PCA Cyber Security logo

PCA Cyber Security

Munich- and Budapest-based embedded cybersecurity experts focused on financial services, automotive and mobility, manufacturing and industrial automation, energy and more. The services and platform go beyond compliance, supporting the requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and other standards and regulations.

Featured in: Best Automotive Penetration Testing Companies (2026)

Visit PCA Cyber Security
Embedded Security SpecialistPwn2Own Automotive
Headquarters
Munich, Germany
Founded
2019
Team Size
11-50
Geography
Regional
Markets
Europe, Global
Last verified: Sept 2026

Key facts

  • Holds TISAX (Trusted Information Security Assessment Exchange) Assessment Level 3, covering information with very high protection needs and the protection of prototype parts and components.
  • Registered Associate Participating Organization (APO) of the PCI Security Standards Council since March 2026.
  • Participated in the Pwn2Own Automotive contest in Tokyo in January 2024 and January 2025.
  • Won $40,000 at Pwn2Own Automotive 2024 in Tokyo for CVE-2024-23923.
  • Speakers at Black Hat, Hexacon, Escar and Hacktivity.
  • Specialises in financial services, automotive security, product threat intelligence, and PTS device, ATM, ECU and other embedded device penetration testing.
  • Builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform.
  • Tests ATMs end to end: network and authentication, OS hardening, middleware, backend encryption, card readers and cash dispensers, and physical anti-tamper bypass.
  • Payment device testing covers POS terminals, unattended payment terminals, PIN entry devices, and mobile payment applications, framed as PCI PTS pre and post compliance testing.
  • PCI DSS penetration testing aligned to version 4.0.1, including Requirement 11.3 segmentation testing.
  • Founded in 2019.
  • Headquartered in Munich, Germany.
  • Team of 11-50 security professionals.
  • Delivers 15 penetration testing services.
  • Typical response time: 1-2 weeks.
  • Operates globally, with delivery across Europe.
  • Compliance expertise across TISAX, Cyber Resilience Act, NIS 2, GDPR, and PCI DSS.

About

PCA Cyber Security is an embedded cybersecurity firm headquartered in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare. Its services and platform are built around the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards, and aim to go beyond a compliance checklist.

Penetration testing covers payment devices, ATMs and PCI DSS environments; ECUs, telematics, full vehicles and EV chargers; industrial control systems, PLCs and OT networks; IoT and embedded devices; medical devices; railway signalling and control networks; and the mobile, web and cloud applications that sit around them. The work is hands-on in PCA's own labs, CyberLab and CyberGarage, with firmware extraction, fault injection, side-channel analysis and cryptographic review alongside network and application testing. Threat intelligence and security assessment services complete the offer.

PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform for embedded products. It takes a supplier's SBOM through to remediation evidence: validating and creating SBOMs, checking whether reported vulnerabilities and patches really apply to the device, and mapping results to regulatory requirements.

The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in Tokyo in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Accreditations

PCA Cyber Security in Depth

Enhanced

Overview

PCA Cyber Security is an embedded cybersecurity firm founded in 2019, working on the hardware, firmware and software of connected products. It runs dedicated labs across Budapest, Munich and Madrid, holds TISAX Assessment Level 3, and is an Associate Participating Organization of the PCI Security Standards Council. It works across financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform.

Approach

Work is hands-on hardware research rather than scanning. Devices are attacked on the bench with fault injection, side-channel analysis, firmware extraction and cryptographic implementation review, alongside the network, OS and backend testing that surrounds them. Findings are written to the standard the client is being assessed against, whether that is a PCI PTS submission, PCI DSS 4.0.1 including Requirement 11.3 segmentation testing, or ISO/SAE 21434 clauses and TARA outputs for type approval. The team took $40,000 at Pwn2Own Automotive 2024 in Tokyo for CVE-2024-23923, and publishes vulnerabilities disclosed to manufacturers.

What They Test

ATMs
Network and authentication, OS hardening including kiosk mode and BIOS, middleware, backend encryption and client-server authentication, card readers and cash dispensers, and physical access and anti-tamper bypass.
Payment devices
POS terminals, unattended payment terminals, PIN entry devices including IPP and EPP, and mobile payment applications, as PCI PTS pre and post compliance testing.
Cardholder data environments
PCI DSS 4.0.1 penetration testing, including Requirement 11.3 segmentation testing and CDE interface testing, with remediation and retest.
Vehicles and components
ECU and component testing on the bench, full vehicle assessments, in-vehicle networks, OTA update back ends, telematics and companion apps.
EV charging
Charging infrastructure and OCPP protocol security.
Supply chain
Software composition analysis and SBOM validation, reconstructing and verifying the real component list inside a device.
Industrial control systems
SCADA, PLCs and OT environments, including industrial network protocols and controller firmware.
Medical devices
Embedded systems, wireless communication and connected healthcare platforms.
Railway
Signalling, communication and control networks.
Applications
Mobile apps, web applications and cloud platforms used in connected-product ecosystems.

Working with PCA Cyber Security

What makes PCA different from a general penetration testing firm?
A hardware lab and embedded expertise. Attacking an ATM, a PIN pad or an ECU needs bench setups, fault injection and side-channel rigs, firmware extraction and cryptographic analysis, which is a different discipline from network or web application testing. Very few firms do both.
Is PCA a PCI Recognized Laboratory?
No. PCA is an Associate Participating Organization of the PCI Security Standards Council, which is a membership tier. Formal PCI PTS evaluation is carried out by Recognized Laboratories. PCA provides the adversarial testing before and after that evaluation, which is a separate and complementary discipline.
Which standards does PCA test against?
For payments, PCI PTS, PCI DSS 4.0.1 and PSD2. For automotive, UN R155 and ISO/SAE 21434. For connected products more widely, the EU Cyber Resilience Act, IEC 62443-4-2, RED / EN 18031 and NIS 2. It holds TISAX Assessment Level 3 for the automotive supply chain.
Where is PCA based?
Budapest and Munich, with an office in Madrid, serving European manufacturers, payment solution providers, banks and fintechs. It was founded in 2019 and has around thirty staff.

Methodologies

OWASPPTESOSSTMM

Team Activity

Active in CTF competitions
Pwn2Own Automotive 2024, Tokyo: $40,000 for CVE-2024-23923
Speaker: Black Hat
Speaker: Hexacon
Speaker: Escar
Speaker: Hacktivity
Takes part in: Pwn2Own Automotive, Tokyo (2024 and 2025)
Takes part in: PCI SSC Community Meetings

Is this your company?

Claim PCA Cyber Security to verify the listing, update your services and pricing, respond to leads, and add the Verified badge to your profile. Free for companies, we just need to confirm your business email.

Claim This Profile
Visit PCA Cyber Security