PCA Cyber Security vs Vector Informatik
PCA Cyber Security
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Pros
- Elite offensive research talent. Repeat Pwn2Own Automotive contestants in 2024 and 2025
- Proven track record of high-impact disclosed vehicle research (Skoda/VW, Nissan Leaf)
- Deep hands-on embedded and hardware expertise via dedicated lab facilities
- TISAX Assessment Level 3 with protection of prototype parts; speakers at Black Hat, Hexacon, Escar and Hacktivity
- Registered PCI SSC Associate Participating Organization, taking part in PCI SSC Community Meetings
Pricing: Project-based; contact for an engagement.
Vector Informatik
Vector Informatik is a Stuttgart-based automotive software and tooling company founded in 1988, whose portfolio includes embedded cybersecurity components for electronic control units. Its MICROSAR HSM firmware provides secure boot, secure key storage and cryptographic services on ECU hardware security modules, and was certified to ISO/SAE 21434 by test house exida in June 2025. The MICROSAR Classic basic software includes a crypto stack with drivers for SHE and HSM trust anchors and the AUTOSAR Key Manager for in-vehicle key and certificate handling. On the verification side, vTESTstudio provides fuzz test design executed in CANoe, and Vector Consulting Services delivers TARA, ISO/SAE 21434 and UNECE R155 work.
Pros
- MICROSAR HSM firmware holds a product-level ISO/SAE 21434 certificate issued by exida in June 2025, rather than only an organisational process certificate
- Security functions ship inside an AUTOSAR basic software stack already used in series ECU development, so they fit an existing production toolchain
- Covers both the build side (embedded crypto stack, key management, HSM firmware) and the verification side (fuzz testing in vTESTstudio and CANoe)
- Vector Group reported roughly 4,000 employees and EUR 1.16bn revenue for 2023, indicating a stable long-term supplier
Pricing: