Contact Terminal Level 2 – Implementation Conformance Statement

v4.4c Type Approval Forms
Contact Acceptance Device

Verify Form Data Export Form Data Import Form Data Level 2 – EMV® KERNEL Implementation Conformance Statement Version 44..44cc Version 4.3f ICS Reference Number and Validity Period (for EMVCo administrative use only) ICS Reference Number: Valid from: Valid to: Notice: This ICS form shall be completed for products submitted to receive EMVCo Level 2 testing and approval. The form shall be completed in its entirety. Part I

  • Administrative Product Provider Identification Company Legal Name: (As listed on the Letter of Registration) EMVCo Registration Number: Laboratory Identification Company Legal Name: EMVCo Registration Number: ICS Submission Type Select submission type For any submission except Initial, please provide the approval number of the Baseline configuration (cf Config ‘1C’ on the letter of approval, if already approved) Is this ICS a replacement of a previously accepted ICS? Yes No If Yes, please provide the reference number of the previously accepted ICS If Yes, please provide the reason for replacing the ICS If Yes, please provide details of ICS replacement If EMVCo approval is issued, the EMV Kernel identification information provided in Part II is utilized on the EMVCo approval notification and posted on the EMVCo website. This identification information must agree with the information provided on the approval request letter and test results submitted for EMVCo evaluation. Inconsistent identification information in these three documents may delay the approval process or may result in a decline for the approval request. If submitting a Configurable Kernel for type approval, then all configurable options must be defined in Parts II through V. These configurable options must show all values supported. Part VI is required to specify the vendor defined configurations of these options. If submitting multiple PIN pads for approval under the PIN Pad Change process, section IIb must be completed for each PIN Pad. Any PIN pad identified in section IIa will serve as the baseline for this process. PART IIa – Product Identification EMV Kernel Name This is the name of the overall EMV Kernel whether the Kernel is split in several submodules or in a single module. In case the Kernel is in a single physical location, the EMV Kernel Name maybe the same as Kernel Name below (first line of 'as tested in') EMV Kernel Version: EMV Kernel Java runtime machine Name (only in Case that the Kernel run on a JVM): EMV Kernel Java runtime machine Version (only in Case that the Kernel run on a JVM): Device/Terminal(s) Name within which the EMV Kernel will be tested (referred to 'As tested in' Name): The EMV Kernel may be contained within a single physical location, module, or library in which case the entries above must be complete. However, when the EMV Kernel is split across several physical component devices (e.g.: server, mobile etc.), All hardware components must be fully described below (Only first line if a single location, multiple lines if multiple locations): Note: If PIN Pad contains Kernel functions (such as PIN management), it shall be described below and in section ‘Part IIb
  • PIN Pad Identification’ Device / Terminal HW Name Type of Device Kernel Name (or sub-kernel if multiple location) Kernel Version (or subkernel if multiple location) Kernel Checksum (or subkernel if multiple location) OS Name (or sub-OS if multiple location) OS version (or subOS if multiple location) IFM (Level 1) Approval Reference1 Please identify the Device / Terminal within which the EMV Kernel will be tested, for information purposes only (multiple tick possible): Standard POS Standard POS with PIN Pad ATM Cash Register based Solution PC based Solution mPOS / Phablet 1 When supporting the PIN Change Process the IFM Approval Reference may vary for some PIN pads, if so these references must be identified in section IIb. Tablet Merchant Server Solution (closed environment) Cloud based Solution (open environment) Others If the answer to the above question is Yes for “others”, please describe the device/terminal with in which kernel is tested Is Device / Terminal within which the EMV Kernel will be tested PCI-PTS approved (For information purpose only)? If the answer to the previous question is yes, please provide the PCI-PTS Certificate reference Are Device / Terminal(s) within which the EMV Kernel is tested present in the Laboratory (Devices maybe not present ONLY for ATM or Petrol Station or Cloud or Server based Solutions) If the answer to the above question is “No”, are the Device / Terminal(s) following the Solution 1 (as per Administrative Process section 4.2.4)? (If the answer is ‘No’ the Laboratory shall request the EMVCo Acceptance before starting any test) If the answer to the two above question is “No”, please describe why the ATM or Petrol Station or Cloud or Server based Solutions cannot be located in the Laboratory premises If the Device / Terminal within which the EMV Kernel is tested is NOT present in the Laboratory, Product Provider understand he has to comply with the Sample retention described in the Administrative Process Section 4.2.4. PART IIb – PIN Pad Identification If the PIN is supported, is the PIN Pad Yes No transparent? If the PIN Pad is transparent, please confirm Yes you provided the requested transparency information as per Administrative Process section 2.7.7 The tables below shall be used to describe all PIN pads, including those defined in part IIa.
  • If a single PIN Pad is supported it must be described in the first Table below. Section VII, first line must also be filled.
  • In case the PIN Pad is the same device as the Device/terminal within which the Application Kernel will be tested (a single box), it must be described in the first Table below (copy from section IIa the 'Device/terminal Name' into the section IIb ' PIN Pad “Marketing name”).
  • For PIN Pad Change Process; the minimum number of PIN pads that must be supported is 1, there is no maximum number of PIN pads that may be submitted for the PIN Pad Change Process. If more PIN pads are submitted than space allows, an additional ICS Part IIb must be provided.
  • If PIN Pad is supported the question ‘is the Terminal equipped with a PIN Pad’ of section V and VII shall be answered with ‘yes’ (even if the PIN Pad is the same device as the Device/terminal within which the Application Kernel will be tested).
  • If this ICS is a subsequent submission with additional PIN Pad(s), make sure to assign to each new PIN Pad a number that has not been used for another PIN Pad during the previous session(s). PIN Pad PIN Pad “Marketing name” which will be submitted with the application kernel. PIN Pad software name and version: If the PIN Pad is Non Transparent, are the EMV functionality limited to PIN processing? Please note: in order for the PIN Pad to be eligible for this process the only EMV functions that may reside on the PIN pad are those related to PIN processing. List all EMV PIN processing functions residing on the PIN pad (only for Non Transparent PIN pad): PIN Pad combined with an IFM? IFM (Level 1) approval reference, if combined with PIN pad: PIN Pad Checksum: PIN Pad PIN Pad “Marketing name” which will be submitted with the application kernel. PIN Pad software name and version: If the PIN Pad is Non Transparent, are the EMV functionality limited to PIN processing? Please note: in order for the PIN Pad to be eligible for this process the only EMV functions that may reside on the PIN pad are those related to PIN processing. List all EMV PIN processing functions residing on the PIN pad (only for Non Transparent PIN pad): PIN Pad combined with an IFM? IFM (Level 1) approval reference, if combined with PIN pad: PIN Pad Checksum: EMV PIN Pad Identification PIN Pad “Marketing name” which will be submitted with the application kernel. PIN Pad software name and version: If the PIN Pad is Non Transparent, are the EMV functionality limited to PIN processing? Please note: in order for the PIN Pad to be eligible for this process the only EMV functions that may reside on the PIN pad are those related to PIN processing. List all EMV PIN processing functions residing on the PIN pad (only for Non Transparent PIN pad): PIN Pad combined with an IFM? IFM (Level 1) approval reference, if combined with PIN pad: PIN Pad Checksum: EMV PIN Pad Identification PIN Pad “Marketing name” which will be submitted with the application kernel. PIN Pad software name and version: If the PIN Pad is Non Transparent, are the EMV functionality limited to PIN processing? Please note: in order for the PIN Pad to be eligible for this process the only EMV functions that may reside on the PIN pad are those related to PIN processing. List all EMV PIN processing functions residing on the PIN pad (only for Non Transparent PIN pad): PIN Pad combined with an IFM? IFM (Level 1) approval reference, if combined with PIN pad: PIN Pad Checksum: EMV PIN Pad Identification PIN Pad “Marketing name” which will be submitted with the application kernel. PIN Pad software name and version: If the PIN Pad is Non Transparent, are the EMV functionality limited to PIN processing? Please note: in order for the PIN Pad to be eligible for this process the only EMV functions that may reside on the PIN pad are those related to PIN processing. List all EMV PIN processing functions residing on the PIN pad (only for Non Transparent PIN pad): PIN Pad combined with an IFM? IFM (Level 1) approval reference, if combined with PIN pad: PIN Pad Checksum: EMV PIN Pad Identification PIN Pad “Marketing name” which will be submitted with the application kernel. PIN Pad software name and version: If the PIN Pad is Non Transparent, are the EMV functionality limited to PIN processing? Please note: in order for the PIN Pad to be eligible for this process the only EMV functions that may reside on the PIN pad are those related to PIN processing. List all EMV PIN processing functions residing on the PIN pad (only for Non Transparent PIN pad): PIN Pad combined with an IFM? IFM (Level 1) approval reference, if combined with PIN pad: PIN Pad Checksum: PART IIc – Additional Operating System Identification This section applies to the Multi OS process only The tables below shall be used to describe the additional Operating Systems for the Multi OS process. When supporting the Multiple OS process indicate all EMV kernel operating systems and versions submitted for type approval at this time, in addition to the operating system defined in part IIa. Additional Operating System Identification EMV Kernel Operating System Name: EMV Kernel Operating System Version: I confirm that for this additional operating system to apply, no recompilation or linkage for the kernel code is needed and the kernel checksum and/or PIN pad checksum does not change Additional Operating System Identification EMV Kernel Operating System Name: EMV Kernel Operating System Version: I confirm that for this additional operating system to apply, no recompilation or linkage for the kernel code is needed and the kernel checksum and/or PIN pad checksum does not change Additional Operating System Identification EMV Kernel Operating System Name: EMV Kernel Operating System Version: I confirm that for this additional operating system to apply, no recompilation or linkage for the kernel code is needed and the kernel checksum and/or PIN pad checksum does not change Additional Operating System Identification EMV Kernel Operating System Name: EMV Kernel Operating System Version: I confirm that for this additional operating system to apply, no recompilation or linkage for the kernel code is needed and the kernel checksum and/or PIN pad checksum does not change PART III – Terminal Resident Data Objects Value Terminal Type: (if configurable, list all supported values 11 separated by a comma) 12 Warning: All Terminal Type value supported for 13 additional configuration shall be listed 14 15 16 21 22 23 24 25 26 34 35 36 Configurable? PART IV – EMV Specifications EMV Specification Date & Version: EMV Integrated Circuit Card Specifications for Payment Systems version 4.4, October 2022 PART V – Terminal Details Terminal Capabilities Card Data Input Capability Manual Key Entry Magnetic Stripe IC with Contacts CVM Capability Plaintext PIN for ICC Verification Enciphered PIN for online Verification Signature Enciphered PIN for offline Verification (RSA ODE) No CVM Required Enciphered PIN for offline Verification (ECC ODE) Does the Kernel support Biometric? If Yes:
  • The values in range 000110-001111 of the Book3, Table 39
  • CVM Codes are considered as recognized values for unsupported Biometric CVM Codes - the Kernel implements the Biometric flow ‘T’ of the Book3, figure 9
  • Biometric Data Objects as per Book3, Annex A1 are recognized by the Kernel, If no the kernel shall not support any Biometric requirements (the values in range 000110-001111 of the Book3, Table 39
  • CVM Codes are considered as RFU) Value Supported Yes No If Biometric supported, does the Kernel support Finger biometric verified offline (by ICC)? If Biometric supported, does the Kernel support Finger biometric verified online (by ICC)? If Biometric supported, does the Kernel support Facial biometric verified offline (by ICC)? Note: This Biometric CVM is not supported for approval and No testing in this version. In case your Product support it, please contact EMVCo If Biometric supported, does the Kernel support Facial biometric verified online (by ICC)? Note: This Biometric CVM is not supported for approval and No testing in this version. In case your Product support it, please contact EMVCo If Biometric supported, does the Kernel support Palm biometric verified offline (by ICC)? Note: This Biometric CVM is not supported for approval and No testing in this version. In case your Product support it, please contact EMVCo If Biometric supported, does the Kernel support Palm biometric verified online (by ICC)? Note: This Biometric CVM is not supported for approval and No testing in this version. In case your Product support it, please contact EMVCo If Biometric supported, does the Kernel support Iris biometric verified offline (by ICC)? Note: This Biometric CVM is not supported for approval and No testing in this version. In case your Product support it, please contact EMVCo If Biometric supported, does the Kernel support Iris biometric verified online (by ICC)? Note: This Biometric CVM is not supported for approval and No testing in this version. In case your Product support it, please contact EMVCo If Biometric supported, does the Kernel support Voice biometric verified offline (by ICC)? Note: This Biometric CVM is not supported for approval and No testing in this version. In case your Product support it, please contact EMVCo If Biometric supported, does the Kernel support Voice biometric verified online (by ICC)? Note: This Biometric CVM is not supported for approval and No testing in this version. In case your Product support it, please contact EMVCo If One of the Biometric CVM is supported, what is the Biometric Data Block Maximum Length supported? Security Capability Static Data Authentication and Dynamic Data Authentication (Mandatory for offline capable terminals) Card Capture Combined Dynamic Data Authentication / Application Cryptogram Generation (if CDA is supported it shall support one of the 4 modes described in EMV Book2) Extended Data Authentication (XDA) No Additional Terminal Capabilities Transaction Type Capability At least one of the following transaction types must be supported: Cash Goods Services Cash Back Inquiry Transfer Payment Administrative Cash Deposit Terminal Data Input Capability Does terminal have a keypad (If keypad is supported the terminal shall support one or more of the following key types:) Numeric Keys Alphabetic and Special Character Keys Command Keys Function Keys Terminal Data Output Capability Print, Attendant and/or Cardholder Display, Attendant and/or Cardholder Code Table 10 Code Table 9 Code Table 8 Code Table 7 Code Table 6 Code Table 5 Code Table 4 Code Table 3 Code Table 2 Code Table 1 Value Supported Application Selection How Many AIDs with the associated set of data (such as TAC,…) can be supported by the Application Kernel? (if unlimited number please enter 99) Support PSE selection Method Support Cardholder Selection & Confirmation Does the terminal have a preferred order of displaying applications Does the terminal perform partial AID selection Does the terminal have multi language support Does the terminal support the EMV Language Selection method Does the terminal support the Common Character Set as defined in Annex B Table 20 Book 4 Value Supported Yes Yes Selectable Kernel Configurations (MCK only) Is your Multi-Configuration Kernel capable of dynamically selecting a configuration at the time of transaction Value Supported Data Authentication During data authentication does the terminal check validity for revocation of Issuer Public Key Certificate When supporting certificate revocation, what is the Certificate Revocation List format? (CRL format must include: RID, CA Public Key Index, Certificate Serial Number, and optional additional data) Does the terminal contain a default DDOL (Mandatory for terminals supporting DDA) Value Supported Cardholder Verification Method Terminal supports bypass PIN Entry If the terminal supports bypass PIN Entry: When selecting to bypass a PIN method, all other PIN entry methods are also considered bypassed. Terminal supports Get Data for PIN Try Counter Terminal supports Fail CVM Are amounts known before CVM processing Value Supported Yes Terminal Risk Management Floor limit checking (Mandatory for offline only terminals and offline terminals with online capability) Random Transaction Selection (Mandatory for offline terminals with online capability, except when cardholder controlled) Velocity Checking (Mandatory for offline only terminals and offline terminals with online capability) Transaction Log Exception File Terminal Risk Management performed irrespective of AIP setting (expected behavior) Value Supported Yes Terminal Action Analysis Does the terminal support the Terminal Action Codes (If the answer is no, please contact EMVCo) Can the Terminal Action Codes be deleted or disabled? If yes, the default TAC values of the TAC-Online, TAC-default and TAC-denial shall be set to zeroes If Offline Only is supported, which option of the Offline Only Terminal processing is implemented? (according to Book3, section 10.7) If Online Only is supported, how does online only terminal process TAC/IAC-Default when unable to go online? Value Supported Completion Processing Transaction Forced Online Capability Transaction Forced Acceptance Capability Does the terminal support Issuer initiated Voice Referrals Does the terminal support a Default TDOL If a Default TDOL is supported, can this default TDOL be not configured (or not loaded) in the terminal Is the Default TDOL TVR bit set before or after the 1st Generate AC Terminal Action Analysis? (Note: When applicable, the setting/unsetting of the Default TDOL TVR bit according to the Default TDOL usage is always performed prior to the 1st Generate AC. However this TVR bit only impacts the 1st Generate AC TAA if it is set before the 1st Generate AC TAA is performed) Value Supported Exception Handling What is the POS Entry Mode value when IC cannot be read and the transaction falls back using Magstripe