EMV® Terminal Type Approval Contactless Product – Administrative Process

v2.11c.r Type Approval Process
Contactless Acceptance Device

EMV® Terminal Type Approval Contactless Product __________________________________________________ Administrative Process Version 2.11c.r September 2025

EMV® Type Approval Terminal Contactless Product Administrative Process

Legal Notice

Page i / v Legal Notice This document is subject to change by EMVCo at any time. This document does not create any binding obligations upon EMVCo or any third party regarding the subject matter of this document, which obligations will exist, if at all, only to the extent set forth in separate written agreements executed by EMVCo or such third parties. In the absence of such a written agreement, no product provider, test laboratory or any other third party should rely on this document, and EMVCo shall not be liable for any such reliance. No product provider, test laboratory or other third party may refer to a product, service or facility as EMVCo approved, in form or in substance, nor otherwise state or imply that EMVCo (or any agent of EMVCo) has in whole or part approved a product provider, test laboratory or other third party or its products, services, or facilities, except to the extent and subject to the terms, conditions and restrictions expressly set forth in a written agreement with EMVCo, or in an approval letter, compliance certificate or similar document issued by EMVCo. All other references to EMVCo approval are strictly prohibited by EMVCo. Under no circumstances should EMVCo approvals, when granted, be construed to imply any endorsement or warranty regarding the security, functionality, quality, or performance of any particular product or service, and no party shall state or imply anything to the contrary. EMVCo specifically disclaims any and all representations and warranties with respect to products that have received evaluations or approvals, and to the evaluation process generally, including, without limitation, any implied warranties of merchantability, fitness for purpose or noninfringement. All warranties, rights and remedies relating to products and services that have undergone evaluation by EMVCo are provided solely by the parties selling or otherwise providing such products or services, and not by EMVCo, and EMVCo will have no liability whatsoever in connection with such products and services. This document is provided "AS IS" without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in this document. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON- INFRINGEMENT, AS TO THIS DOCUMENT. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to this document. EMVCo undertakes no responsibility to determine whether any implementation of this document may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of this document should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, this document may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement this document is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party's infringement of any intellectual property rights in connection with this document.

EMV® Type Approval Terminal Contactless Product Administrative Process Revision Log – Version 2.11c.r

/ v Revision Log – Version 2.11c.r The following changes have been made to the document since the publication of Version 2.11c. Some of the numbering and cross references in this version have been updated to reflect changes introduced by the published bulletins. The numbering of existing requirements did not change, unless explicitly stated otherwise. Reason for change Editorial Updates

EMV® Type Approval Terminal Contactless Product Administrative Process Contents Contents

1. 1. 1. 1. 1.4. 1. 2. 2.1. 2.1. 2.1. 2.1. 2.1. 2. 2.2. 2.2. 2.2. 2.2. 2.2. 2.2. 2.2. 2. 2.3. 2.3. 2.3. 2.3. 2.3. 2. 2.4. 2.4. 2. 3. 3. 3.

EMV® Type Approval Terminal Contactless Product Administrative Process Contents

/ v 3. 3. 3.5. 3.5. 4. 4. 4. 4.3. 4.3. 4.3. 4.3. 4.3. 4.3. 4. 4.4. 4.4. 4.4. 4.4. 5. 5. 5. 10. 10. 10.2. 10.2. 10.2. 10.2. 11. 11. 11.2.1 ‘Contactless Product submitted for the initial Approval contains a Contactless Kernel C-REGx 56

EMV® Type Approval Terminal Contactless Product Administrative Process Contents Page v / v 11.2. 13.

EMV® Type Approval Terminal Contactless Product Administrative Process Introduction

/ 60 1

Introduction

EMVCo, LLC (“EMVCo”) is the manager of the EMV Contactless Specifications for Payment Systems hereinafter called the EMV Contactless Specifications. The objective of this document is to provide a Type Approval process for Contactless Products implementing the following specifications:

  • EMV Contactless Specifications for Payment Systems – Book A
  • EMV Contactless Specifications for Payment Systems – Book B
  • EMV Contactless Specifications for Payment Systems – Books C-n Note: EMV Level 1 Contactless Specifications for Payment Systems is addressed in a separate process document dedicated to Level 1. Common industry practice requires Product Providers to accommodate local Acquirer requirements in their Product. These Acquirer requirements are out of the EMVCo type approval scope. The Product Software Architecture plays a significant role in determining whether complying with non-EMV acquirer requirements are likely to impact the approved EMV Contactless product. EMVCo limits type approval to the EMV Contactless product, leaving the responsibility to the appropriate local acquiring entity (also referred to as the owner of the environment of use) to validate continued compliance with the EMV Contactless Specifications functionality in the integrated acquiring environment. All readers of this document are advised that type approval, when granted by EMVCo, shall not be construed as a warranty or representation of any sort, nor may it be relied upon by any party as an assurance of quality or functionality of any product or service. Please note the legal notice stated above at of this document for important limitations on the scope of type approval.

