PCA Cervus

Featured

Device-by-device vulnerability monitoring for embedded products, from supplier SBOMs to patch validation

ToolSBOM AnalysisVendor-verified

Pricing: Pricing is not published.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below and information provided directly by the vendor · Last reviewed September 2026 · How we review listings

What is PCA Cervus?

PCA Cervus is a device-centric vulnerability monitoring and threat intelligence platform for embedded and connected products, made by PCA Cyber Security, the Budapest-based product security firm. PCA describes the workflow in six steps: upload an SBOM, Cervus validates the software components, new vulnerabilities are detected, affected products are identified, risk is prioritised and engineering is notified. It validates supplier SBOMs or generates them, models each device from its components, and correlates vulnerability and threat intelligence with those components, so the picture is built around the product rather than around individual CVEs. Monitoring continues after a product is released or certified, and PCA supports remediation through to patch validation. Compliance reporting covers the Cyber Resilience Act, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031. Cervus imports existing SBOMs, integrates with ticketing systems and exports data, and PCA says its AI-assisted analysis uses self-hosted models so product information stays under the customer's control. It is aimed at manufacturers, importers and operators of embedded products in payment, automotive, industrial, energy, medical and consumer IoT markets. PCA says the platform was developed with its offensive security researchers. Pricing and deployment options are not published.

Best for: Manufacturers, importers and operators of embedded and connected products in payment, automotive, industrial and IoT markets that need to track vulnerabilities device by device against supplier SBOMs and produce evidence for regulations such as the Cyber Resilience Act, PCI PTS and UNECE R155

Key Features

Import of existing and supplier SBOMs, with validation of the software components
SBOM validation and/or generation for embedded products
Device-centric model: each product's components are correlated with vulnerability and threat intelligence
Continuous monitoring for new vulnerabilities, exploits and threats after release or certification, identifying the affected products
Prioritisation of exploitable vulnerabilities rather than every CVE
Remediation support through to patch validation, with engineering notified through ticketing integrations
Compliance reports and evidence for the CRA, PCI PTS, PCI DSS, UNECE R155, ISO/SAE 21434, IEC 62443-4-2 and RED / EN 18031
AI-assisted analysis using self-hosted models, per PCA
Monitoring of threats targeting company secrets, infrastructure and code

Know what's in your products. Stay ahead of cyber risk.

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent PCA Cervus? Request a correction.

Key facts

Pricing
Pricing is not published.
Founded
2019

Where PCA Cervus appears

Guides