Skip to content
Nenkin

EMVCo: Payment Product Security Evaluation

EMVCo is the technical body co-owned by American Express, Discover, JCB, Mastercard, UnionPay, and Visa. It publishes the EMV specifications and operates security evaluation programmes for payment hardware and software components used in card and mobile payments.

Key facts

  • Authorizing body: EMVCo, co-owned by the six global payment networks
  • Country / region: Global
  • Year established: EMVCo was founded in 1999 to manage the EMV chip card specifications; security evaluation programmes have evolved over time
  • Product types: payment ICs, contact and contactless payment terminals (acceptance devices), card and mobile payment products, 3-D Secure components, and Level 3 testing tools
  • CCRA status: EMVCo is not a CCRA scheme; many evaluated products also carry Common Criteria certificates from national schemes
  • Canonical portal: https://www.emvco.com/processes-forms/product-approval/

Overview

EMVCo operates approval programmes across five categories: Card and Mobile, Acceptance Device, 3-D Secure, Security Evaluation, and Level 3 Testing. These cover payment ICs, contact and contactless payment terminals, mobile payment software, and the laboratory tools used to qualify them. While EMVCo’s methodology is distinct from Common Criteria, evaluations often complement national CC certifications for the same hardware, particularly for payment ICs, which are frequently evaluated under both BSI CC (at high EAL+VAN.5) and EMVCo’s IC security programme.

How evaluations work under this scheme

Accredited laboratories perform evaluations against EMVCo security guidelines and attack potential tables. EMVCo reviews the results and issues letters of approval, which are listed on the EMVCo public approval search. Approvals have validity periods and are subject to re-evaluation when underlying components change.

Notable product categories

  • Payment ICs used in EMV chip cards and mobile secure elements
  • Contact and contactless payment terminals (PED, PIN-on-Glass, acceptance devices)
  • Mobile payment applications and software
  • 3-D Secure components for card-not-present authentication

Relationship to CC baseline

EMVCo security evaluations use a methodology inspired by but distinct from the CEM. Attack potential ratings and evaluation work share conceptual roots with Common Criteria, particularly for smart card ICs. Many EMVCo-approved payment ICs also hold Common Criteria certificates under BSI, ANSSI, or other schemes; NenkinTracker treats EMVCo approvals as a distinct record linked to the underlying product.

Where to find official records

See also: MIFARE, BSI, Glossary.

Frequently asked questions

What is EMVCo?
EMVCo is the technical body that publishes the EMV chip card specifications and operates security evaluation programmes for payment hardware and software. It is co-owned by the six global payment networks: American Express, Discover, JCB, Mastercard, UnionPay, and Visa. EMVCo was founded in 1999 to manage the EMV specifications and has expanded over time into security approvals.
What does EMVCo certify?
EMVCo issues approvals for payment-related products. The programmes are organised into Card and Mobile, Acceptance Device, 3-D Secure, Security Evaluation, and Level 3 Testing. They cover payment ICs used in EMV chip cards and mobile secure elements, contact and contactless payment terminals, mobile payment software, and the testing tools used to qualify them. Approvals are listed on the EMVCo public approval search.
Is EMVCo a Common Criteria scheme?
No. EMVCo is not a CCRA scheme. It uses its own methodology, attack-potential tables, and accredited laboratories. EMVCo's approach shares conceptual roots with Common Criteria, particularly for smart card ICs, but it is administratively distinct. Many payment ICs hold both an EMVCo approval and a CC certificate from a national scheme such as BSI or ANSSI.
How is an EMVCo approval issued?
An accredited laboratory performs the evaluation against the relevant EMVCo security guidelines and attack potential tables for the product type. The lab produces a report; EMVCo reviews it and issues a letter of approval. Approvals are then listed on the EMVCo product approval search. Approvals have validity periods and require re-evaluation when underlying components change materially.
Why do payment ICs often hold both EMVCo and Common Criteria certificates?
Payment networks require EMVCo approval for use of an IC in EMV chip cards and contactless payment products. Many issuers and acquirers also require Common Criteria certification at high assurance (typically EAL4+ with AVA_VAN.5 under BSI or ANSSI) for the underlying chip hardware. The two evaluations cover overlapping but distinct security claims, and dual certification is the norm for mainstream payment ICs.
How long is an EMVCo approval valid?
EMVCo approvals are issued with defined validity periods that vary by programme. When the validity expires, or when the underlying hardware, firmware, or software is changed in ways that affect the evaluated security properties, the vendor must re-evaluate the product to maintain its listed status. EMVCo's public approval search shows current status for each approved product.