Value Supported Configurable: Miscellaneous Is the terminal equipped with a PIN Pad (shall be answered ‘yes’ if Offline or online PIN is supported) Is the amount and PIN entered at the same keypad Is the ICC/Magstripe Reader combined Does the terminal support account type selection Does the terminal support ‘on fly’ script processing (not recommended behavior) Is the Issuer Script device limit greater than 128 bytes If the Issuer Script device limit is greater than 128 bytes, what is the value supported (If unlimited please enter 0) Note: if the kernel supports unlimited script length, a value of 400 bytes shall be used for testing purpose Does the terminal support Internal Date Management (If the terminal is capable of managing the increment of dates internally without synchronization or instruction from the host, ‘Yes’ should be selected for this option) Is the Level 2 Contact Kernel Random Generator using the algorithm described in Book2, section 11.3 If the Level 2 Contact Kernel Random Generator is not using the algorithm described in Book2, section 11.3, is this function PCI approved? If the Level 2 Contact Kernel Random Generator is not using the algorithm described in Book2, section 11.3, describe the function (such as algorithm used, etc) Is the Random Generator function of the Level 2 Contact Kernel Software dependent on the Terminal Hardware? If answer to previous question is Yes, describe the Hardware (a clear description of the chipset is required) Are the Cryptographic functions (RSA, Hash, etc.) of the Level 2 Contact Kernel Software dependent on the Terminal Hardware? If answer to previous question is Yes, describe the Hardware (a clear description of the chipset is required) Is any other functions of the Level 2 Contact Kernel Software dependent on the Terminal Hardware? If answer to previous question is Yes, describe the functions and the Hardware (a clear description of the chipset is required) Value Supported Yes Configurable: If the answer to at least one of the 6 previous questions is Yes, do you plan to port the Kernel to other Terminals having the same Hardware component supporting these above functions (Family of Terminal)? Does the terminal support Receipt (by printing or any electronic means)? List the Currency Code(s) supported as for ISO 4217: (one currency shall be declared at a minimum, and up to 10 if multiple currencies are supported with at least one per currency exponent supported) Note: Changing from one currency supported to multiple is considered as a major change Does the terminal support the Application Selection Registered Proprietary Data (ASRPD)? List the Language(s) supported as for ISO 639 (minimum one shall be declared, and up to 10 if Multiple Languages are supported) Can the Kernel be configured so the data object ‘Terminal Risk Management Data’ ‘9F1D’ is absent or configured with no value (00 is a value)? Can the Transaction Sequence Counter (TSC) be personalized to any value? If answer to previous question is Yes, what is the Maximun Value of the Transaction Sequence Counter? Checksum Does the product comply with the Checksum rules as defined in Contact Terminal Level 2 administrative process If answer to previous question is No, the following question must be checked Yes:
  • This is an Initial submission or Subsequent submission or renewal of the original approved product prior to the effective date of checksum rules (cf Terminal Type Approval Bulletin No. 134) Configuration Checksum (Static Kernel only) Value Supported PART VI – Terminal Configurations When supporting a configurable kernel, each type approval session is applied to a number of vendor defined configurations. The table below shall be used to describe these configurations. The minimum number of configurations that must be supported is 1, there is no maximum number of configurations that may be submitted for type approval. If more than 10 configurations are submitted for type approval an additional ICS must be provided, detailing the additional configurations in Part VI. About Configuration unique numbers:
  • The unique number of the Baseline configuration (Baseline is always the column 1) is 01.
  • The Baseline configuration settings are always required in the ICS, whatever the submission (initial or subsequent submission). In case of Subsequent Submission, please copy the Baseline settings values submitted in the Initial Submission of this product.
  • Baseline configuration shall be the configuration, submitted during initial configuration, with the highest weight.
  • Please assign a unique number (02, 03, etc.) to each additional configuration listed in the table below.
