Vector Informatik vs PCA Cyber Security

Vector Informatik

Vector Informatik is a Stuttgart-based automotive software and tooling company founded in 1988, whose portfolio includes embedded cybersecurity components for electronic control units. Its MICROSAR HSM firmware provides secure boot, secure key storage and cryptographic services on ECU hardware security modules, and was certified to ISO/SAE 21434 by test house exida in June 2025. The MICROSAR Classic basic software includes a crypto stack with drivers for SHE and HSM trust anchors and the AUTOSAR Key Manager for in-vehicle key and certificate handling. On the verification side, vTESTstudio provides fuzz test design executed in CANoe, and Vector Consulting Services delivers TARA, ISO/SAE 21434 and UNECE R155 work.

Pros
  • MICROSAR HSM firmware holds a product-level ISO/SAE 21434 certificate issued by exida in June 2025, rather than only an organisational process certificate
  • Security functions ship inside an AUTOSAR basic software stack already used in series ECU development, so they fit an existing production toolchain
  • Covers both the build side (embedded crypto stack, key management, HSM firmware) and the verification side (fuzz testing in vTESTstudio and CANoe)
  • Vector Group reported roughly 4,000 employees and EUR 1.16bn revenue for 2023, indicating a stable long-term supplier
Things to check
  • A standalone TARA product could not be confirmed on public pages; TARA appears to be delivered through Vector Consulting Services, so confirm what tooling is in scope
  • Cybersecurity is one strand of a very broad tool and software portfolio, so the boundaries of a security engagement need defining up front
  • No public pricing: licensing, consulting and training are all quote-based

Pricing:

PCA Cyber Security

PCA Cyber Security (formerly PCAutomotive) is a Budapest-based specialist in offensive security and threat intelligence for vehicles and embedded systems. The firm runs dedicated CyberLab and CyberGarage research facilities and has built a strong public reputation through repeated Pwn2Own Automotive participation and disclosed vehicle vulnerability research, including 21 vulnerabilities across Skoda and Volkswagen vehicles and their cloud backend. While rooted in automotive, PCA has expanded into fintech, manufacturing, consumer electronics, and energy. It is a services-led firm focused on penetration testing, TARA, verification and validation, and managed product SOC monitoring rather than off-the-shelf software.

Pros
  • Elite offensive research talent. Repeat Pwn2Own Automotive contestants in 2024 and 2025
  • Proven track record of high-impact disclosed vehicle research (Skoda/VW, Nissan Leaf)
  • Deep hands-on embedded and hardware expertise via dedicated lab facilities
  • TISAX Assessment Level 3 accredited; regular presence at Black Hat, Hexacon, and escar
Things to check
  • Services and consulting model rather than a licensed product. Value scales with engagements
  • Smaller team than the large platform vendors; project-based delivery with no public pricing
  • Less suited to buyers seeking an off-the-shelf, deployable security product

Pricing: Custom (contact sales)