Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

Automotive Cybersecurity: 5 Companies compared

Automotive cybersecurity companies protect connected and software-defined vehicles across their lifecycle, from ECUs, in-vehicle networks and telematics to cloud backends, fleets and EV charging. This guide compares the firms that OEMs and suppliers rely on for penetration testing, in-vehicle protection, managed vehicle SOC monitoring, and ISO/SAE 21434 and UNECE R155 compliance.

5 companies|Updated September 2026

5 Automotive Cybersecurity Companies, side by side

Featured listings are paid placements.

CompanyFoundedEngagementSpecialismStandards / accreditations
PCA Cyber SecurityFeatured2019Project-based engagementsManufacturers and operators of payment devices, vehicles, industrial systems and other em…TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434
Upstream Security2017Subscription (custom)OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle…ISO/SAE 21434, UNECE R155, UNECE R156
Vector Informatik1988Quote-based licensing for embedded software and tools, with separate fees for consulting and trainingAutomotive OEMs and Tier 1 suppliers needing production-grade ECU security software and I…ISO/SAE 21434 product certification for MICROSAR HSM firmware (exida, June 2025), Cybersecurity Management System (CSMS) certification
VicOne2022Subscription (custom)OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an…ISO/SAE 21434, UNECE R155, Automotive SPICE (ASPICE) Level 2
VxLabs2022Subscription for the ThreatZ platform; time and materials, fixed price or retainer for engineering servicesOEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace,…—

Sources: Regulation (EU) 2019/2144, Annex II; TÜV SÜD: China implements vehicle cybersecurity technical requirements (GB 44495-2024) (January 2026); Upstream Security: ransomware attacks on automotive and smart mobility more than doubled in 2025 (18 February 2026); Zero Day Initiative: Pwn2Own Automotive 2026, day three results (January 2026).

By use case

Our read on which firm suits which job. Editorial, not paid, and separate from the alphabetical listing below.

Cloud-scale fleet monitoring

Upstream Security

Agentless and cloud-native, pairing a V-XDR platform with a managed 24/7 Vehicle SOC and dedicated threat intelligence for connected fleets.

Cloud

Lifecycle platform coverage

VicOne

A single-vendor portfolio spanning in-vehicle IDPS, a vehicle SOC, threat intelligence and SBOM, backed by parent Trend Micro and the Zero Day Initiative.

Cloud, Self-hosted

Looking specifically for vehicle pen testing? Read our deep-dive on automotive penetration testing. Scope, standards, Pwn2Own, and the firms doing the research.

Automotive Pen Testing guide →

PCA Cyber Security

Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy

Founded
2019
Pricing
Project-based engagements
Deployment
Cloud
Certifications
TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Capabilities

  • Payment-device penetration testing (POS, PIN pads, unattended terminals)
  • Fuel-pump and EV-charging payment system testing
  • Embedded and IoT device security testing
  • Automotive security testing and research
  • PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
  • Security assessments and continuous monitoring
  • Software composition analysis and SBOM validation by firmware reverse engineering
  • Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
  • Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
  • Vehicle and product threat intelligence
  • Product Security Operations Center (PSOC) / Vehicle SOC monitoring
  • Threat Analysis and Risk Assessment (TARA)
  • Cybersecurity verification and validation (V&V) services
  • Remote attack surface analysis (mobile apps, backend APIs, cloud)
  • Security assessments supporting ISO/SAE 21434 compliance
  • UNECE R155 cybersecurity assessment support
  • Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
  • Vulnerability research and coordinated responsible disclosure
  • ICS and OT penetration testing (SCADA, PLCs, industrial networks)
  • Medical device penetration testing
  • Railway penetration testing (signalling, communication and control networks)
  • Application penetration testing (web, mobile and cloud)

Certifications

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

PCA Cyber Security

PCI PTS Compliance Testing Companies
Best fit for

Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Founded

2019

Engagement

Project-based engagements

Standards & accreditations

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

Upstream Security

Automotive Cybersecurity
Best fit for

OEMs and fleet operators that want cloud-scale detection, response, and a managed Vehicle SOC for connected fleets

Upstream Security operates a cloud-native, agentless AI platform purpose-built for connected vehicles and mobility IoT. It ingests telematics, OTA, diagnostic, and dealership data to deliver cybersecurity detection and response (V-XDR), automotive threat intelligence, and data-driven applications. Upstream pairs its platform with a managed 24/7 Vehicle Security Operations Center and monitors tens of millions of vehicles, making it one of the largest-scale players in connected-vehicle security. Because it works server-side without in-vehicle agents, it is typically deployed alongside embedded ECU protection rather than replacing it.

Founded

2017

Engagement

Subscription (custom)

Standards & accreditations

ISO/SAE 21434, UNECE R155, UNECE R156

Vector Informatik

Automotive Cybersecurity
Best fit for

Automotive OEMs and Tier 1 suppliers needing production-grade ECU security software and ISO 21434 verification tooling inside an existing AUTOSAR toolchain.

Vector Informatik is a Stuttgart-based automotive software and tooling company founded in 1988, whose portfolio includes embedded cybersecurity components for electronic control units. Its MICROSAR HSM firmware provides secure boot, secure key storage and cryptographic services on ECU hardware security modules, and was certified to ISO/SAE 21434 by test house exida in June 2025. The MICROSAR Classic basic software includes a crypto stack with drivers for SHE and HSM trust anchors and the AUTOSAR Key Manager for in-vehicle key and certificate handling. On the verification side, vTESTstudio provides fuzz test design executed in CANoe, and Vector Consulting Services delivers TARA, ISO/SAE 21434 and UNECE R155 work.

Founded

1988

Engagement

Quote-based licensing for embedded software and tools, with separate fees for consulting and training

Standards & accreditations

ISO/SAE 21434 product certification for MICROSAR HSM firmware (exida, June 2025), Cybersecurity Management System (CSMS) certification

VicOne

Automotive Cybersecurity
Best fit for

OEMs and suppliers wanting a broad, lifecycle automotive security portfolio backed by an established cybersecurity parent

VicOne is a wholly-owned subsidiary of Trend Micro dedicated exclusively to automotive cybersecurity for connected and electric vehicles. It leverages Trend Micro's 30-plus years of security expertise and the Zero Day Initiative's vulnerability research network. The same program behind Pwn2Own Automotive. To give OEMs and suppliers lifecycle protection from development and production through in-vehicle operation. Its portfolio covers an in-vehicle IDPS, a managed VSOC, threat intelligence, SBOM and vulnerability management, and penetration testing services.

Founded

2022

Engagement

Subscription (custom)

Standards & accreditations

ISO/SAE 21434, UNECE R155, Automotive SPICE (ASPICE) Level 2, TISAX Assessment Level 3

VxLabs

Automotive Cybersecurity
Best fit for

OEM and Tier 1 teams wanting an integrated TARA, SBOM and compliance evidence workspace, or project-based automotive security engineering.

VxLabs is an automotive cybersecurity and embedded software company founded in January 2022, registered in Regensburg, Germany (HRB 19099) with a US entity in Delaware. Its platform, ThreatZ, is an AWS-hosted SaaS launched in October 2025 that links system modelling, TARA, SBOM, vulnerability management, incident handling and compliance evidence in a single knowledge graph for ISO/SAE 21434 and UNECE R155. The company also sells engineering services covering AUTOSAR Classic and Adaptive ECU development, penetration testing, CSMS consulting and R155 type approval support. Uraeus was the earlier platform brand and uraeus.io now redirects to vxlabs.ai.

Founded

2022

Engagement

Subscription for the ThreatZ platform; time and materials, fixed price or retainer for engineering services

Related guides

Other categories you might be evaluating alongside automotive cybersecurity.

Shortlists

Editorial lists and deep dives from this category.

About this listing

Automotive Cybersecurity companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →

Frequently Asked Questions

Automotive cybersecurity protects vehicles and the systems around them from cyber attacks. It spans the electronic control units (ECUs) and in-vehicle networks inside the car, the telematics and connectivity that link it to the outside world, the cloud backends and mobile apps that serve it, and the EV charging and fleet infrastructure it depends on. Specialist firms provide a mix of penetration testing, embedded protection software, managed monitoring, and compliance tooling.

ISO/SAE 21434 is the international standard for cybersecurity engineering of road vehicles. It defines how manufacturers and suppliers manage cyber risk across a vehicle's lifecycle. UN Regulation No 155 makes an approved cybersecurity management system a condition of vehicle type approval. In the EU it has applied to new vehicle types since 6 July 2022 and to all newly registered vehicles since 7 July 2024.

Yes. GB 44495-2024, released on 23 August 2024, sets China's technical requirements for vehicle cybersecurity, including a cybersecurity management system, risk assessment and testing. It has applied to new type approval applications since 1 January 2026, and vehicles that are already type-approved must meet it from 1 January 2028.

It depends on where your risk and resources sit. Embedded products such as intrusion detection agents and ECU runtime protection defend the vehicle itself but require integration into hardware. Cloud platforms and managed Vehicle SOCs detect and respond to threats across a connected fleet without an in-vehicle footprint. Penetration testing and TARA services validate security before and after launch. Most mature programs combine all three rather than picking one.

The primary buyers are vehicle manufacturers (OEMs) and Tier-1 suppliers that must meet type-approval requirements and secure increasingly software-defined vehicles. Fleet operators, EV charging networks, insurers, and connected-device manufacturers also use these firms, since the same embedded and connected-system risks apply well beyond passenger cars.