  • If this ICS concerns a Static Kernel, the table below is left empty. The unique number of the configuration is 01 by default;
  • If this ICS is a subsequent submission with additional configuration(s), make sure to assign to each new configuration a number that has not been used for another configuration during the previous session(s). Configuration 01 unique nb. Identification Terminal Type Manual Key Entry Magnetic Stripe IC with Contacts Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Plaintext PIN Online Enciphered PIN Signature Offline Enciphered PIN (RSA) No CVM Offline Enciphered PIN No No No No No No No No No No (ECC) Biometric Configuration 01 unique nb. Offline Finger Online Finger Offline Facial No No No No No No No No No No Online Facial No No No No No No No No No No Offline Palm No No No No No No No No No No Online Palm No No No No No No No No No No Offline Iris No No No No No No No No No No Online Iris No No No No No No No No No No Offline Voice No No No No No No No No No No Online Voice No No No No No No No No No No SDA and DDA Card Capture CDA XDA No No No No No No No No No No Tran Type – Cash Tran Type – Goods Tran Type – Services Tran Type – Cash Back Tran Type
  • Inquiry Tran Type – Transfer Tran Type – Payment Tran Type – Administrative Tran Type – Cash Deposit Keypad Numeric Keys Configuration 01 unique nb. Alphabetic and Special Character Keys Command Keys Function Keys Print Display Code Table 10 Code Table 9 Code Table 8 Code Table 7 Code Table 6 Code Table 5 Code Table 4 Code Table 3 Code Table 2 Code Table 1 PSE Cardholder Confirmation Preferred display order? Partial AID Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Selection Multi language? EMV Language Selection method? Common Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Character Set Revocation of Issuer Public Key Certificate Certificate Revocation List Format Configuration 01 unique nb. Default DDOL Bypass PIN Entry Subsequent Bypass PIN Entry Get Data for PIN Try Counter Fail CVM Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes Amount known before CVM processing Floor limit checking Random Transaction Selection Velocity Checking Transaction Log Exception File Terminal Risk Management Yes Yes Yes Yes Yes Yes Yes Yes Yes Yes irrespective of AIP setting Terminal Action Codes supported Terminal Action Codes can be deleted/or disabled Offline Only Terminal processing Configuration 01 unique nb. TAC/IAC-Default process when unable to go online Forced Online Forced Acceptance Voice Referrals initiated by Issuer Default TDOL Default TDOL not loaded POS Entry Mode Amount and PIN entered on the same keypad Is the ICC/Magstripe Reader combined? Does the terminal support account type selection? ‘on fly’ script processing Is Issuer Script device limit > 128 bytes? If the Issuer Script device limit > 128 bytes, what is the value supported? Configuration 01 unique nb. Internal Date Management Does the terminal support Receipt? Configuration Checksum Total weight PART VII – Supported Combination(s) of PIN Pads / Configurations The table below shall be used to identify uniquely the supported Combinations of PIN Pads / Configurations.
  • The PIN Pad Unique numbers refer to those assigned in Part IIb of the present ICS but also to Part IIb of ICS used for previous submission(s) of the same product (if any).
  • The Configuration Unique numbers refer to those assigned in Part VI of the present ICS but also to Part VI of ICS used for previous submission(s) of the same product (if any).
  • Information provided in this table shall be exhaustive and consistent with the information of the section VII in ICS of the previous submission(s) (if any), so if a previous submission was made the table below contain also the information of these combinations. Supported combinations 01 02 03 04 Unique PIN Pad number 05 (as per 06 section IIb) 07 08 09 10 Unique Configuration number (as per section VI) 01 02 03 04 05 06 07 08 09 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 Part VIII
  • Digital Signatures Product Provider I hereby declare that the above referenced product currently is and will remain in compliance with the above referenced EMV specification for all mandatory and supported optional requirements. Comments Signature Laboratory I hereby declare that this ICS document has been reviewed, and that all product information is consistent throughout the ICS. Comments Signature EMVCo Approval Secretariat Signature V241213 Copyright ©2025 EMVCo, LLC. All rights reserved. ICS Contact L2 – version 4.4c ICS Reference Number: of 25