulnerabilities, in targets including Tesla's infotainment system, EV chargers and Automotive Grade Linux.
The firms do different jobs. PCA Cyber Security is an offensive testing specialist; Vector Informatik and VicOne supply in-vehicle security software; Upstream Security and VicOne run managed vehicle SOCs; and VxLabs sells a TARA, SBOM and compliance evidence platform alongside engineering services. Most programmes combine testing, in-vehicle protection and fleet monitoring rather than choosing one.
5 Automotive Cybersecurity Companies, side by side
Featured listings are paid placements.
| Company | Founded | Engagement | Specialism | Standards / accreditations |
|---|---|---|---|---|
| PCA Cyber SecurityFeatured | 2019 | Project-based engagements | Manufacturers and operators of payment devices, vehicles, industrial systems and other em… | TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434 |
| Upstream Security | 2017 | Subscription (custom) | OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle… | ISO/SAE 21434, UNECE R155, UNECE R156 |
| Vector Informatik | 1988 | Quote-based licensing for embedded software and tools, with separate fees for consulting and training | Automotive OEMs and Tier 1 suppliers needing production-grade ECU security software and I… | ISO/SAE 21434 product certification for MICROSAR HSM firmware (exida, June 2025), Cybersecurity Management System (CSMS) certification |
| VicOne | 2022 | Subscription (custom) | OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an… | ISO/SAE 21434, UNECE R155, Automotive SPICE (ASPICE) Level 2 |
| VxLabs | 2022 | Subscription for the ThreatZ platform; time and materials, fixed price or retainer for engineering services | OEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace,… | — |
Sources: Regulation (EU) 2019/2144, Annex II; TÜV SÜD: China implements vehicle cybersecurity technical requirements (GB 44495-2024) (January 2026); Upstream Security: ransomware attacks on automotive and smart mobility more than doubled in 2025 (18 February 2026); Zero Day Initiative: Pwn2Own Automotive 2026, day three results (January 2026).
By use case
Our read on which firm suits which job. Editorial, not paid, and separate from the alphabetical listing below.
Cloud-scale fleet monitoring
Upstream Security
Agentless and cloud-native, pairing a V-XDR platform with a managed 24/7 Vehicle SOC and dedicated threat intelligence for connected fleets.
Cloud
Lifecycle platform coverage
VicOne
A single-vendor portfolio spanning in-vehicle IDPS, a vehicle SOC, threat intelligence and SBOM, backed by parent Trend Micro and the Zero Day Initiative.
Cloud, Self-hosted
Looking specifically for vehicle pen testing? Read our deep-dive on automotive penetration testing. Scope, standards, Pwn2Own, and the firms doing the research.
Automotive Pen Testing guide →PCA Cyber Security
Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Capabilities
- Payment-device penetration testing (POS, PIN pads, unattended terminals)
- Fuel-pump and EV-charging payment system testing
- Embedded and IoT device security testing
- Automotive security testing and research
- PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
- Security assessments and continuous monitoring
- Software composition analysis and SBOM validation by firmware reverse engineering
- Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
- Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
- Vehicle and product threat intelligence
- Product Security Operations Center (PSOC) / Vehicle SOC monitoring
- Threat Analysis and Risk Assessment (TARA)
- Cybersecurity verification and validation (V&V) services
- Remote attack surface analysis (mobile apps, backend APIs, cloud)
- Security assessments supporting ISO/SAE 21434 compliance
- UNECE R155 cybersecurity assessment support
- Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
- Vulnerability research and coordinated responsible disclosure
- ICS and OT penetration testing (SCADA, PLCs, industrial networks)
- Medical device penetration testing
- Railway penetration testing (signalling, communication and control networks)
- Application penetration testing (web, mobile and cloud)
Certifications
TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155
Sources
- PCA Payment Device Penetration Testing
- PCA Cyber Security joins PCI SSC as APO
- PCA: software composition analysis and SBOM validation service
- PCA Cyber Security: TISAX AL3, PCI SSC APO, Pwn2Own Automotive 2024 and 2025, conference speaking
- PCA Cyber Security: penetration testing services
- PCA Cervus platform
PCA Cyber Security
PCI PTS Compliance Testing CompaniesManufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Upstream Security
Automotive CybersecurityOEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets
Upstream Security operates a cloud-native, agentless AI platform purpose-built for connected vehicles and mobility IoT. It ingests telematics, OTA, diagnostic, and dealership data to deliver cybersecurity detection and response (V-XDR), automotive threat intelligence, and data-driven applications. Upstream pairs its platform with a managed 24/7 Vehicle Security Operations Center and monitors tens of millions of vehicles, making it one of the largest-scale players in connected-vehicle security. Because it works server-side without in-vehicle agents, it is typically deployed alongside embedded ECU protection rather than replacing it.
Vector Informatik
Automotive CybersecurityAutomotive OEMs and Tier 1 suppliers needing production-grade ECU security software and ISO 21434 verification tooling inside an existing AUTOSAR toolchain.
Vector Informatik is a Stuttgart-based automotive software and tooling company founded in 1988, whose portfolio includes embedded cybersecurity components for electronic control units. Its MICROSAR HSM firmware provides secure boot, secure key storage and cryptographic services on ECU hardware security modules, and was certified to ISO/SAE 21434 by test house exida in June 2025. The MICROSAR Classic basic software includes a crypto stack with drivers for SHE and HSM trust anchors and the AUTOSAR Key Manager for in-vehicle key and certificate handling. On the verification side, vTESTstudio provides fuzz test design executed in CANoe, and Vector Consulting Services delivers TARA, ISO/SAE 21434 and UNECE R155 work.
VicOne
Automotive CybersecurityOEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent
VicOne is a wholly-owned subsidiary of Trend Micro dedicated exclusively to automotive cybersecurity for connected and electric vehicles. It leverages Trend Micro's 30-plus years of security expertise and the Zero Day Initiative's vulnerability research network. The same program behind Pwn2Own Automotive. To give OEMs and suppliers lifecycle protection from development and production through in-vehicle operation. Its portfolio covers an in-vehicle IDPS, a managed VSOC, threat intelligence, SBOM and vulnerability management, and penetration testing services.
VxLabs
Automotive CybersecurityOEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace, or project-based automotive security engineering.
VxLabs is an automotive cybersecurity and embedded software company founded in January 2022, registered in Regensburg, Germany (HRB 19099) with a US entity in Delaware. Its platform, ThreatZ, is an AWS-hosted SaaS launched in October 2025 that links system modelling, TARA, SBOM, vulnerability management, incident handling and compliance evidence in a single knowledge graph for ISO/SAE 21434 and UNECE R155. The company also sells engineering services covering AUTOSAR Classic and Adaptive ECU development, penetration testing, CSMS consulting and R155 type approval support. Uraeus was the earlier platform brand and uraeus.io now redirects to vxlabs.ai.
Related guides
Other categories you might be evaluating alongside automotive cybersecurity.
Shortlists
Editorial lists and deep dives from this category.
About this listing
Automotive Cybersecurity companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →