Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

PCA Cyber Security vs VxLabs

PCA Cyber Security

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Pros
  • Elite offensive research talent. Repeat Pwn2Own Automotive contestants in 2024 and 2025
  • Proven track record of high-impact disclosed vehicle research (Skoda/VW, Nissan Leaf)
  • Deep hands-on embedded and hardware expertise via dedicated lab facilities
  • TISAX Assessment Level 3 with protection of prototype parts; speakers at Black Hat, Hexacon, Escar and Hacktivity
  • Registered PCI SSC Associate Participating Organization, taking part in PCI SSC Community Meetings

Pricing: Project-based; contact for an engagement.

VxLabs

VxLabs is an automotive cybersecurity and embedded software company founded in January 2022, registered in Regensburg, Germany (HRB 19099) with a US entity in Delaware. Its platform, ThreatZ, is an AWS-hosted SaaS launched in October 2025 that links system modelling, TARA, SBOM, vulnerability management, incident handling and compliance evidence in a single knowledge graph for ISO/SAE 21434 and UNECE R155. The company also sells engineering services covering AUTOSAR Classic and Adaptive ECU development, penetration testing, CSMS consulting and R155 type approval support. Uraeus was the earlier platform brand and uraeus.io now redirects to vxlabs.ai.

Pros
  • Registered operating company with a German commercial register entry (HRB 19099, Regensburg) and a separate US entity
  • The ThreatZ launch in October 2025 was covered by independent automotive trade press including Telematics Wire
  • Scope is automotive specific throughout, built around ISO/SAE 21434 and UNECE R155 rather than repackaged general IT security
  • Publishes concrete engagement models (time and materials, fixed price, managed-service retainer) and a defined delivery process

Pricing: