Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

PCI PTS Compliance Testing Companies: 6 companies compared

Companies involved in PCI PTS compliance for payment devices fall into two distinct roles. PCI Recognized evaluation laboratories perform the formal PCI PTS POI and HSM evaluations (and related EMVCo terminal testing) that a device needs to become PCI PTS approved. Separately, offensive security firms test payment devices before and after that formal process, looking for real-world vulnerabilities that certification alone does not catch. These are not interchangeable: a PCI Recognized Lab is accredited to certify a device; an offensive security firm is not, and does not claim to be.

6 companies|Updated September 2026

6 PCI PTS Compliance Testing Companies, side by side

Featured listings are paid placements.

companyFoundedEngagementSpecialismStandards / accreditations
PCA Cyber SecurityFeatured2019Project-based engagementsManufacturers and operators of payment devices, vehicles, industrial systems and other em…TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434
Keysight (Riscure Device Security)—Project-based engagementsPayment device, terminal and mobile payment vendors needing accredited EMVCo or PCI secur…PCI Recognized Laboratory (SPoC, CPoC, MPoC), EMVCo accredited security laboratory (SBMP)
SERMA Safety & Security—Project-based engagementsManufacturers needing PCI PTS and payment-acceptance device evaluation from an accredited…PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC, 3DS SDK), EMVCo, Common Criteria
SGS Brightsight—Project-based engagementsPayment terminal and HSM manufacturers needing formal PCI PTS, EMVCo or Common Criteria e…PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC, 3DS SDK), EMVCo, Common Criteria
SRC Security Research & Consulting—Project-based engagementsManufacturers needing PCI PTS plus German DK/OSeC/JTEMS terminal evaluationPCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC)
UL Solutions—Project-based engagementsManufacturers needing PCI PTS and EMVCo evaluation from a large, globally accredited labPCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC), EMVCo

Accreditations are checked against the PCI Security Standards Council's list of recognised laboratories, 30 September 2026. Sources: PCI SSC: PCI Recognized Laboratories; PCI SSC: Just published, PTS POI v7.0 (29 May 2025); PCI SSC bulletin: extension of PTS POI v6 requirements and approvals (17 June 2025); PCI SSC bulletin: extension of expiration of PTS POI v5 devices (11 September 2025); PCI SSC: Contactless Payments on COTS (CPoC).

PCA Cyber Security

Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy

Founded
2019
Pricing
Project-based engagements
Deployment
Cloud
Certifications
TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Capabilities

  • Payment-device penetration testing (POS, PIN pads, unattended terminals)
  • Fuel-pump and EV-charging payment system testing
  • Embedded and IoT device security testing
  • Automotive security testing and research
  • PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
  • Security assessments and continuous monitoring
  • Software composition analysis and SBOM validation by firmware reverse engineering
  • Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
  • Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
  • Vehicle and product threat intelligence
  • Product Security Operations Center (PSOC) / Vehicle SOC monitoring
  • Threat Analysis and Risk Assessment (TARA)
  • Cybersecurity verification and validation (V&V) services
  • Remote attack surface analysis (mobile apps, backend APIs, cloud)
  • Security assessments supporting ISO/SAE 21434 compliance
  • UNECE R155 cybersecurity assessment support
  • Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
  • Vulnerability research and coordinated responsible disclosure
  • ICS and OT penetration testing (SCADA, PLCs, industrial networks)
  • Medical device penetration testing
  • Railway penetration testing (signalling, communication and control networks)
  • Application penetration testing (web, mobile and cloud)

Certifications

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

Keysight (Riscure Device Security)

PCI PTS Compliance Testing Companies
Best fit for

Payment device, terminal and mobile payment vendors needing accredited EMVCo or PCI security evaluation of hardware and secure elements

Keysight's device vulnerability analysis business, built on its acquisition of the Dutch security lab Riscure, tests chips, smart cards and embedded devices using side-channel analysis and fault injection: introducing controlled faults through voltage, clock, electromagnetic or optical techniques to uncover weaknesses that let attackers bypass protections. It operates as an accredited EMVCo security laboratory for all products under the Software Based Mobile Payment (SBMP) programme, covering software protection tools, trusted execution environments, consumer device cardholder verification, OEM payment solutions and host card emulation, and the PCI Security Standards Council lists its Delft lab as a recognised laboratory for the SPoC, CPoC and MPoC mobile payment programmes, though not for PTS device evaluation. Keysight is a NYSE-listed test and measurement company headquartered in Santa Rosa, California.

Engagement

Project-based engagements

Standards & accreditations

PCI Recognized Laboratory (SPoC, CPoC, MPoC), EMVCo accredited security laboratory (SBMP)

PCA Cyber Security

PCI PTS Compliance Testing Companies
Best fit for

Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Founded

2019

Engagement

Project-based engagements

Standards & accreditations

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

SERMA Safety & Security

PCI PTS Compliance Testing Companies
Best fit for

Manufacturers needing PCI PTS and payment-acceptance device evaluation from an accredited European lab

SERMA Safety & Security is a French ITSEF/CESTI evaluation lab that assesses security products from chip to full system, evaluating more than 200 products a year. It is a PCI Recognized Laboratory for PTS payment acceptance devices and for the SPoC, CPoC, MPoC and 3DS SDK programmes and is accredited for EMVCo and Common Criteria. Headquartered near Bordeaux, France.

Engagement

Project-based engagements

Standards & accreditations

PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC, 3DS SDK), EMVCo, Common Criteria

SGS Brightsight

PCI PTS Compliance Testing Companies
Best fit for

Payment terminal and HSM manufacturers needing formal PCI PTS, EMVCo or Common Criteria evaluation

Brightsight, part of SGS, is one of the largest security evaluation laboratories for payment and chip technology. It is a PCI Recognized Laboratory for the PTS, SPoC, CPoC, MPoC and 3DS SDK programmes and an accredited EMVCo and Common Criteria lab, having completed hundreds of PCI PTS device approvals for terminal and HSM makers worldwide. Headquartered in Delft, Netherlands.

Engagement

Project-based engagements

Standards & accreditations

PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC, 3DS SDK), EMVCo, Common Criteria

SRC Security Research & Consulting

PCI PTS Compliance Testing Companies
Best fit for

Manufacturers needing PCI PTS plus German DK/OSeC/JTEMS terminal evaluation

SRC Security Research & Consulting is a German PCI Recognized test lab performing PCI PTS device evaluations alongside German DK, OSeC and JTEMS payment terminal evaluations. The PCI Security Standards Council also lists it as recognised for the SPoC, CPoC and MPoC mobile payment programmes. Headquartered in Bonn, Germany.

Engagement

Project-based engagements

Standards & accreditations

PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC)

UL Solutions

PCI PTS Compliance Testing Companies
Best fit for

Manufacturers needing PCI PTS and EMVCo evaluation from a large, globally accredited lab

UL Solutions is a global testing, inspection and certification firm with a major payment-device security practice. It is a PCI Recognized Laboratory for PTS POI and HSM evaluation and for the SPoC, CPoC and MPoC mobile payment programmes, through its labs in Basingstoke and Guangzhou, and an EMVCo type-approval lab, and states it has supported approval of over a thousand payment terminals since the PTS program began. Headquartered in Northbrook, Illinois.

Engagement

Project-based engagements

Standards & accreditations

PCI Recognized Laboratory (PTS, SPoC, CPoC, MPoC), EMVCo

Related guides

Other categories you might be evaluating alongside pci pts compliance testing companies.

About this listing

PCI PTS Compliance Testing Companies companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →

Frequently Asked Questions

A PCI Recognized Laboratory is formally accredited by the PCI Security Standards Council to perform the PCI PTS POI or HSM evaluation a device needs to become PCI PTS approved. A payment-device penetration testing firm is not accredited to certify devices; instead it performs offensive security testing before a device goes through formal evaluation, or after approval, to find vulnerabilities that certification testing did not catch. Certification and offensive testing are complementary, not substitutes for each other.

If you need a device to be PCI PTS approved, you need a PCI Recognized Laboratory; there is no substitute. Many device makers additionally use an offensive security firm before submission, to catch and fix issues ahead of formal evaluation, or after approval, since PCI PTS certification does not guarantee a device is free of every real-world vulnerability.

Version 7.0. The PCI Security Standards Council published PTS POI v7.0 on 29 May 2025, and version 6 closed to new device approvals on 30 June 2026, so evaluations for new approvals now use v7.0.

Devices approved under PTS POI v5 now expire on 30 April 2027, after the Council extended the original date of 30 April 2026 by a year. No new v5 approvals are possible. Devices approved under v6 expire in April 2032, which was also extended by a year.

The Council has set a sunset period of 1 May to 31 October 2026 for the Contactless Payments on COTS (CPoC) standard. It points vendors to Mobile Payments on COTS (MPoC), the newer standard for accepting contactless payments and PINs on smartphones and other off-the-shelf devices.

The PCI Security Standards Council publishes a list of PCI Recognized Laboratories that shows which programmes each lab is recognised for, and a separate list of approved PTS devices. Both are on the Council's website.