PCA Cyber Security

Payment-device and embedded penetration testing firm; tests payment terminals beyond PCI PTS certification.

companyPCI PTS Compliance Testing Companies

Pricing: Project-based; contact for an engagement.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed August 2026 · How we review listings

What is PCA Cyber Security?

PCA Cyber Security is a Munich-based penetration-testing and security-research firm with a dedicated payment-device practice. It performs real-world security testing of payment terminals, PIN pads, unattended and self-service terminals, and fuel-pump and EV-charging payment systems, testing beyond PCI PTS certification to find vulnerabilities even in approved devices. PCA became a PCI SSC Associate Participating Organisation in 2026 and also runs a strong automotive and embedded security practice. PCA also offers software composition analysis and SBOM validation, reverse-engineering device firmware rather than relying on vendor documentation or an existing SBOM. The vendor describes reconstructing a verified component inventory from the firmware binary, mapping dependencies against runtime behaviour, surfacing undocumented components and mapping findings to CVEs, delivered as an extended bill of materials (xBOM). The service targets payment and financial devices including PTS terminals, smart POS, mPOS and ATMs, alongside automotive ECUs, kiosks, fuel pumps and EV charging interfaces.

Best for: Payment-device makers and operators wanting offensive, real-world security testing of terminals beyond baseline PCI PTS certification

Key Features

Payment-device penetration testing (POS, PIN pads, unattended terminals)
Fuel-pump and EV-charging payment system testing
Embedded and IoT device security testing
Automotive security testing and research
Threat intelligence (TICAP platform)
Security assessments and continuous monitoring
Software composition analysis and SBOM validation by firmware reverse engineering
Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation

Are you PCA Cyber Security? Improve this listing with screenshots, case studies and more.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent PCA Cyber Security? Request a correction.

Quick Info
PricingProject-based; contact for an engagement.
ModelProject-based engagements
Founded2019
CloudNo
Self-HostedNo

Last updated: Aug 19, 2026