Best PCI PTS Compliance Testing Companies (2026)

PCI PTS (PIN Transaction Security) is the PCI Security Standards Council standard governing the security of Point of Interaction (POI) payment devices: PIN entry devices (PEDs), encrypting PIN pads (EPPs), unattended payment terminals (UPTs), and secure card readers. Unlike PCI DSS, which covers the cardholder data environment, PCI PTS is a device-level hardware and firmware standard: terminals must resist physical tampering, side-channel and fault-injection attacks, and protect PIN and account data in the device itself. Formal evaluation against the PTS POI requirements is carried out by PCI Recognized Laboratories, and manufacturers commission security testing to reach and maintain approval.

About this list

PCI PTS penetration testing is therefore a specialist hardware and embedded security discipline, closer to ECU or IoT device testing than to network or web application work. It needs a hardware lab: bench setups, fault-injection and side-channel rigs, firmware extraction and analysis, and familiarity with the PTS POI security requirements and the approval process. The providers below have demonstrated payment-device security capability. PCA Cybersecurity, our Featured partner, leads the list and is a PCI SSC Associate Participating Organization with hands-on PCI PTS payment terminal testing experience.

A distinct niche within this space is offensive, pre and post compliance testing of payment devices by specialists who are not formal certification labs. See the related PCI PTS pre and post compliance testing list below.

Related: PCI PTS pre and post compliance testing · PCI DSS pen testing · Automotive pen testing companies

Featured partnerFeatured
PCA Cybersecurity logo

PCA Cybersecurity

Munich- and Budapest-based automotive cybersecurity specialist focused on UN R155, ISO/SAE 21434, and vehicle research. Pwn2Own Automotive participant with a dedicated ECU and vehicle test lab.

PCI SSC Participating Organization
  • Holds PCI SSC PO accreditation.
  • Associate Participating Organization of the PCI Security Standards Council since March 2026.
  • Tests ATMs end to end: network and authentication, OS hardening, middleware, backend encryption, card readers and cash dispensers, and physical anti-tamper bypass.
  • Payment device testing covers POS terminals, unattended payment terminals, PIN entry devices, and mobile payment applications, framed as PCI PTS pre and post compliance testing.
View PCA Cybersecurity
1 provider
Seattle, Washington, United States · Checked Sept 2026

Boutique security consultancy specialising in IoT, SCADA/ICS, embedded systems, and hardware security research with world-renowned researchers.

Accreditations: OSCP Employer
Services: Web Application, Network, IoT, SCADA/ICS +6

Best PCI PTS Compliance Testing Companies (2026), FAQs

What is PCI PTS?+

PCI PTS (PIN Transaction Security) is a PCI Security Standards Council standard for the security of Point of Interaction (POI) payment devices, such as PIN entry devices, encrypting PIN pads, unattended payment terminals, and secure card readers. It governs the device's hardware and firmware: physical tamper resistance, secure cryptographic operations, and protection of PIN and account data within the device.

How is PCI PTS different from PCI DSS?+

PCI DSS covers the cardholder data environment, the networks, systems, and processes that store, process, or transmit card data, and is what most penetration testing firms assess. PCI PTS is a device-level standard for the payment terminal hardware itself. A firm strong in PCI DSS testing is not automatically equipped for PCI PTS, which requires a hardware security lab and embedded device expertise.

What does PCI PTS penetration testing involve?+

It is hardware and embedded security testing of the payment device: physical and tamper-resistance attacks, side-channel analysis, fault injection, firmware extraction and review, cryptographic implementation analysis, and assessment of how the device protects PINs and account data. The goal is to find weaknesses against the PTS POI security requirements before, or in support of, formal approval.

Who needs PCI PTS testing?+

Manufacturers of payment terminals and POI devices, and their suppliers, who need to reach or maintain PCI PTS approval to sell into the payments ecosystem. Acquirers and payment service providers may also commission device security testing as part of vendor due diligence.