SB nº 313: Update to Book C-5
EMV® Specification Bulletin No. 313 First Edition May 2025 Confidential Updates to EMV® Book C-5
Applicability
This Specification Bulletin applies to:
- EMV Contactless Specifications for Payment Systems, Book C-5 – Kernel 5 Specification, Version 2.11, June 2023
Related Documents
- None
Effective Date
- October 1st, 2025
Description
This Bulletin describes updates to several sections in the EMV Book C-5 Specification. The main changes are as follows: 1. Outcome Parameter for End Application (with restart On-Device CVM): The status of UI Request on Outcome Present has been changed from “Processing Error” to “Not Ready”. 2. Clarification for TVR update before Generate AC processing: This specification bulletin is a clarification for TVR Byte 1 bit 3 (‘CDA Failed’) update in case of CDA failure. If CDA is failed due to 3.4.1.3, the Kernel shall set TVR Byte 1 bit 3 (‘CDA Failed’) to ‘1’ before Generate AC. If CDA is failed due to any reason other than 3.4.1.3, the Kernel shall set TVR Byte 1 bit 3 (‘CDA Failed’) to ‘1’ after Generate AC. 3. Update to the Requirement (Generate AC Response Analysis): The requirements have been updated to provide an End Application Outcome if the Terminal Interchange Profile does not indicate ‘EMV contact chip supported’. The following section provides details. CONFIDENTIAL.
2025 Details of the Changes 1 Description Change of Outcome Parameter for End Application (with restart - On-Device CVM) Replace the section 3.12.9.1 as follows. Requirement – On-Device CVM to be Performed 3.12.9.1 If the Kernel is informed that the transaction shall be reattempted to allow entry of a Confirmation Code into a mobile device, Then the Kernel shall provide an End Application Outcome with the following parameters: End Application: ・Start: B ・Online Response Data: N/A ・CVM: N/A ・UI Request on Outcome Present: Yes Message Identifier: ‘20’ (“See Phone for Instructions”) Status: Processing Error Not Ready Hold Time: 13 ・UI Request on Restart Present: Yes Message Identifier: ‘21’ (“Present Card Again”) Status: Ready to Read ・Data Record Present: No ・Discretionary Data Present: No ・Alternate Interface Preference: N/A ・Receipt: N/A ・Field Off Request: 13 ・Removal Timeout: Zero
2025 2 Clarification for TVR update before Generate AC processing in case of CDA failure (1) Replace the section 3.4.1.3 as follows.
3.4.1.3 If the Transaction Mode is ‘EMV Mode’ And Offline Data Authentication is supported (implementation and acquirer option) And the AIP (Tag ‘82’) indicates that CDA is supported (Byte 1 bit 1 is ‘1’) And any of the following Data Elements is absent from the card: Certification Authority Public Key Index (Tag ‘8F’) Issuer Public Key Certificate (Tag ‘90’) Issuer Public Key Exponent (Tag ‘9F32’) Issuer Public Key Remainder (Tag ‘92’), when required (based on the sizes of tags ‘9F46’ and ‘90’, when both are present) ICC Public Key Certificate (Tag ‘9F46’) ICC Public Key Exponent (Tag ‘9F47’) ICC Public Key Remainder (Tag ‘9F48’), when required (based on the ICC Public Key Length and the size of tag ‘9F46’, when both are present) Then the Kernel shall set TVR Byte 1 bit 6 (‘ICC Data Missing’) and Byte 1 bit 3 (‘CDA Failed’) to ‘1’.4 (except for when Issuer Public Key Remainder (Tag ‘92’) and ICC Public Key Remainder (Tag ‘9F48’) are not required)5 4 If the AIP (Tag ‘82’) indicates that CDA is supported (Byte 1 bit 1 is ‘1’), and if CDA processing failes due to any reason other than 3.4.1.3 such as CAPK index mismatch, kernel shall set TVR byte1bit3 (CDA failed) to “1” after Generate AC processing in accordance with the section 3.8.2.1. 5 If the kernel performs the validation of certificates during CDA Signature verification, it is not mandatory to check the absence of data elements and to set the TVR value described in the requirement 3.4.1.3
2025 (2) To ensure clarity of the requirements, remove section 3.4.1.4 and integrate its content as a note into section 3.4.1.3.
3.4.1.4 If the Transaction Mode is ‘EMV Mode’ And Offline Data Authentication is supported (implementation and acquirer option) And the Certification Authority Public Key corresponding to the CAPK index (Tag ‘8F’) provided by the card is not present in the Kernel configuration data, Then the Kernel shall set TVR Byte 1 bit 3 (‘CDA Failed’) to ‘1’. (Note: the kernel recovers the ICC public key later during the transaction to optimise the performance).
2025 3 Update to the Requirement – Generate AC Response Analysis Replace the section 3.8.1.6 as follows. Requirement – GENERATE AC Response Analysis 3.8.1.6 If the Status Word returned by the card is equal to ‘6984’, Then If the Terminal Interchange Profile (dynamic) indicates ‘EMV contact chip supported’ (byte 1 bit 2 = ‘1’), Then the Kernel shall terminate the transaction with a Try Another Interface Outcome as defined in section 3.12.6. Else The kernel shall terminate the transaction with End Application Outcome as defined in section 3.12.7. This Status Word indicates that the card is a dual-interface card that prefers to conduct the transaction using the contact interface.
2025
Legal Notice
Unless the user has an applicable separate agreement with EMVCo or with the applicable payment system, any and all uses of these Specifications is subject to the terms and conditions of the EMVCo Terms of Use agreement available at www.emvco.com and the following supplemental terms and conditions. The license granted in the EMVCo Terms of Use specifically excludes (a) the right to disclose, distribute or publicly display these Specifications or otherwise make these Specifications available to any third party, and (b) the right to make, use, sell, offer for sale, or import any software or hardware that practices, in whole or in part, these Specifications. Further, EMVCo does not grant any right to use the Kernel Specifications to develop contactless payment applications designed for use on a Card (or components of such applications). As used in these supplemental terms and conditions, the term “Card” means a proximity integrated circuit card or other device containing an integrated circuit chip designed to facilitate contactless payment transactions. Additionally, a Card may include a contact interface and/or magnetic stripe used to facilitate payment transactions. To use the Specifications to develop contactless payment applications designed for use on a Card (or components of such applications), please contact the applicable payment system. To use the Specifications to develop or manufacture products, or in any other manner not provided in the EMVCo Terms of Use, please contact EMVCo. These Specifications are provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of these Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of these Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with these Specifications. © 2025 EMVCo, LLC. All rights reserved. Reproduction, distribution and other use of this document is permitted only pursuant to the applicable agreement between the user and EMVCo found at www.emvco.com. EMV® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries.