C2A Security
C2A Security sells the EVSec platform, an AI-driven product security orchestration system that automates threat analysis, SBOM management, and regulatory compliance for automotive, medical device, industrial, and other regulated manufacturers of software-defined products.
- Company typePrivate
- Founded2016
- HeadquartersJerusalem, Israel
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What C2A Security does
C2A Security is an Israel-based software company founded in 2016 that sells the EVSec platform, an AI-driven, context-driven product security orchestration system for manufacturers of software-defined cyber-physical products operating in heavily regulated sectors. The platform combines six functional modules (EVSec Analysis for automated TARA, BOM & Vulnerability Management for SBOM automation, Attacker for fuzz and penetration testing, Network & Endpoint Protection, SOC Enrichment & Analytics, and AutoSynth AI for generative threat intelligence) into a single workflow that ties vulnerabilities, threat models, and component data to each customer's specific product architecture, supplier map, and regulatory obligations. Target customers include automotive OEMs and Tier-1 suppliers, medical device manufacturers, industrial automation vendors, semiconductor firms, and defense and telecom equipment makers, with named deployments at BMW Group, Daimler Truck, Valeo, Marelli, NTT DATA, HARMAN, Elekta, Bayer, Ascensia, Siemens, and NVIDIA.
C2A generates revenue through multi-year enterprise SaaS subscriptions priced on a quote basis, with a direct field sales motion complemented by channel partners (Deloitte Germany and Deloitte Taiwan for implementation, ThunderSoft and Itbigtec in China for distribution, and integration partners such as HARMAN and NTT DATA). Pricing is not publicly disclosed; the primary call-to-action is 'Schedule a Demo' and contract structures are referenced as enterprise agreements with annual billing. The company holds ISO 27001 and ISO 27017 certifications and operates from a Jerusalem headquarters with regional offices or subsidiaries in Munich (C2A Security GmbH), the United States, and partner-led presence in China and Taiwan.
The company's go-to-market emphasis on regulatory frameworks (UN R155/R156, ISO/SAE 21434, FDA premarket/postmarket guidance, IEC 62443, and the EU Cyber Resilience Act) and its growing vertical footprint following the October 2025 acquisition of Vigilant Ops position it as a specialist DevSecOps vendor for industries where product certification depends on auditable cybersecurity evidence. Headcount of 11-50 employees, board representation from investors OurCrowd, Maniv Mobility, and MoreVC, and approximately $13.2M in disclosed equity funding through 2023 indicate an early-stage but institutionally backed scale-up rather than a bootstrapped startup.
C2A Security firmographics
Firmographics- Name
- C2A Security
- Legal name
- C2A-SEC LTD
- Website
- https://c2a-sec.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- C2A Security sells the EVSec platform, an AI-driven product security orchestration system that automates threat analysis, SBOM management, and regulatory compliance for automotive, medical device, industrial, and other regulated manufacturers of software-defined products.
- Ownership category
- akta.pro rank
C2A Security industry classification
Industry- Product category
- Cybersecurity Software
- NAICS
- Computer Systems Design and Related Services (5415)
- akta.pro primary industry
- Governance, Risk & Compliance (GRC) Advisory & Assessments (BPAKAHAH)
- akta.pro secondary industries
- Control System Cybersecurity for OT (ICS Security, Monitoring, Hardening) (IMAGABAL), Security Governance, Risk & Compliance (GRC) Advisory (BPAKADAG), Security Awareness, Training & Compliance Attestation (HDADAIAJ)
Keywords
Where C2A Security is headquartered
LocationHeadquarters
- HQ city
- Jerusalem
- HQ country
- Israel
- HQ region
- Middle East
Offices4 records
Markets served
C2A Security business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Enterprise SaaS Platform Licensing: C2A Security operates on a subscription-based model providing access to the EVSec platform and its various modules. The company sells enterprise agreements to large manufacturers in regulated industries. A multi-year enterprise agreement with a leading automotive player has been referenced in company materials.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Enterprise platform pricing - custom quotes based on organizational requirements |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels8 records
C2A Security product offering
Product offeringCore offering
C2A Security provides an AI-driven, context-based product security orchestration platform (EVSec) that enables manufacturers in regulated industries to embed Security-by-Design principles and manage cybersecurity across the entire software development lifecycle. The platform automates threat analysis and risk assessment (TARA), SBOM and vulnerability management, fuzz and penetration testing, on-board vehicle network protection, and compliance reporting against standards such as UN R155/R156, ISO/SAE 21434, FDA premarket and postmarket guidelines, IEC 62443, and the EU Cyber Resilience Act. Core customers include automotive OEMs and Tier 1 suppliers, medical device manufacturers, and industrial and critical infrastructure operators.
Product overview
C2A Security offers EVSec, the only AI-driven, context-driven product security orchestration platform for software-defined products in regulated industries. The platform consists of a core EVSec Platform with integrated modules including EVSec Analysis (automated TARA and compliance), EVSec BOM & Vulnerability Management (SBOM automation), EVSec Attacker (automated fuzz/pen testing), EVSec Network & Endpoint Protection (real-time on-board security), EVSec SOC Enrichment & Analytics (SOC integration), and EVSec AutoSynth AI (generative AI layer). The platform serves healthcare, automotive, industrial, semiconductor, and critical infrastructure sectors with global customers including BMW Group, Daimler Truck AG, Elekta, Bayer, Siemens, Valeo, and Marelli.
Differentiator
Problem solved
Functional benefit
Brands
- EVSec Platform: AI-driven product security orchestration platform for context-based risk management across software-defined products.
- EVSec Analysis
- EVSec BOM & Vulnerability Management
- EVSec Attacker
- EVSec Network & Endpoint Protection
- EVSec SOC Enrichment & Analytics
- EVSec AutoSynth AI
Products and services
- EVSec Platform Core platform that enables product security teams to embed Security-by-Design principles and scale cybersecurity across the entire software development lifecycle from design to deployment, with automation, compliance, and complete visibility built in.
- EVSec Analysis Automated Threat Analysis and Risk Assessment (TARA) module that ensures adherence to regulations and standards including FDA premarket and postmarket guidelines, ISA/IEC 62443, ISO/SAE 21434, and UN R155.
- EVSec BOM & Vulnerability Management Automates risk management by identifying and mitigating the impact of vulnerabilities across the software supply chain with automated SBOM generation and vulnerability correlation.
- EVSec Attacker Speeds up vulnerability detection by automating fuzz and penetration testing, enabling early discovery of security weaknesses in software-defined products.
- EVSec Network & Endpoint Protection Secures the mobility ecosystem through real-time on-board protection for connected vehicles and cyber-physical systems.
- EVSec SOC Enrichment & Analytics Bridges the gap between the SOC and the product with an integrated event and analysis management module for post-market surveillance.
- EVSec AutoSynth AI Generative AI infrastructure layer that accelerates threat intelligence and risk management with AI-driven contextual analysis for vulnerability prioritization and compliance reporting.
- EVSec Context-Based Threat Intelligence Module Provides contextual insights tailored to specific product infrastructure, connecting SBOM information to device architecture, data flows, threat models, potential attack paths, and real-world exposure.
- EVSec Claude Inside Dedicated version of EVSec integrating Anthropic's Claude AI to advance AI-driven product security orchestration, ease of use, and advanced automation across the EVSec AutoSynth AI capabilities.
- EVSec Workflow Automation Module Automates cybersecurity workflows including CSMS (Cybersecurity Management System) automation for mobility companies, enabling efficient regulatory compliance.
Quantifiable outcome
- 80% reduction of development costs
- +2 more outcomes
Companies that use C2A Security
Customer profileNamed customers16 records
Segments6 records
Ideal customer profiles4 records
C2A Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration3 records
AI capability10 records
Feature9 records
C2A Security partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core and minor.
- Deloitte TaiwancoreStrategic alliance announced January 8, 2026 to help Taiwanese companies meet cybersecurity compliance requirements and compete globally in automotive, industrial, semiconductor, and medical markets. The partnership leverages C2A's AI-driven EVSec platform and Deloitte's implementation expertise to address regulatory demands including the Cyber Resilience Act, IEC 62443, and UN R155/R156. The alliance targets Taiwanese exporters facing growing cybersecurity requirements from global OEMs.
- Vigilant OpscoreAcquisition completed October 9, 2025. Vigilant Ops, a Pittsburgh-based company specializing in product security and SBOM automation for MedTech sectors. The deal aims to enhance C2A Security's platform for compliance, risk management, and regulatory readiness in highly regulated industries like healthcare, defense, and telecom. Added tens of MedTech, Telecom, and Defense customers.
- Deloitte GermanycoreStrategic alliance announced October 22, 2024 to help clients meet cybersecurity demands at scale. The partnership combines EVSec with Deloitte's implementation services including tool migration, tailoring of EVSec, risk management expert advice, and project management. Building on successful collaboration with a leading player in the automotive industry.
- ThunderSoftcoreStrategic partnership for Chinese automotive cybersecurity market. Collaboration on webinars and joint go-to-market activities in China. ThunderSoft provides cybersecurity solutions for the whole lifecycle of connected vehicles in China.
- SiemenscoreTechnology partnership for DevSecOps integration. EVSec platform integrates with Siemens Polarion for Application Lifecycle Management and ServiceNow for automated asset management.
- HARMANcoreCollaboration announced September 22, 2025 to empower global carmakers in their product security journey. Partnership leverages EVSec platform with HARMAN's Automotive Engineering Services capabilities to automate compliance and regulatory monitoring with US DoC 791D Rule.
- NTT DATAcoreGlobal partnership for automotive cybersecurity. NTT DATA operates an Automotive Security Test Center and leverages C2A Security's platform to protect connected cars from cyber-attacks and ensure drivers' safety.
- Itbigtec Technology Co., Ltd.minorChina-based distribution and partnership contact for C2A Security products. WeChat: 13533491614
Scale indicators3 records
Recent moves7 records
Expansion highlights6 records
C2A Security competitors and assessment
Company assessmentDirect peers
- Upstream Security: Israel-based cloud-native cybersecurity platform purpose-built for connected vehicles and mobility. Directly competes with C2A in automotive product/vehicle cybersecurity, with overlapping OEM and Tier-1 customer base and comparable subscription SaaS model.
- Cybellum (LG Vehicle Security Solutions): Pre-acquisition by LG, Cybellum was a direct competitor in automotive product cybersecurity and SBOM-based vulnerability management. C2A's CRO John Auld previously led North America at Cybellum, underscoring the close competitive and product overlap with C2A's EVSec BOM & Vulnerability Management module.
- Karamba Security: Israeli automotive cybersecurity company focused on ECU-level runtime security and vulnerability management. Overlaps with C2A on ISO/SAE 21434 compliance and automotive OEM customers, though Karamba is more endpoint-focused while C2A covers the full product lifecycle.
- VicOne: Automotive cybersecurity subsidiary of Trend Micro offering VSOC, penetration testing, and product security for OEMs/Tier-1s. Competes with C2A's EVSec Network & Endpoint Protection and SOC Enrichment modules for the same enterprise vehicle cybersecurity buyers.
- Argus Cyber Security (Continental): Pioneer in automotive cybersecurity now part of Continental; offers in-vehicle network protection, VSOC, and lifecycle security. Direct competitor to C2A's product security orchestration platform, especially for Tier-1 suppliers and OEMs operating in EU markets.
- Finite State: Product security platform for connected devices and IoT/embedded systems with strong SBOM and supply chain risk management capabilities. Comparable to C2A's BOM & Vulnerability Management and Context-Based Threat Intelligence modules across regulated verticals.
- MedCrypt: Medical device cybersecurity platform addressing FDA premarket/postmarket requirements. Highly comparable to C2A's expanded MedTech vertical following the Vigilant Ops acquisition, with overlapping customer profile of connected medical device manufacturers.
- GuardKnox: Israeli automotive cybersecurity company focused on in-vehicle network and ECU security. Direct competitor for OEM and Tier-1 automotive product cybersecurity deals, with similar Israeli roots and comparable regulatory focus on UN R155.
Broad incumbents
- Claroty: Established OT/ICS cybersecurity leader with a much larger installed base across industrial and critical infrastructure. Overlaps with C2A's industrial vertical (IEC 62443) but operates as a broad incumbent with wider portfolio beyond product security orchestration.
- Nozomi Networks: Incumbent OT/IoT cybersecurity vendor with strong presence in industrial, energy, and critical infrastructure. Comparable to C2A on the industrial/critical infrastructure side, but with significantly broader scope and a larger sales organization.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
C2A Security social profiles
Digital presenceC2A Security compliance and trust
Trust signalCompliance2 records
C2A Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
C2A Security leadership team
Management profileNumber of profiles
Profiles19 records
C2A Security subsidiaries and ownership
Company hierarchySubsidiaries1 record
C2A Security funding detail
Funding detailFunding overview
Funding rounds5 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
C2A Security M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about C2A Security
What does C2A Security do?
C2A Security provides an AI-driven, context-based product security orchestration platform (EVSec) that enables manufacturers in regulated industries to embed Security-by-Design principles and manage cybersecurity across the entire software development lifecycle. The platform automates threat analysis and risk assessment (TARA), SBOM and vulnerability management, fuzz and penetration testing, on-board vehicle network protection, and compliance reporting against standards such as UN R155/R156, ISO/SAE 21434, FDA premarket and postmarket guidelines, IEC 62443, and the EU Cyber Resilience Act. Core customers include automotive OEMs and Tier 1 suppliers, medical device manufacturers, and industrial and critical infrastructure operators.
Is C2A Security a public or private company?
C2A Security is a private company. It is classified as venture growth investor backed and is currently operating.
When was C2A Security founded?
C2A Security was founded in 2016. It employs 11 to 50 people.
Where is C2A Security based?
C2A Security is headquartered in Jerusalem, Israel, in the Middle East region.
How does C2A Security make money?
One revenue line is on record: enterprise SaaS Platform Licensing.
Who are C2A Security's main competitors?
Direct peers on record are Upstream Security, Cybellum (LG Vehicle Security Solutions), Karamba Security, VicOne, Argus Cyber Security (Continental), Finite State, MedCrypt and GuardKnox. Broad incumbents are Claroty and Nozomi Networks.
Does C2A Security have an API?
No public API is recorded for C2A Security.
What industry is C2A Security in?
C2A Security's product category is Cybersecurity Software. Its primary akta.pro industry code is BPAKAHAH, Governance, Risk & Compliance (GRC) Advisory & Assessments, with a secondary code of IMAGABAL, Control System Cybersecurity for OT (ICS Security, Monitoring, Hardening). Its NAICS code is 5415.