Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

PCA Cyber Security

Featured

Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy

CompanyPCI PTS Compliance Testing CompaniesCloudVendor-verified

Pricing: Project-based; contact for an engagement.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below and information provided directly by the vendor · Last reviewed September 2026 · How we review listings

What is PCA Cyber Security?

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Best for: Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434

Pros

  • Elite offensive research talent. Repeat Pwn2Own Automotive contestants in 2024 and 2025
  • Proven track record of high-impact disclosed vehicle research (Skoda/VW, Nissan Leaf)
  • Deep hands-on embedded and hardware expertise via dedicated lab facilities
  • TISAX Assessment Level 3 with protection of prototype parts; speakers at Black Hat, Hexacon, Escar and Hacktivity
  • Registered PCI SSC Associate Participating Organization, taking part in PCI SSC Community Meetings

Key Features

Payment-device penetration testing (POS, PIN pads, unattended terminals)
Fuel-pump and EV-charging payment system testing
Embedded and IoT device security testing
Automotive security testing and research
PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
Security assessments and continuous monitoring
Software composition analysis and SBOM validation by firmware reverse engineering
Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
Vehicle and product threat intelligence
Product Security Operations Center (PSOC) / Vehicle SOC monitoring
Threat Analysis and Risk Assessment (TARA)
Cybersecurity verification and validation (V&V) services
Remote attack surface analysis (mobile apps, backend APIs, cloud)
Security assessments supporting ISO/SAE 21434 compliance
UNECE R155 cybersecurity assessment support
Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
Vulnerability research and coordinated responsible disclosure
ICS and OT penetration testing (SCADA, PLCs, industrial networks)
Medical device penetration testing
Railway penetration testing (signalling, communication and control networks)
Application penetration testing (web, mobile and cloud)

Add the Cyber Vendor Guide badge to your site

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent PCA Cyber Security? Request a correction.

Key facts

Pricing
Project-based; contact for an engagement.
Model
Project-based engagements
Founded
2019
Cloud
Yes
Self-hosted
No

PCA Cyber Security Alternatives

  • Upstream SecurityCloud-based, agentless connected-vehicle cybersecurity platf...
  • VicOneTrend Micro subsidiary delivering end-to-end automotive cybe...
  • Vector InformatikAutomotive embedded security stacks, fuzz testing tools and ...
  • VxLabsAutomotive TARA, SBOM and compliance platform plus security ...
View all alternatives

Certifications

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155