SB n° 308 Contact Chip Features Sunsetting -Phase1

v1.0 Specification Bulletins
Contact Acceptance Device

EMV® Specification Bulletin No. 308 First Edition January 2025 EMV® Contact Chip Features Sunsetting – Phase 1 This Specification Bulletin provides information on specification changes regarding the removal of the features described below.

Applicability

This Specification Bulletin applies to:

  • EMV Integrated Circuit Card Specifications for Payment Systems, Book 1/2/3/4, v.4.4

Related Documents

  • GB 60 2nd edition dated 30 July 2024

Effective Date

  • 1 January 2026

Description

General Bulletin 60 2nd edition published on 30 July, 2024 outlined the features to be sunsetted from the specifications with the aim of collectively improving security, optimising the usability of the specifications, simplifying editorial understanding, and removing obsolete or unused features. This bulletin provides information on how the Phase 1 sunset features listed below will be removed from the specification. Features to be sunsetted from the specification in Phase 1: ⚫ Offline Plaintext PIN (unattended) ⚫ Combination CVMs ⚫ TDOL ⚫ Unused Tags ➢ ‘9F04’ (Amount, Other (Binary)) ➢ ‘9F3A’ (Amount, Reference Currency) ➢ ‘9F3B’ (Application Reference Currency) ➢ ‘9F43’ (Application Reference Currency Exponent) ➢ ‘81’ (Amount, Binary) ➢ ‘97’ (Transaction Certificate Data Object List (TDOL))

countries.

Details of the Change < Offline Plaintext PIN (unattended)> [Changes to Book 3]

  • Section 6.5.12.2, Table 24: ➢ Add following footnote to the second item (“Plaintext PIN, format as defined below”) as below: 4 Plaintext PIN is not allowed for Unattended terminals.
  • Section 10.5.1: ➢ Add footnote to the first sentence: 15 Plaintext PIN shall not be allowed for Unattended terminal. ➢ Insert following sentence after the first sentence: Plaintext PIN is not supported in Unattended terminals (Terminal Type = ‘x4’, ‘x5’, or’ x6’).
  • Section 10.5.1, Table 43 (“CVM Codes”), bit 6 to 1: ➢ Add following footnote to the second item (“Plaintext PIN verification performed by ICC”): 27 Plaintext PIN is not allowed for Unattended terminals. [Changes to Book 4]
  • Section 6.4 ➢ Insert following sentence before the first sentence: Plaintext PIN shall not be supported in Unattended terminals (Terminal Type = ‘x4’, ‘x5’, or’ x6’).
  • Annex A, A2, Table 26: ➢ Add following footnote to the first item (“Plaintext PIN for ICC verification”): 21 Plaintext PIN is not allowed for Unattended terminals. countries. < Combination CVMs> [Changes to Book 3]
  • Section 10.5.4 ➢ Delete the entire section but retain the section header as below to keep the sequence of the following sections unchanged.

10.5.4 Section has been deleted

  • Figure 8 ➢ Delete the description “For Combination CVMs, both CVMs must be supported.” under the note. ➢ Delete the description “Z in Part 5 – Combo. CVM” from the box after the decision box “Is CVM Code Supported?”.
  • Figure 9 ➢ Delete the descriptions “Plaintext PIN verification performed by ICC and Signature” and “Enciphered PIN verification performed by ICC and Signature” under the note 1.
  • Figure 12 ➢ Delete the entire flow of the Combination CVMs.
  • Annex C3, Table 43 (“CVM Codes”): In the table, change “Plaintext PIN verification performed by ICC and signature” and “Enciphered PIN verification performed by ICC and signature” to “RFU” countries. countries. [Changes to Book 4]
  • Section 6.3.4: ➢ Among the four bullet points, delete the third bullet point related to Combined CVM. ⚫ For Combination CVMs, both CVM codes must be supported.
  • Section 6.3.4.5, Table 2: ➢ Delete the last two entries relating to Combined CVM: countries. [Changes to Book 1 and Book 2]
  • Section 4.1: ➢ Delete the entry of the TDOL. [Changes to Book 3]
  • Section 4.1: ➢ Delete the entry of the TDOL.
  • Section 5.4: ➢ Delete the third bullet point regarding the TDOL. ⚫ The Transaction Certificate Data Object List (TDOL) used to generate a TC Hash Value
  • Section 9.2.2: ➢ Delete the entire section.
  • Annex A1, Table 37: ➢ Delete the entries of the Default TDOL, TDOL, and TC Hash Value.
  • Annex A2, Table 38: ➢ Delete the entries of the TDOL and TC Hash Value.
  • Annex C5, Table 46, TVR Byte 5: ➢ For bit 8, change the value to 0 and the meaning to “RFU”. countries.
  • Common Core Definitions, 9.2.2 Transaction Certificate Data: ➢ Delete the entire section but retain the section header as below to keep the sequence of the following sections unchanged.

9.2.2 Section has been deleted

  • Common Core Definitions, Annex A Data Elements Dictionary: ➢ Delete the description above the Table CCD 6 and the Table CCD 6. [Changes to Book 4]
  • Section 4.1: ➢ Delete the entry of the TDOL.
  • Section 10.2, Table 7: ➢ Delete the entry of the Default TDOL from the table.
  • Section 12.1: ➢ Delete “and the TDOL” from the footnote 10. 10 At a minimum, all data listed in the Card Risk Management Data Object Lists and the TDOL shall be available at the point of transaction. countries. [Changes to Book 3]
  • Annex A1, Table 37 and Annex A2, Table 38: ➢ Delete following entries from the tables. ‘9F04’ (Amount, Other (Binary)) ‘9F3A’ (Amount, Reference Currency) ‘9F3B’ (Application Reference Currency) ‘9F43’ (Application Reference Currency Exponent) ‘81’ (Amount, Binary) ‘97’ (Transaction Certificate Data Object List (TDOL)) [Changes to Book 4]
  • Annex C Example Data Element Conversion: ➢ Delete Tag ‘81’ from the entry of Amount, Authorised. ➢ Delete Tag ‘9F04’ from the entry of Amount, Other. countries.

Legal Notice

The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications

countries.