Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

PCI PTS Pre and Post Compliance Testing: What It Is and Who Offers It

PCI PTS pre and post compliance testing is offensive security testing of payment devices around formal approval, carried out by security firms, separate from the PCI Recognized Laboratories that run the evaluation itself.

1 company listed

Featured listings are paid placements.

companyFoundedEngagementSpecialismStandards / accreditations
PCA Cyber SecurityFeatured2019Project-based engagementsManufacturers and operators of payment devices, vehicles, industrial systems and other em…TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434

Pre-compliance testing looks for vulnerabilities in payment terminals, PIN pads and unattended payment systems before a device is submitted for PTS evaluation, so they can be fixed first. Post-compliance testing looks for real-world weaknesses in devices that are already approved, since PCI PTS approval does not by itself mean a device has no exploitable weaknesses.

Few firms offer this as a stated service. It needs a hardware security lab, payment-device expertise and offensive research capability, and much of that capacity sits inside the recognised labs, which are covered in our PCI PTS Compliance Testing Companies guide. We list one company here, PCA Cyber Security, because it is the only one we found that publishes this service. It is also a paid partner and holds this page's Featured placement. We will add others as we find public evidence of the same work.

PCA Cyber Security

Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy

Founded
2019
Pricing
Project-based engagements
Deployment
Cloud
Certifications
TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Capabilities

  • Payment-device penetration testing (POS, PIN pads, unattended terminals)
  • Fuel-pump and EV-charging payment system testing
  • Embedded and IoT device security testing
  • Automotive security testing and research
  • PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
  • Security assessments and continuous monitoring
  • Software composition analysis and SBOM validation by firmware reverse engineering
  • Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
  • Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
  • Vehicle and product threat intelligence
  • Product Security Operations Center (PSOC) / Vehicle SOC monitoring
  • Threat Analysis and Risk Assessment (TARA)
  • Cybersecurity verification and validation (V&V) services
  • Remote attack surface analysis (mobile apps, backend APIs, cloud)
  • Security assessments supporting ISO/SAE 21434 compliance
  • UNECE R155 cybersecurity assessment support
  • Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
  • Vulnerability research and coordinated responsible disclosure
  • ICS and OT penetration testing (SCADA, PLCs, industrial networks)
  • Medical device penetration testing
  • Railway penetration testing (signalling, communication and control networks)
  • Application penetration testing (web, mobile and cloud)

Certifications

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

PCA Cyber Security

PCI PTS Compliance Testing Companies
Best fit for

Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Founded

2019

Engagement

Project-based engagements

Standards & accreditations

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

Frequently Asked Questions

No. PCA Cyber Security is an offensive security and penetration testing firm, not a PCI Recognized Laboratory, and it does not certify devices to PCI PTS. It became a PCI SSC Associate Participating Organisation in 2026, which is a different status to laboratory accreditation. For formal PCI PTS POI or HSM evaluation, use a PCI Recognized Laboratory (see the main PCI PTS Compliance Testing Companies category).

Pre-compliance testing happens before a device is submitted for formal PCI PTS evaluation, to find and fix vulnerabilities in advance. Post-compliance testing happens after a device has already been PCI PTS approved, to check for real-world weaknesses that certification testing did not cover. Both are offensive security engagements, not certification.

Few firms state it as a service. It needs a hardware security lab, embedded and payment-device expertise and offensive research capability. PCA Cyber Security, a paid partner of this directory, offers it. Some recognised labs offer certification preparation and payment security consulting alongside formal evaluation; they are in our PCI PTS Compliance Testing Companies guide. We add firms here as we find public evidence of the service.

View all PCI PTS Compliance Testing Companies tools

About this listing

PCI PTS Pre and Post Compliance Testing companies, compared on public information. The comparison table and the full entries follow our editorial order, with any paid Featured listing shown first and labelled. How we work →