1.1 Audience The target audience of this document includes:

  • Product Providers
  • Laboratories recognised to perform the type approval tests
  • Auditors acting on behalf of EMVCo 1.2 Normative

References

Reference [N1] [N2] Table 1: Reference Documents Publication name Bookmark EMV Integrated Circuit Card Specification for Version 4.4 – October Payment Systems – Book 1 – Application 2022 Independent ICC to Terminal Interface Requirements EMV Integrated Circuit Card Application Version 4.4 – October Specification for Payment Systems – Book 2 – 2022 Security and Key Management

EMV® Type Approval Terminal Contactless Product Administrative Process Introduction

/ 60 [N3] EMV Integrated Circuit Card Terminal Specification Version 4.4 – October for Payment Systems – Book 3 – Application 2022 Specification [N4] EMV Integrated Circuit Card Terminal Specification Version 4.4 – October for Payment Systems – Book 4 – Cardholder, 2022 Attendant, and Acquirer Interface Requirements [Book A] EMV Contactless Specifications for Payment Latest version available Systems – Book A – Architecture and General Requirements [Book B] EMV Contactless Specifications for Payment Latest version available Systems – Book B – Entry Point Specification [Book C-n] EMV Contactless Specifications for Payment Latest version available Systems – Book C-n – kernel Specification [Book D] EMV Level 1 Contactless Specifications for Payment Latest version available Systems – EMV Contactless Interface Specification [ICS] EMVCo Type Approval Contactless Product - Latest version available Implementation Conformance Statement [TA A&B] EMVCo Type Approval Contactless Product - Books Latest version available A & B Test Plan [TA P] EMVCo Type Approval Contactless Product - Latest version available Performance Test Plan [TA C- EMVCo Type Approval Contactless Product - C-8 Latest version available 8RRP] RRP Test Plan [TA M] EMVCo Type Approval Contactless Product- Latest version available Modular Test Plan [TA Archi] EMVCo Type Approval Contactless Product - Latest version available Modular Architecture Requirements [TA EMVCo Type Approval Contactless Product – Level Latest version available ADMIN L1] 1 Administrative Process [TA C-n] Kernel Test Plans - Functional Test Plan Latest version available [TA INT C- Integration Test Plans Latest version available n] this includes all additional testing required by each Payment System, such as:

  • Integration Test Plan
  • Combination Test Plan
  • Interoperability Test Plan [TB1] EMV Terminal Type Approval Bulletin 185 Latest version available 1.3

Definitions

The following terms are used in this specification:

EMV® Type Approval Terminal Contactless Product Administrative Process Introduction Card - A payment card as defined by a payment system.

/ 60 CATA – EMVCo Type Approval secretariat. Check Sum - A Product Provider-generated value (minimum 4 bytes) for each module. This checksum must be a unique value for each module. The method or algorithm used for generating the checksum is left to the discretion of the Product Provider. For example, a Product Provider may choose to implement SHA-1 or CRC. These values shall be easily retrievable for each Kernel Module, Software Module, External Libraries or Entry Point Module when loaded in the Product and this for comparative purposes. Refer to Appendix B: Checksum Implementation Rules for more details on Checksum defined rules. Compliance - Meeting all the requirements including any implemented optional requirement(s). Contactless Kernel C-REGX – The proprietary kernel software located in the Contactless Product where x is a registered Kernel ID using the EMVCo kernel ID registration process. CREGX does not refer to EMVCo Kernel C-n. EMVCo Software – The part of the software present in the Product which follows EMVCo requirements (i.e. Books A, B and C-n) Entry Point Module – A POS System software managing application (AID) and kernel selection according to [Book B]. Family of Product - A Family of Products means multiple Contactless Products having the same Hardware and Communication Configuration:

