KL Bulletin N°29: EMVCo Annual RSA Key Lengths Assessment

General Bulletin
ChipContactContactless Acceptance DeviceCardChip & PlatformNFC Consumer Device

Notice Bulletin No. 29 July 2025 EMV SWG NP62r2 EMVCo Annual Public Key Lengths Assessment EMVCo, LLC (“EMVCo”) has completed its annual review of the Certification Authority Public Key lengths and expiry dates for chip-basedpayments and makes the following recommendations to EMV®-based payment systems. For RSA keys:

  • 1408-bit keys are recommended to have expired 31 December 2024.
  • 1984-bit keys are recommended to have an anticipated lifetime to at least 31 December 2035. EMVCo does not project beyond a 10-year horizon. For ECC keys:
  • As noted in Book 2 v4.4 and Book E v1.1, new ECC payment system keys may be introduced into terminals.
  • 256-bit and 521-bit ECC keys are recommended to have an anticipated lifetime beyond 31 December 2035. Although EMVCo does not project beyond a 10-year horizon, in general 256-bit ECC keys are considered much more robust than 1984-bit RSA keys.
  • 521-bit ECC keys are included in EMV specifications for contingency purposes only. Payment systems will decide individually whether to adopt the recommendations made in this Bulletin and will notify their members of their final decision. Note that no certificate should be issued that expires later than the expiry date of the CA key. © 1994-2025 EMVCo, LLC. All rights reserved. Any and all uses of the EMV Specifications shall be permitted only pursuant to the terms and conditions of the license agreement between the user and EMVCo found at www.emvco.com. EMV® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries.