Merchants Eye — Payments & Ecommerce News

PCA Cyber Security Launches CERVUS to Protect Embedded Payment Devices and Connected Tech

By Lauren Towner · 1 October 2026

Press Release: PCA Cyber Security Launches CERVUS to Protect Embedded Payment Devices and Connected Tech | Featured Image by FF News

PCA Cyber Security has launched PCA CERVUS, a vulnerability monitoring platform designed to secure the lifecycle of embedded and connected devices. For fintech professionals, this addresses the growing security debt in payment terminals and IoT infrastructure, providing the continuous visibility required to maintain compliance with evolving global cybersecurity regulations and standards.

What was announced

Launched on 1st October 2026 in Budapest, Hungary, PCA CERVUS is a device-centric threat intelligence platform that provides continuous risk visibility for products from development through to maintenance. It targets manufacturers, importers, and operators of connected hardware, including payment terminals, industrial controllers, and connected vehicles. The platform functions by correlating vulnerability disclosures and security research with a product’s specific architecture and software bills of materials (SBOMs). It allows security teams to identify which specific vulnerabilities affect their hardware, assess exposure levels, and prioritise remediation efforts.

Beyond identification, the platform tracks the remediation lifecycle, validating patches to ensure security issues are fully addressed rather than just flagged. It supports the generation or validation of SBOMs, offering a detailed view of software components and third-party dependencies. This functionality is specifically designed to assist organisations in meeting compliance requirements for several major frameworks, including the EU Cyber Resilience Act, PCI DSS, PCI PTS, RED, and UNECE R155. By automating the monitoring of emerging exploits and threats, the platform aims to replace manual security checks with a persistent, data-driven overview of a company’s entire device portfolio. The platform is applicable across various sectors, including financial services, automotive, industrial automation, energy, and medical devices. Its name is derived from the Latin word for stag, reflecting its intended role as a guide through the complexities of unknown security risks.

"Today’s world is connected. Businesses rely on millions of payment devices, industrial controllers, and connected vehicles to keep commerce moving and critical infrastructure running. Manufacturers, importers and operators responsible for these devices need continuous visibility of which products are exposed and where to act. PCA CERVUS connects vulnerabilities and threats with the components inside each device, helping teams prioritise risk, track remediation and demonstrate if security issues have been addressed."

Gianfranco Vinucci, Chief Operating Officer of PCA Cyber Security.

The companies involved

PCA Cyber Security is an embedded cybersecurity specialist headquartered in Budapest, Hungary. The firm focuses on providing visibility into the risks affecting connected products throughout their entire lifecycle, from the initial certification phase to long-term deployment. This focus is particularly relevant for the financial services sector, where the security of payment terminals and IoT-enabled commerce devices is paramount. The company’s approach centers on the correlation of threat intelligence with the specific software architecture of embedded systems.

Also operating in the cybersecurity domain is Securious Cyber Security, which provides a range of security services and consultancy, reflecting the broader market's need for both technical tools and strategic oversight. As the regulatory landscape becomes more demanding, particularly with the introduction of the EU Cyber Resilience Act, the role of specialized firms like PCA Cyber Security is expanding. These companies provide the technical bridge between high-level regulatory requirements and the granular reality of software components in hardware. By focusing on SBOMs and continuous monitoring, PCA Cyber Security addresses a critical gap in the supply chain security of connected devices.

What this means

The launch of PCA CERVUS highlights a shift in the fintech industry from reactive patching to proactive lifecycle management of hardware. As the EU Cyber Resilience Act and updated PCI standards impose stricter transparency requirements, the "black box" nature of payment terminals is no longer tenable. This announcement puts pressure on traditional hardware manufacturers who have historically lagged in providing real-time vulnerability data. The industry is moving toward a model where the Software Bill of Materials (SBOM) is a mandatory requirement for trust. The open question remains whether smaller manufacturers can keep pace with these rigorous monitoring demands or if the market will consolidate around those with the most robust automated security platforms.

Companies in this story: PCA Cyber Security

People in this story: Gianfranco Vinucci

More from News