  • CPU
  • Operating System
  • RAM (same or higher)
  • Communication Interface and API with the PCD Function – A process accomplished by one or more commands and resultant actions that are used to perform all or part of a transaction. Implementation Conformance Statement (ICS) - A form completed by the product provider. The written statement lists all optional functions as specified in the EMV Contactless Specifications. Integrated circuit(s) - Electronic component(s) designed to perform processing and/or memory functions. EMV® Type Approval Terminal Contactless Product Administrative Process Introduction / 60 International Organization for Standardization (ISO) - An international body that provides standards for financial transactions and telecommunication messages. ISO works in conjunction with the International Telecommunication Union (ITU) for standards that affect telecommunications. ISO supports specific technical committees and work groups to promulgate and maintain financial service industry standards. Interface - Technical requirements for exchanging data and functions between two software modules. Kernel C-n - Is a software Module compliant to one of the [Book C-n] specifications. Letter of Approval - Written statement that documents the decision of EMVCo that a specified Product has demonstrated sufficient compliance to the EMV Contactless Specifications on the date of testing. Main Laboratory – The Laboratory performing Books A & B testing, Independency testing and Modular testing for a Product approval. Major modification - Technical change to the EMV application or addition to the application that implies the product provider cannot guarantee continued compliance of the modified application with the requirements of EMV Contactless Specifications, as defined by EMVCo. Minor modification - technical change to the EMV application that does not affect the functionality of the application with respect to the requirements of EMV Contactless Specifications, as defined by EMVCo. Modular Architecture – A software architecture that follows the requirements defined in this document. Modular Label - Written statement (optional) that documents the decision of EMVCo that the Product Providers specified software architecture has demonstrated sufficient compliance to the EMV modular requirements on the date of the audit. PCD - Proximity Coupling Device. A device of the Product that uses inductive coupling to provide power to the PICC and also controls the data exchange with the PICC. POS System - According to definition Book A in section 4.3. It is the device that communicates with contactless cards, processes contactless transactions, and may support other payment functionalities such as magnetic stripe or contact chip transactions. Procedure - Specified way to perform a set of tasks. Product - According to the definition in sections 2.1.2 and 2.1.5 which defines the product to EMV® Type Approval Terminal Contactless Product Administrative Process Introduction be type approved during the Type Approval process. / 60 Product Hardware and Communication Configuration - identify the set of resources of the Product:
  • CPU
  • Operating System
  • RAM
  • Communication Interface and API with the PCD Proficiency - Ability of a testing laboratory to perform the specified tests in an exact and reproducible manner and to provide an accurate test report. Protocol - Method of communication between the ICC and the PCD, represented in this specification by Type A and Type B Reference specification (EMV Contactless Specifications) - A set of documents defining the requirements the Product shall comply with. The reference specification consists of the current EMV Contactless Specifications (Books A, B, C-n, D) for Payment Systems and any additional documentation required when performing type approval. Registration number - A unique identification number assigned by EMVCo to a product provider. Request for approval - A form that goes with a product submitted to EMVCo for type approval and marks the launch of its invoice Sample - A product taken out of the production line for testing. Software Module - A self-contained program that carries out a clearly defined task and is intended to operate within a larger program suite. Mainly a module represents a Kernel C-n or Entry Point. Terminal - According to Book A definition in section 5.1. Terminal could be a standalone device or any networked solution such as a POS, a ATM, a PIN PAD or any other physical payment device. Test - Any activity that aims at verifying the compliance of a selected product or process to a given requirement under a given set of conditions. Test case - A description of the actions required to achieve a specific test objective. EMV® Type Approval Terminal Contactless Product Administrative Process Introduction Laboratory - A facility recognised by EMVCo to perform Type Approval testing. / 60 Test Kernel – Software simulating a Contactless Kernel that must be present in the product under test for testing reason. The Test Kernel present shall be in accordance with section 6.1 of the [TA A&B] document. Type approval – The acknowledgment by EMVCo that the specified Product has demonstrated sufficient compliance to the EMV Contactless Specifications for its stated purpose. Type approval documentation - Full set of documents and procedures issued by EMVCo to enable the type approval process. Type approval process - The processes that test a product for compliance with specification.

