PCA Cyber Security
Munich- and Budapest-based embedded cybersecurity experts focused on financial services, automotive and mobility, manufacturing and industrial automation, energy and more. The services and platform go beyond compliance, supporting the requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and other standards and regulations.
Featured in: Best Automotive Penetration Testing Companies (2026)
Visit PCA Cyber SecurityKey facts
- Holds TISAX (Trusted Information Security Assessment Exchange) Assessment Level 3, covering information with very high protection needs and the protection of prototype parts and components.
- Registered Associate Participating Organization (APO) of the PCI Security Standards Council since March 2026.
- Participated in the Pwn2Own Automotive contest in Tokyo in January 2024 and January 2025.
- Won $40,000 at Pwn2Own Automotive 2024 in Tokyo for CVE-2024-23923.
- Speakers at Black Hat, Hexacon, Escar and Hacktivity.
- Specialises in financial services, automotive security, product threat intelligence, and PTS device, ATM, ECU and other embedded device penetration testing.
- Builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform.
- Tests ATMs end to end: network and authentication, OS hardening, middleware, backend encryption, card readers and cash dispensers, and physical anti-tamper bypass.
- Payment device testing covers POS terminals, unattended payment terminals, PIN entry devices, and mobile payment applications, framed as PCI PTS pre and post compliance testing.
- PCI DSS penetration testing aligned to version 4.0.1, including Requirement 11.3 segmentation testing.
- Founded in 2019.
- Headquartered in Munich, Germany.
- Team of 11-50 security professionals.
- Delivers 15 penetration testing services.
- Typical response time: 1-2 weeks.
- Operates globally, with delivery across Europe.
- Compliance expertise across TISAX, Cyber Resilience Act, NIS 2, GDPR, and PCI DSS.
About
PCA Cyber Security is an embedded cybersecurity firm headquartered in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare. Its services and platform are built around the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards, and aim to go beyond a compliance checklist.
Penetration testing covers payment devices, ATMs and PCI DSS environments; ECUs, telematics, full vehicles and EV chargers; industrial control systems, PLCs and OT networks; IoT and embedded devices; medical devices; railway signalling and control networks; and the mobile, web and cloud applications that sit around them. The work is hands-on in PCA's own labs, CyberLab and CyberGarage, with firmware extraction, fault injection, side-channel analysis and cryptographic review alongside network and application testing. Threat intelligence and security assessment services complete the offer.
PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform for embedded products. It takes a supplier's SBOM through to remediation evidence: validating and creating SBOMs, checking whether reported vulnerabilities and patches really apply to the device, and mapping results to regulatory requirements.
The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in Tokyo in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Accreditations
PCA Cyber Security in Depth
EnhancedOverview
PCA Cyber Security is an embedded cybersecurity firm founded in 2019, working on the hardware, firmware and software of connected products. It runs dedicated labs across Budapest, Munich and Madrid, holds TISAX Assessment Level 3, and is an Associate Participating Organization of the PCI Security Standards Council. It works across financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform.
Approach
Work is hands-on hardware research rather than scanning. Devices are attacked on the bench with fault injection, side-channel analysis, firmware extraction and cryptographic implementation review, alongside the network, OS and backend testing that surrounds them. Findings are written to the standard the client is being assessed against, whether that is a PCI PTS submission, PCI DSS 4.0.1 including Requirement 11.3 segmentation testing, or ISO/SAE 21434 clauses and TARA outputs for type approval. The team took $40,000 at Pwn2Own Automotive 2024 in Tokyo for CVE-2024-23923, and publishes vulnerabilities disclosed to manufacturers.
What They Test
Working with PCA Cyber Security
Services
Compliance Expertise
Best For
Methodologies
Team Activity
Is this your company?
Claim PCA Cyber Security to verify the listing, update your services and pricing, respond to leads, and add the Verified badge to your profile. Free for companies, we just need to confirm your business email.
Claim This Profile