PCI PTS Pre and Post Compliance Testing: What It Is and Who Offers It
PCI PTS pre and post compliance testing is offensive security testing of payment devices around formal approval, carried out by security firms, separate from the PCI Recognized Laboratories that run the evaluation itself.
1 company listed
Featured listings are paid placements.
| company | Founded | Engagement | Specialism | Standards / accreditations |
|---|---|---|---|---|
| PCA Cyber SecurityFeatured | 2019 | Project-based engagements | Manufacturers and operators of payment devices, vehicles, industrial systems and other em… | TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434 |
Pre-compliance testing looks for vulnerabilities in payment terminals, PIN pads and unattended payment systems before a device is submitted for PTS evaluation, so they can be fixed first. Post-compliance testing looks for real-world weaknesses in devices that are already approved, since PCI PTS approval does not by itself mean a device has no exploitable weaknesses.
Few firms offer this as a stated service. It needs a hardware security lab, payment-device expertise and offensive research capability, and much of that capacity sits inside the recognised labs, which are covered in our PCI PTS Compliance Testing Companies guide. We list one company here, PCA Cyber Security, because it is the only one we found that publishes this service. It is also a paid partner and holds this page's Featured placement. We will add others as we find public evidence of the same work.
PCA Cyber Security
Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Capabilities
- Payment-device penetration testing (POS, PIN pads, unattended terminals)
- Fuel-pump and EV-charging payment system testing
- Embedded and IoT device security testing
- Automotive security testing and research
- PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
- Security assessments and continuous monitoring
- Software composition analysis and SBOM validation by firmware reverse engineering
- Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
- Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
- Vehicle and product threat intelligence
- Product Security Operations Center (PSOC) / Vehicle SOC monitoring
- Threat Analysis and Risk Assessment (TARA)
- Cybersecurity verification and validation (V&V) services
- Remote attack surface analysis (mobile apps, backend APIs, cloud)
- Security assessments supporting ISO/SAE 21434 compliance
- UNECE R155 cybersecurity assessment support
- Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
- Vulnerability research and coordinated responsible disclosure
- ICS and OT penetration testing (SCADA, PLCs, industrial networks)
- Medical device penetration testing
- Railway penetration testing (signalling, communication and control networks)
- Application penetration testing (web, mobile and cloud)
Certifications
TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155
Sources
- PCA Payment Device Penetration Testing
- PCA Cyber Security joins PCI SSC as APO
- PCA: software composition analysis and SBOM validation service
- PCA Cyber Security: TISAX AL3, PCI SSC APO, Pwn2Own Automotive 2024 and 2025, conference speaking
- PCA Cyber Security: penetration testing services
- PCA Cervus platform
PCA Cyber Security
PCI PTS Compliance Testing CompaniesManufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Frequently Asked Questions
About this listing
PCI PTS Pre and Post Compliance Testing companies, compared on public information. The comparison table and the full entries follow our editorial order, with any paid Featured listing shown first and labelled. How we work →