
Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.
Hardware penetration testing attacks the physical device rather than the network around it. Testers open the product on the bench and work on its debug interfaces, firmware, memory and chips, using techniques such as UART and JTAG access, firmware extraction and reverse engineering, fault injection and side-channel analysis. It covers embedded and connected products of every kind: payment terminals and ATMs, vehicle ECUs and telematics units, EV chargers, industrial controllers, medical devices and consumer IoT.
The work matters most where a device holds secrets an attacker can physically reach, such as keys, credentials or cardholder data, and where regulation now expects evidence of product security. The EU Cyber Resilience Act, UN R155 and ISO/SAE 21434, PCI PTS and IEC 62443-4-2 all ask manufacturers to show their products resist realistic attack. Few firms run the lab equipment and hardware expertise this needs, so the providers below are a short list by nature.

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.
Munich- and Budapest-based embedded cybersecurity experts focused on financial services, automotive and mobility, manufacturing and industrial automation, energy and more. The services and platform go beyond compliance, supporting the requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and other standards and regulations.

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.

Vienna-headquartered Austrian cybersecurity consultancy with a prolific Vulnerability Lab research program and deep expertise in IoT and embedded systems security across the DACH region.

Boutique security consultancy specialising in IoT, SCADA/ICS, embedded systems, and hardware security research with world-renowned researchers.

Offensive security firm founded by former DoD professionals. Combines deep offensive testing with the Chariot attack surface management platform and its Exploit validation engine.
Airbus group cybersecurity consultancy with ANSSI PASSI qualification. Aerospace, defence, and critical infrastructure penetration testing across Europe.

Independent Italian offensive security firm specialising in web, mobile, network, and embedded security assessments with a strong research focus.
Dutch security evaluation lab, part of SGS, recognised by the PCI SSC for PTS device evaluation and accredited for EMVCo and Common Criteria.
Global testing and certification firm, recognised by the PCI SSC for PTS POI and HSM evaluation, with labs in the UK and China.
French security evaluation lab (ITSEF/CESTI) recognised by the PCI SSC for PTS device evaluation, plus EMVCo and Common Criteria.
German security lab in Bonn, recognised by the PCI SSC for PTS device evaluation, plus German payment terminal schemes.
IoT testing usually covers the whole connected system: the device, its mobile app, cloud back end and network traffic. Hardware testing goes deeper into the device itself, working on the circuit board, debug ports, firmware and chips. Many engagements combine both.
Several units of the device, ideally including ones that can be damaged, plus any documentation, firmware images and developer or debug builds you can share. Techniques such as chip removal and fault injection can destroy a sample, so most providers ask for spares.
None name it word for word, but several expect evidence that a product resists physical and local attack: the EU Cyber Resilience Act for products with digital elements, UN R155 and ISO/SAE 21434 for vehicles, PCI PTS for payment devices, and IEC 62443-4-2 for industrial components.