EMVCo Common Core Definitions Level 1 & Level 2 Implementation Conformance Statement
Export Form Data Import Form Data EMVCo Common Core
Definitions
Level 1 & Level 2 Implementation Conformance Statement Version 4.4a ICS Reference Number and Validity Period (for EMVCo administrative use only) ICS Reference Number: Valid from: Valid to: Notice: This ICS form shall be completed for card products submitted for CCD Level 1 & Level 2 Functional evaluations. The form shall be completed in its entirety. All Yes and No questions shall be answered. If a feature/option is NOT supported, i.e. a question is answered “No,” the sub-questions for that feature/question shall be left blank. A
- Administrative Product Provider Identification A.1.1
- Company Legal Name: (As listed on the Letter of Registration) A.1.2 – EMVCo Registration Number: Level 1 Protocol Laboratory Identification A.1.3
- Company Legal Name: A.1.4 – EMVCo Registration Number: Level 2 Laboratory Identification A.1.5
- Company Legal Name: A.1.6 – EMVCo Registration Number: ICS Submission Type A.2.1
- Select submission type A.2.2
- For any submission except Initial, please provide the EMVCo letter of approval reference number of the previously approved product A.2.3
- Is this ICS a replacement of a previously accepted ICS? Yes No A.2.4
- If Yes. please provide the reference number of the previously accepted ICS A.2.5
- If Yes, please provide the reason for replacing the ICS A.2.6
- If Yes, please provide details of ICS replacement 18 Product Specification & Non-CCD Test Cases
References
Name Version Number Release Date Released by A.3.1 – EMV Specification EMV Integrated Circuit 4.4 Card Specifications for Payment Systems Level 1 Specifications 1.0 for Payment Systems
- EMV Contact Interface Specification A.3.3
- Owner Specification(s) for CCD application(s) A.3.4
- Non-CCD Test Cases A.3.5
- Other Specification(s) for Operating System A.3.6
- Other Specification(s) for non CCD application(s) Oct 2022 Oct 2022 Audit Report Tracking Number 18 Product and Chip Descriptions A.5.1 – Product Name: Product Version: (This is the name that will appear on the Approved Products List) A.5.2 – Who is the Card Manufacturer who will be producing the test cards being submitted for testing: A.5.3
- Chip Provider: A.5.4
- Chip Type or Identifier: A.5.5
- EMVCo IC Compliance Certificate reference number: Date: A.5.8
- Operating System Name: A.5.9
- Operating System Version Number: Chip Feature
Description
A.5.10 – RAM size (Kbytes) A.5.11 – ROM size (Kbytes) A.5.12 – Total EEPROM or Flash size (Kbytes) A.5.13 – Available EEPROM or Flash size (Kbytes)* A.5.14 – CPU (8, 16 or 32 bit etc.) A.5.15
- Crypto coprocessor present? Yes No A.5.16 – RSA implementation supported by the card * Free EEPROM or Flash size available for initialization and personalization of the application(s) listed in Section A.6.1 (excluding any memory utilized for the card operating system). 18 Applications on the Card A.6.1 – CCD Application(s) if applicable* Name Version Developer Functional Description AID or File ID Code Loaded A.6.2 – Other Application(s) if applicable Name Version Developer Functional Description AID(s) or File ID(s) of the actual application Code Loaded * Note: For testing purposes, ‘multiple application’ is defined by several instances of the same or different CCD application code with each instance having its own independent application life cycle – please list the AIDs for all instances of the application under the AID column. Multiple AIDs that share the same instance are not considered as multiple applications – in such a case, please list only one AID for each instance of the application under the AID column. Please also specify the number of AIDs listed here in L2.3.1. 18 Applications Interaction with the CCD application A.7.1
- Do any other applications interact with the CCD application? Yes No A.7.2
- If yes, describe how the other applications interact with the CCD application (Data shared, functions shared). Please provide details below. Limitation on simultaneous personalization and activation of all applications listed in section A.6 A.7.3
- Is there any limitation that precludes submitting card images for testing with all applications personalized and activated simultaneously? (e.g. restriction on EEPROM size, other application selected by default, etc.) Yes No A.7.4
- If yes, please describe the limitation below. Please also list in A.7.5 and A.7.6 the original and additional multi-application configurations that will be submitted for testing. A.7.5
- Original multi-application configuration (submitted on all card images for testing): A.7.6
- Additional multi-application configurations (submitted on card images listed in the latest Card Approval Communication N°69 for non-regression testing): 18 EMV Level 1 Electrical Characteristics L1E.1 – Sample information L1E.1.1 – EMV Contact protocol type(s) supported? L1E.2 – Card Class L1E.2.1
- Class A Supported? L1E.2.2
- Class B Supported? L1E.2.3
- Class C Supported? T=0 T=1 Yes No Yes No Yes No EMV Level 1 Protocol Characteristics L1P.1 – Answer to Reset (ATR) L1P.1.1
- Hex values (with no space and no wildcard ‘XX’) returned by the ICC in response to cold reset: (Provide the longest historical byte string the card can support) Note: Products that are exactly the same except for the ATR historical bytes may benefit from the ICS and LoA of the product tested L1P.1.1.1 – Is TA2 returned with b5 = 0 (specific mode, parameters defined by the interface bytes) in the Cold ATR? Yes No L1P.1.1.2 – Is the Cold ATR EMV Compatible? Yes No An ATR is EMV compatible when it shall be accepted by at least one generation of EMV terminals. L1P.1.1.3 – Is the Cold ATR EMV Compliant? Yes No L1P.1.2
- Hex values returned by the ICC in response to warm reset: (Provide the longest historical byte string the card can support) Transport Protocol L1P.2 – T = 0 supported? Yes No L1P.2.1
- Can the card issue procedure byte ‘60’ to request a Work Waiting Time extension? Yes No L1P.2.1.1
- If yes, can the card issue procedure byte ‘60’ to request a Work Waiting Time extension, during any command & response exchange of the payment application? Yes No L1P.2.1.1
- If Yes, describe how and where in the transaction this will occur. Please provide details below. L1P.2.1.2
- If yes, does the card issue procedure byte ‘60’ to request Yes No a Work Waiting Time extension, during ICC L1 testing? 18 L1P.3 – T = 1 supported? Yes No L1P.3.1
- Can the card issue a waiting time extension request, S (WTX request) block? Yes No L1P.3.1.1 – If yes, can the card issue a waiting time extension request, S (WTX request) block, during any command & response exchange of the payment application? Yes No L1P.3.1.1.1
- If Yes, describe how and where in the transaction this will occur. Please provide details below: L1P.3.1.2
- If yes, does the card issue a waiting time extension request, S (WTX request) block, during ICC L1 testing? Yes No L1P.3.2
- Value of IFSC L1P.3.3
- Can the ICC initiate chaining? Yes No L1P.3.3.1
- If yes, can the card initiate chaining, during any command & response exchange of the payment application? Yes No L1P.3.3.1.1
- If Yes, describe how and where in the transaction this is initiated? Please provide details below: L1P.3.3.2
- If yes, does the card initiate chaining, during ICC L1 testing? Yes No L1P.3.4
- Can the ICC by means of chaining receive a C-APDU command Yes No of length > IFSC? L1P.3.4.1 – If yes, can the ICC by means of chaining receive a C- Yes No APDU command of length > IFSC, during any command & response exchange of the payment application? L1P.3.4.1.1
- If yes, specify such C-APDU command and its response. Please provide details below: L1P.3.4.2
- If yes, does the ICC by means of chaining receive a CAPDU command of length > IFSC, during ICC L1 testing? L1P.4
- Dynamic Calculations L1P.4.1
- Can the ATR timings be impacted by any dynamic computation during the card reset? If Yes, please submit card(s) which display different timings. L1P.4.1.1
- If Yes, please provide details below: Yes No Yes No Yes No 18 Level 2 Additional Information for preparation of Level 1 test tool L1L2.1 – PSE SUPPORTED? Yes No L1L2.1.1
- FCI Data: returned by card L1.L2.1.2 – List of READ RECORD Commands and Responses: Command Response L1L2.1.3
- SFI of Directory File and Record Number L1L2.2 – Direct Select supported? L1L2.2.1
- EMV Application Name: Yes No L1L2.2.2 – Is there any dynamic Yes No computations or internal check that could make variable the duration of the SELECT command? L1L2.2.2.1
- If yes, describe the worst case L1L2.2.3 –Is this EMV application implicitly selected by Cold Reset? Yes No L1L2.2.3.1
- If no, please state ADF or Name of the application implicitly selected by Cold Reset, if any: L1L2.2.4 –Is this EMV application implicitly selected by Warm Reset? Yes No L1L2.2.4.1
- If no, please state ADF or Name of the application implicitly selected by Warm Reset, if any: L1L2.3 – DYNAMIC DATA AUTHENTICATION supported? L1L2.4
- Enciphered PIN supported? Yes No Yes No L1L2.4.1- if yes, what is the max length of the private key? 18 L1L2.5 – 1st GENERATE AC L1L2.5.1 - 1st GAC Command L1L2.5.2
- Maximum Response size (depending if CDA is supported) L1L2.7 – 2nd GENERATE AC L1L2.6.1 - 2nd GAC Command L1L2.6.2
- Maximum Response size (depending if CDA is supported) 18 L2
- EMV Level 2 L2.0
- Implementer Options L2.0.1 – Cryptogram Version supported Version & Cryptogram Confirmation L2.1 – MAC longer than 4 supported? L2.1.1
- Is MAC with length equal to 5 supported? L2.1.2
- Is MAC with length equal to 6 supported? L2.1.3
- Is MAC with length equal to 7 supported? L2.1.4
- Is MAC with length equal to 8 supported? Application Selection L2.2 – PSE supported? SELECT Command L2.2.1
- FCI Maximum Length READ RECORD Command L2.2.2
- SFI value(s) for the DIR File L2.2.3
- Number of records supported L2.2.4
- Maximum Record size (bytes per record) L2.2.5
- Minimum Record size (bytes per record) L2.2.6
- How many template ‘61’ can be loaded in Records L2.3 – ADF L2.3.1
- How many CCD application AIDs are supported? SELECT Command L2.3.2
- FCI Maximum Length Yes No Yes No Yes No Yes No Yes No Yes No 18 Initiate Application Processing (GPO) L2.4 – PDOL supported? PDOL Management L2.4.1 -How many PDOL are supported (count only those that affect CCD behaviour) L2.4.2
- Content of PDOL (list only those that affect CCD behaviour) L2.4.3 -How many PDOL related data set (per PDOL) are supported (count only those that affect CCD behaviour) L2.4.4
- Value of PDOL data (list only those that affect CCD behaviour)** L2.4.5
- PDOL related data making the transaction initialisation to be rejected (if existing) L2.4.6
- Can this option be not activated (or not personalised)? Read Application Data L2.5 – READ RECORD Command L2.5.1 - [SFI 11 to 20] range supported L2.5.2 - [SFI 21 to 30] range supported L2.5.3 -List the SFI value(s) supported (all ranges) L2.5.4
- Number of Records supported L2.5.5
- Maximum Record size (bytes per record) L2.5.6
- Minimum Record size (bytes per record) Yes No Yes No Yes No Yes No 18 Data Authentication L2.6 – Public Keys L2.6.1
- Maximum CA Public Key length L2.6.2
- Maximum Issuer Public Key length L2.6.3 – If Maximum CA key size is different from the pre-determined EMVCo test keys please provide CA public key value for testing L2.6.4 – If Maximum issuer key size is different from the pre-determined EMVCo test keys please provide Issuer public key value for testing L2.7 – SDA supported? * Yes No L2.8 – DDA supported? * L2.8.1
- Maximum ICC Public Key Length Yes No L2.8.2
- If Maximum key size is different from the pre-determined EMVCo test keys please provide ICC public key value (modulus and exponent) for testing L2.8.3
- Odd Key Length supported? L2.8.4 Can this option be not activated (or not personalised)? L2.9 – CDA supported? * L2.9.1
- Maximum ICC Public Key length Yes No Yes No Yes No L2.9.2
- If Maximum key size is different from the pre-determined EMVCo test keys please provide ICC public key value (modulus and exponent) for testing L2.9.3
- Odd Key Length supported? Yes No L2.9.4
- Can this option be not activated (or not personalised)? Yes No Note: * At least one of the options SDA, DDA, or CDA must be supported. 18 Cardholder Verification L2.10 – VERIFY Command L2.10.1
- PIN lengths supported L2.10.2
- PIN Try Limit values supported L2.11 – Enciphered PIN supported? L2.11.1
- If Enciphered PIN and DDA/CDA supported can the ICC Public key be different? L2.11.2
- If Enciphered PIN and DDA/CDA supported can the ICC Public key be the same? L2.11.3
- Maximum ICC Public Key length L2.11.4
- If Maximum key size is different from the pre-determined EMVCo test keys please provide ICC public key value (modulus and exponent) for testing L2.11.5
- Odd Key Length supported? L2.11.6
- Can this option be not activated (or not personalised)? Yes No Yes No Yes No Yes No Yes No Card Action Analysis L2.12 – CDOL Management L2.12.1
- How many CDOL1/CDOL2 related data are supported (count only those that affect CCD behaviour) L2.12.2
- Content of CDOL1 (list only those that affect CCD behaviour) L2.12.3
- Content of CDOL2 (list only those that affect CCD behaviour) L2.12.4
- Value of CDOL1 data (list only those that affect CCD behaviour)** L2.12.5
- Value of CDOL2 data (list only those that affect CCD behaviour)** L2.12.6
- Group of CDOL1/CDOL2 by CCD behaviour L2.13 – GENERATE AC Command L2.13.1
- Is the CCD application able to Yes No detect that the Terminal is Offline Only? L2.13.2
- Is the CCD application able to Yes No detect that the Terminal is Online Capable? L2.13.3 – Does the CCD application Yes No support multiple risk management configurations including Online Only? L2.13.3b – Does the CCD application only Yes No support online only configuration? ** For example if the CDOL1 requests the Terminal Type, the CCD application may have different behaviour depending if it is an Offline Only terminal or if it is an Online/Offline Terminal. In that case, there are two different behaviours; therefore, both terminal types must be listed in this ICS section. 18 Issuer Scripts L2.14 – APPLICATION BLOCK Command L2.14.1
- Supported before 2nd Yes No GENERATE AC? L2.14.2
- Supported after 2nd GENERATE Yes No AC? L2.14.3
- Second nibble range of the CLA byte (with first nibble is ‘8’) supported (different from ‘C’) L2.15 – APPLICATION UNBLOCK Command L2.15.1
- Supported before 2nd Yes No GENERATE AC? L2.15.2
- Supported after 2nd GENERATE Yes No AC? L2.15.3
- Second nibble range of the CLA byte (with first nibble is ‘8’) supported (different from ‘C’) L2.16 – CARD BLOCK Command L2.16.1
- Supported before 2nd Yes No GENERATE AC? L2.16.2
- Supported after 2nd GENERATE Yes No AC? L2.16.3
- Second nibble range of the CLA byte (with first nibble is ‘8’) supported (different from ‘C’) L2.17 – PIN CHANGE / UNBLOCK Command L2.17.1
- Supported before 2nd Yes No GENERATE AC? L2.17.2
- Supported after 2nd GENERATE Yes No AC? L2.17.3
- Second nibble range of the CLA byte (with first nibble is ‘8’) supported (different from ‘C’) L2.18 – Additional SCRIPT Command without Secure Messaging for Confidentiality (without tag ‘87’) L2.18.1 – L2.18.2
- L2.18.3
- L2.18.4
- L2.18.5
- List of script commands Supported Supported Second nibble Additional supported by the application before 2nd after 2nd range of the SCRIPT as additional functionality GEN AC? GEN AC? CLA byte (with Command with first nibble is tag ‘81’ ‘8’) supported supported? (different from ‘C’) Yes Yes Yes No No No Yes Yes Yes No No No Yes Yes Yes No No No Note: If there are more than 3 Additional SCRIPT Command without Secure Messaging for Confidentiality (without tag ‘87’), list them here and provide the information appropriate for L2.18.2, L2.18.3, L2.18.4, and L2.18.5. 18 L2.19 – Additional SCRIPT Command with Secure Messaging for Confidentiality (with tag L2.19.1 – L2.19.2
- L2.19.3
- L2.19.4
- List of script commands supported by the application Supported before 2nd Supported after 2nd Second nibble range of the as additional functionality GEN AC? GEN AC? CLA byte (with first nibble is ‘8’) supported (different from ‘C’) Yes Yes No No Yes Yes No No Yes Yes No No Note: If there are more than 3 Additional SCRIPT Command with Secure Messaging for Confidentiality (with tag ‘87’), list them here and provide the information appropriate for L2.19.2, L2.19.3, and L2.19.4. ‘87’) L2.20 – Can the CVR bits ‘Number of Issuer Script commands’ be reset after successful Authentication? Yes No Log L2.22 – LOG file supported? L2.22.1a
- SFI value(s) supported for the Log File L2.22.2
- Records numbers supported for the Log File L2.22.3
- List the different Log Entry(s) supported L2.22.4
- List the different Log Format(s) supported L2.22.5
- Can this option be not activated (or not personalised)? Specific Data L2.23 – ATC L2.23.1
- ATC range L2.23.2
- Maximum value of the ATC L2.24 – CSU L2.24.1
- CSU Issuer discretionary data Yes No Yes No 18 L2.25 – Proprietary Authentication Data (greater than zero) supported? L2.25.1
- What is (are) the length(s) supported? L2.25.2
- Can it be included in the ARPC calculation (CSU Byte 1 bit 8 supported)? L2.25.3
- What is (are) the Proprietary Authentication Data Value(s), or how it is calculated? L2.26 – Currency Code X L2.26.1
- What is the currency X (international) used by the test cards? L2.27 – Currency Code Y L2.27.1
- What is the currency Code Y (Domestic) used by the test cards? Yes No Yes No Beyond CCD components Check-list L2.28 – Are EMV Reserved Tags used? Yes No L2.28.1
- List Reserved Tags and formats of the associated data objects L2.29 – Are Payment Scheme Reserved Tags used? L2.29.1
- List Reserved Tags and formats of the associated data objects L2.30 – Are EMV Reserved Tags retrievable by GET DATA? Yes No Yes No L2.30.1
- List Reserved Tags retrievable by GET DATA L2.31 – Are Payment Scheme Reserved Tags retrievable by GET DATA? Yes No L2.32 L2.33 L2.34 L2.31.1 List Reserved Tags retrievable by GET DATA – Issuer Application Data different from CCD one? L2.32.1
- Describe the 32 bytes of Issuer Application Data (Counter, Issuer Discretionary Data,…) – APPLICATION UNBLOCK Command L2.33.1
- What is the procedure to perform an APPLICATION UNBLOCK (if supported)? – SELECT Command L2.34.1 – NON-CCD CLA byte value(s) supported Yes No L2.34.2 – NON-CCD P1/P2 bytes value(s) supported 18 L2.35 – READ RECORD Command READ RECORD used during PSE Selection (if supported) L2.35.1 – NON-CCD CLA byte value(s) supported L2.35.2 – NON-CCD P1/P2 bytes value(s) supported READ RECORD used during Read Application Data L2.36 L2.37 L2.35.3 – NON-CCD CLA byte value(s) supported L2.35.4 – NON-CCD P1/P2 bytes value(s) supported – GET PROCESSING OPTIONS Command L2.36.1 – NON-CCD second nibble value(s) of the CLA byte (with first nibble is ‘8’) supported – GENERATE AC Command L2.37.1
- Second nibble range of the CLA byte (with first nibble is ‘8’) supported L2.38 – INTERNAL AUTHENTICATE Command (if DDA is supported) L2.38.1
- NON CCD CLA byte value(s) supported L2.38.2
- NON CCD P1/P2 bytes value(s) supported L2.39 – VERIFY Command L2.39.1
- NON CCD CLA byte value(s) supported L2.39.2
- NON CCD P1/P2 bytes value(s) supported L2.40 – GET CHALLENGE Command (if DDA is supported) L2.40.1 – NON-CCD CLA byte value(s) supported L2.40.2 – NON-CCD P1/P2 bytes value(s) supported L2.41 – GET DATA Command L2.41.1 – NON-CCD CLA byte value(s) supported L2.41.2 – NON-CCD P1/P2 bytes value(s) supported L2.42 – Non EMV Commands L2.42.1
- Does the CCD Application Yes No support Non EMV Commands? (other than Proprietary Script Commands) L2.42.2
- Please list all supported pairs of CLA/INS (when CLA byte has one of the following values: ‘00’, ’04, ‘08’, ‘0C’, ‘80’, ‘84’ ‘88’, ‘8C’, ‘9x’ or ‘Ex’) 18 Digital Signatures Product Provider I agree and understand that the cards submitted for Functional Level 1, Functional Level 2 and Security Evaluation testing are exactly the same. Also if an issue requires a change to the code of the card or the addition of a patch or new executable code to the card, EMVCo must be notified. In case of such change, new cards must be submitted for Functional Level 1 and Functional Level 2 and Security Evaluation testing. I hereby declare that the above referenced product currently is and will remain in compliance with the above referenced EMV specification for all mandatory and supported optional requirements. Comments Signature Level 1 Laboratory I hereby declare that this ICS document has been reviewed, and that all product information is consistent throughout the ICS. Comments Signature Level 2 Laboratory I hereby declare that this ICS document has been reviewed, and that all product information is consistent throughout the ICS. Comments Signature EMVCo Approval Secretariat Signature 18