PCI PTS Compliance Testing Companies: 6 companies compared
The requirements moved on in 2026. PCI PTS POI version 7.0, published on 29 May 2025 with 59 requirement changes, is now the only version open to new device approvals: version 6 closed to them on 30 June 2026, and devices already approved under it keep their approval until April 2032. Version 5 devices were due to expire on 30 April 2026, but the PCI Security Standards Council extended them to 30 April 2027, citing deployment problems such as constrained hardware supply. No new version 5 approvals are possible.
Payments taken on phones and tablets follow separate standards. The Council has set a sunset period of 1 May to 31 October 2026 for its Contactless Payments on COTS (CPoC) standard and points vendors to the newer Mobile Payments on COTS (MPoC) standard. Four of the five labs listed here are recognised for both PTS and these mobile programmes; Keysight's Riscure lab is recognised for SPoC, CPoC and MPoC only.
Any lab's recognition can be checked on the Council's public list of PCI Recognized Laboratories. The accreditations below were checked against it on 30 September 2026.
6 PCI PTS Compliance Testing Companies, side by side
Featured listings are paid placements.
| company | Founded | Engagement | Specialism | Standards / accreditations |
|---|---|---|---|---|
| PCA Cyber SecurityFeatured | 2019 | Project-based engagements | Manufacturers and operators of payment devices, vehicles, industrial systems and other em… | TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434 |
| Keysight (Riscure Device Security) | — | Project-based engagements | Payment device, terminal and mobile payment vendors needing accredited EMVCo or PCI secur… | PCI Recognized Laboratory (SPoC, CPoC, MPoC), EMVCo accredited security laboratory (SBMP) |
| SERMA Safety & Security | — | Project-based engagements | Manufacturers needing PCI PTS and payment-acceptance device evaluation from an accredited… | PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC, 3DS SDK), EMVCo, Common Criteria |
| SGS Brightsight | — | Project-based engagements | Payment terminal and HSM manufacturers needing formal PCI PTS, EMVCo or Common Criteria e… | PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC, 3DS SDK), EMVCo, Common Criteria |
| SRC Security Research & Consulting | — | Project-based engagements | Manufacturers needing PCI PTS plus German DK/OSeC/JTEMS terminal evaluation | PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC) |
| UL Solutions | — | Project-based engagements | Manufacturers needing PCI PTS and EMVCo evaluation from a large, globally accredited lab | PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC), EMVCo |
Accreditations are checked against the PCI Security Standards Council's list of recognised laboratories, 30 September 2026. Sources: PCI SSC: PCI Recognized Laboratories; PCI SSC: Just published, PTS POI v7.0 (29 May 2025); PCI SSC bulletin: extension of PTS POI v6 requirements and approvals (17 June 2025); PCI SSC bulletin: extension of expiration of PTS POI v5 devices (11 September 2025); PCI SSC: Contactless Payments on COTS (CPoC).
PCA Cyber Security
Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Capabilities
- Payment-device penetration testing (POS, PIN pads, unattended terminals)
- Fuel-pump and EV-charging payment system testing
- Embedded and IoT device security testing
- Automotive security testing and research
- PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
- Security assessments and continuous monitoring
- Software composition analysis and SBOM validation by firmware reverse engineering
- Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
- Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
- Vehicle and product threat intelligence
- Product Security Operations Center (PSOC) / Vehicle SOC monitoring
- Threat Analysis and Risk Assessment (TARA)
- Cybersecurity verification and validation (V&V) services
- Remote attack surface analysis (mobile apps, backend APIs, cloud)
- Security assessments supporting ISO/SAE 21434 compliance
- UNECE R155 cybersecurity assessment support
- Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
- Vulnerability research and coordinated responsible disclosure
- ICS and OT penetration testing (SCADA, PLCs, industrial networks)
- Medical device penetration testing
- Railway penetration testing (signalling, communication and control networks)
- Application penetration testing (web, mobile and cloud)
Certifications
TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155
Sources
- PCA Payment Device Penetration Testing
- PCA Cyber Security joins PCI SSC as APO
- PCA: software composition analysis and SBOM validation service
- PCA Cyber Security: TISAX AL3, PCI SSC APO, Pwn2Own Automotive 2024 and 2025, conference speaking
- PCA Cyber Security: penetration testing services
- PCA Cervus platform
Keysight (Riscure Device Security)
PCI PTS Compliance Testing CompaniesPayment device, terminal and mobile payment vendors needing accredited EMVCo or PCI security evaluation of hardware and secure elements
Keysight's device vulnerability analysis business, built on its acquisition of the Dutch security lab Riscure, tests chips, smart cards and embedded devices using side-channel analysis and fault injection: introducing controlled faults through voltage, clock, electromagnetic or optical techniques to uncover weaknesses that let attackers bypass protections. It operates as an accredited EMVCo security laboratory for all products under the Software Based Mobile Payment (SBMP) programme, covering software protection tools, trusted execution environments, consumer device cardholder verification, OEM payment solutions and host card emulation, and the PCI Security Standards Council lists its Delft lab as a recognised laboratory for the SPoC, CPoC and MPoC mobile payment programmes, though not for PTS device evaluation. Keysight is a NYSE-listed test and measurement company headquartered in Santa Rosa, California.
PCA Cyber Security
PCI PTS Compliance Testing CompaniesManufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
SERMA Safety & Security
PCI PTS Compliance Testing CompaniesManufacturers needing PCI PTS and payment-acceptance device evaluation from an accredited European lab
SERMA Safety & Security is a French ITSEF/CESTI evaluation lab that assesses security products from chip to full system, evaluating more than 200 products a year. It is a PCI Recognized Laboratory for PTS payment acceptance devices and for the SPoC, CPoC, MPoC and 3DS SDK programmes and is accredited for EMVCo and Common Criteria. Headquartered near Bordeaux, France.
SGS Brightsight
PCI PTS Compliance Testing CompaniesPayment terminal and HSM manufacturers needing formal PCI PTS, EMVCo or Common Criteria evaluation
Brightsight, part of SGS, is one of the largest security evaluation laboratories for payment and chip technology. It is a PCI Recognized Laboratory for the PTS, SPoC, CPoC, MPoC and 3DS SDK programmes and an accredited EMVCo and Common Criteria lab, having completed hundreds of PCI PTS device approvals for terminal and HSM makers worldwide. Headquartered in Delft, Netherlands.
SRC Security Research & Consulting
PCI PTS Compliance Testing CompaniesManufacturers needing PCI PTS plus German DK/OSeC/JTEMS terminal evaluation
SRC Security Research & Consulting is a German PCI Recognized test lab performing PCI PTS device evaluations alongside German DK, OSeC and JTEMS payment terminal evaluations. The PCI Security Standards Council also lists it as recognised for the SPoC, CPoC and MPoC mobile payment programmes. Headquartered in Bonn, Germany.
UL Solutions
PCI PTS Compliance Testing CompaniesManufacturers needing PCI PTS and EMVCo evaluation from a large, globally accredited lab
UL Solutions is a global testing, inspection and certification firm with a major payment-device security practice. It is a PCI Recognized Laboratory for PTS POI and HSM evaluation and for the SPoC, CPoC and MPoC mobile payment programmes, through its labs in Basingstoke and Guangzhou, and an EMVCo type-approval lab, and states it has supported approval of over a thousand payment terminals since the PTS program began. Headquartered in Northbrook, Illinois.
Related guides
Other categories you might be evaluating alongside pci pts compliance testing companies.
About this listing
PCI PTS Compliance Testing Companies companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →