PCA Cyber Security
Payment-device and embedded penetration testing firm; tests payment terminals beyond PCI PTS certification.
Pricing: Project-based; contact for an engagement.
Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings
What is PCA Cyber Security?
PCA Cyber Security is a Munich-based penetration-testing and security-research firm with a dedicated payment-device practice. It performs real-world security testing of payment terminals, PIN pads, unattended and self-service terminals, and fuel-pump and EV-charging payment systems, testing beyond PCI PTS certification to find vulnerabilities even in approved devices. PCA became a PCI SSC Associate Participating Organisation in 2026 and also runs a strong automotive and embedded security practice. PCA also offers software composition analysis and SBOM validation, reverse-engineering device firmware rather than relying on vendor documentation or an existing SBOM. The vendor describes reconstructing a verified component inventory from the firmware binary, mapping dependencies against runtime behaviour, surfacing undocumented components and mapping findings to CVEs, delivered as an extended bill of materials (xBOM). The service targets payment and financial devices including PTS terminals, smart POS, mPOS and ATMs, alongside automotive ECUs, kiosks, fuel pumps and EV charging interfaces.
Key Features
Are you PCA Cyber Security? Improve this listing with screenshots, case studies and more.
Sources & references
Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.
Spot an error, or do you represent PCA Cyber Security? Request a correction.
Quick Info
| Pricing | Project-based; contact for an engagement. |
| Model | Project-based engagements |
| Founded | 2019 |
| Cloud | No |
| Self-Hosted | No |
Last updated: Aug 19, 2026