1.4 Notational Conventions 1.4.1 Abbreviations FIT ICC ICR ICS ISO Lab LoA ML PCD PICC RFA TTA Fully Integrated Terminal Integrated Circuit Card Integrated Card Reader Implementation Conformance Statement International Organization for Standardization Laboratory Letter of Approval Modular Label Proximity Coupling Devices Proximity Integrated Circuit Card Request for Approval Terminal Type Approval

EMV® Type Approval Terminal Contactless Product Administrative Process Introduction

/ 60 1.5 Terminology & conventions The following words are often used in this specification and have a specific meaning: May Defines a product or system capability, which is optional or a statement which is informative only and is out of scope for this specification. Should Defines a product or system capability, which is recommended.

EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview 2 Type Approval Overview

/ 60 2.1 Scope of Contactless Type Approval 2.1.1 EMVCo Contactless Terminal Type Approval Process Goal EMVCo terminal type approval contactless ascertains the level of confidence that Product Providers have correctly implemented the EMV Contactless Specifications. Product Providers submit their Product with the software and appropriate documentation, including the Implementation Conformance Statement (ICS), to an EMVCo recognised Laboratory for testing. The Laboratory executes a set of EMVCo-defined test cases and prepares a test report document for the Product Provider that may then be submitted to EMVCo for evaluation. EMVCo’s evaluation of the test report concludes with the issuance of a Letter of approval or decline notification. Obtaining an EMV Product approval from EMVCo has the following advantages:

  • Acquirers have access to terminal implementations in respect of which compliance to the EMV Contactless Specifications has already been tested - yielding a likely reduction in testing costs as well as improved time to market for final implementations.
  • Product Providers can sell the approved EMVCo compliant product on a worldwide basis and differentiate themselves from the competition.

2.1.2 Contactless Terminal Architecture: the Product There are two possible options for the Product Under Test, called the 'Product' in the rest of the document: 1 / The Contactless Product: it is the general case defining the Contactless Product that is submitted in this process. The Product includes:

  • Communication with contactless cards
  • Application selection and kernel activation
  • Kernel(s)
  • The Terminal hardware 2/ The Contactless Kernel C-8 in standalone Appendix F of the present document describes the EMVCo administrative procedure when the Product Provider wants to submit a Contactless Kernel C-8 as a standalone kernel.

2.1.3 Multi Kernel Environment The contactless Product submitted for approval works in a Multi-Kernel environment. This means that one or several Kernels C-n (C-2 to C-8) are present at the time of testing and will be tested independently. The number of Kernels (C-2 to C-8) present in the Product for approval depends on the Product Provider’s decision. He may decide to submit a Product containing one Kernel (as a

EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview

/ 60 minimum) or up to 7 EMV Kernels for approval. Approval will be granted to the corresponding Product and is valid only for that configuration reflecting the specific Kernel(s) present during approval. A Product Provider can decide at any time to enhance the Product by adding/deleting/changing a Kernel (or Entry Point). However this shall result in a new approval if required to that Product, reflecting the new Product. When the Product contains any software or kernel not described by EMVCo and changes occur to such software, it is considered as a change to the Product, hence, section 8 ‘changes’ applies.

2.1.4 Modular Approach Principles EMVCo considers Type Approval process for Contactless Products using the Modular Architecture according to [TA Archi], where the Product is considered compliant to the Modular Architecture by EMVCo. Product Provider shall declare in the ICS that they conform to the Modular Architecture, in order to submit a Contactless Product.

2.1.4.1 Modular Label A Product Provider claiming that his Product follows the Modular Architecture may decide to perform the Compliance audit to obtain a Modular Label. Please check Appendix C: Modular Label Request (optional) for detail on this optional procedure.

EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview

/ 60 2.1.5 Contactless Product Identification and Family of Product 1/ Contactless Product Identification A Contactless Product submitted for approval is identified by: 1. Its Product Hardware and Communication Configuration: the Hardware managing the EMVCo Software and communicating with the PCD:

  • CPU
  • Operating System
  • RAM
  • Communication Interface and API with the PCD 2. Its EMVCo software that covers:
  • Book A
  • Book B (Entry Point)
  • All C-n Kernels 3. Its Level 1 approved PCD Changing any of the above part of the Contactless Product shall follow the rules defined in the present document. 2/ Family of Products A Family of Products means multiple Contactless Products having the same Hardware and Communication Configuration:
  • CPU
  • Operating System
  • RAM (same or higher)
  • Communication Interface and API with the PCD EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview / 60 Below is an example of 4 Members of the same Family, with different EMVCo Software and different PCDs: EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview / 60 2.2 EMVCo Contactless Type Approval Description 2.2.1 Modular Label Request (optional) Before submission of Products following a Modular Architecture, Product Provider may decide to perform a Compliance Audit in order to obtain a Modular Label of its Architecture. This Step is not mandatory to follow the Approval Process, Product Provider can decide to declare the Product as Modular in the ICS without having the Modular Label. For detail of this procedure please check Appendix C: Modular Label Request (optional).

