3DSA Bulletin nº 26 Activation of the Approval Testing Process for Bridging Message Extension Version 2.0

v1.0 Type Approval Bulletins
3-D Secure

EMV® 3-D Secure Approval Bulletin No. 26 First Edition June 2024 Activation of the Approval Testing Process for Bridging Message Extension Version 2.0

Applicability

This approval bulletin applies to the approval process for the EMV® 3-D Secure (3DS) Products.

Related Documents

  • EMV 3-D Bridging Message Extension version 2.0
  • EMV 3-D Secure Protocol and Core Functions Specification version 2.2.0
  • EMV 3-D Secure SDK Specification version 2.2.0
  • EMV 3-D Secure Approval – Administrative Process version 1.4
  • EMV 3-D Secure Approval Bulletin No 01 4th Edition
  • EMV 3-D Secure Testing Frequently Asked Question (FAQ)

Effective Date

July 1st, 2024

Description

The 3DS approval process is updated to support the testing of EMV 3-D Secure Bridging Message Extension version 2.0 (BME 2.0). The 3-D Secure Bridging Message Extension offers the possibility for a 3DS Product compliant with 3DS Protocol Version 2.2.0 to support a subset of the functionalities introduced into 3DS Protocol Version 2.3.1 (Refer to BME 2.0 for the details of the supported functionalities). Two different processes are offered to a Product Provider willing to test their 3DS Product against the BME 2.0 test plan. Case 1: Testing against BME 2.0 during the approval of a new 3DS Product It becomes possible for a Product Provider to request the testing of their 3DS Product against the BME 2.0 test plan. The standard approval process applies in that case and the Product Provider has to select the BME 2.0 supported option(s) in the ICS. The four BME 2.0 data sets listed below may be selected independently by the Product Provider for testing:

  • Recurring data
  • Challenge data
  • Additional data
  • File URL data Upon successful compliance testing and payment of the regular 3-D Secure approval fee, the Product Provider will obtain a LOA that will indicate the tested BME 2.0 data sets. countries. Case 2: Adding support of BME 2.0 after the approval of a 3DS Product It is also possible for a Product Provider to enhance an existing approved product to support BME 2.0. In that case, the Product Provider may request additional testing of their approved 3DS Product against the BME 2.0 test plan. Detailed instructions are provided in the 3DS Administrative Process section 6.2. From an operative view, some key points to consider:
  • Simplified testing will apply in Pre-Compliance and Compliance:
  • BME 2.0 Test Plan is fully run (Test Plan covering BME features).
  • Regression testing is performed on the Test Plan 2.2.0.
  • Upon successful approval:
  • The LOA is updated to document the compliance to BME 2.0 specification.
  • The reference number of the LOA as well as its expiration date will not change.
  • A specific approval fee for adding BME 2.0 testing applies and is documented in EMV 3-D Secure Approval Bulletin No 01, 4th Edition. Note: A prerequisite to benefit from this specific process is that the LOA of the Product being updated to support BME 2.0 shall still be valid when the RFA is sent to EMVCo. General Rules Even if BME 2.0 support and testing is optional, whenever a Product Provider selects a BME 2.0 data set in the ICS, the related test cases shall all pass successfully to obtain an LOA for the Product. Please reach to your Test Platform Provider and Testing Laboratory on their readiness to support the testing of BME 2.0. For additional information on the changes made to the 3-D Secure Approval process, please contact EMVCo 3DS Secretariat. countries.

Legal Notice

This document summarizes EMVCo’s present plans for evaluation services and related policies and is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or non-infringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document.

countries.