2.2.2 Initial Product Submission The following rules shall be applied to Products initially submitted to EMVCo for formal approval when the Product implements a Modular Architecture and declare it as such in the ICS. These rules do not apply to debug testing that may be conducted directly between the Laboratory and Product Provider.

  • All functional options, Hardware and Communication Configuration, L1 Approved PCD, Entry Point Software and Kernels present must be identified on the ICS. This reflects the Product configuration submitted for approval.
  • The laboratory must validate and submit a copy of the completed ICS to EMVCo prior to performing type approval testing. EMVCo will review the statement for accuracy, archive the form for later comparison, and send an acknowledgement that the ICS is acceptable for testing.
  • Samples are retained by the Laboratory for a period of the LoA validity + 1 year as of the date of approval. The Product Provider is responsible for providing support as necessary to maintain the product in an operational state to accommodate any Derivative testing or analysis that may be deemed necessary by EMVCo. Note: If the EMV Contact is present in the Product, it shall be listed in the ICS for testing purposes.

2.2.3 Derivative Product Submission The following rules shall be applied to Products submitted to EMVCo for Derivative formal approval:

  • Derivative Submission shall be based on the Initial Product or on a Products part of the same Family (so having the same Hardware and Communication Configuration as the Product submitted during the Initial Submission).
  • New PCD must be identified on the ICS (if applicable).
  • Any added Kernels, modified Entry Point module or modified Kernels must be identified on the ICS (if applicable).
  • The laboratory must validate and submit a copy of the completed ICS to EMVCo prior to performing type approval testing. EMVCo will review the statement for accuracy, archive the form for later comparison, and send an acknowledgement that the ICS is acceptable for testing
  • Samples are retained by the Laboratory for a period of the LoA validity + 1 year as of the date of approval. The Product Provider is responsible for providing support as necessary to maintain the product in an operational state to accommodate any Derivative testing or analysis that may be deemed necessary by EMVCo. EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview / 60
  • The Product ending date validity remains the same as the Initial Product.

2.2.3.1 Family of Product vs Derivative Submission Changes to have a new Family Product Member (with the same Hardware and Communication Configuration):

  • EMVCo Software covers:
  • Book A
  • Book B (Entry Point)
  • C-n Kernels
  • PCD replacement by another PCD already tested once in a Contactless Product of the same family. Note1: EMVCo Software changes require testing as described in the Derivative Submission process. Note2: Changing a PCD which is not previously Level 1 and Contactless Product approved require testing as described in the Derivative Submission process Below is an example of creating a new Product in the same Family by updating the Kernel C2 to a new version.

2.2.3.2 Allowed changes in a Product Changes allowed during Derivative Submission:

  • EMVCo Software covers:
  • Book A EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview / 60
  • Book B (Entry Point)
  • C-n Kernels (changes or added) Any of the above changes, if tested once, can be used in any member of the Family without retesting.
  • PCD A PCD change may require, on Payment System request, additional testing such as performance testing or Integration testing. Note: an EMVCo Software (package of Entry Point and Kernels C-n) tested once in a Product can be used in any other Member of the same Family without any testing and so without Derivative Submission. Other Minor Changes: Changes defined as minors in Bulletin 11 – Contactless Product are allowed, without any testing, to create a new Family Product Member. Note: minors changes are not tested, it is the responsibility of the Product Provider to ensure the new Product comply with the Family.

2.2.4 Request of Approval To determine compliance, reference implementations of the Product must undergo predefined tests in a specified test environment (Laboratory). The Product submitted to Laboratory shall be submitted with a Contactless Level 1 (PCD) complete with a valid LoA and must be representative of final deployment. The Letter of Approval will be granted per Kernel in the in Product (but LOA includes also the hardware and the Books A & B software). After the Letter of Approval has been granted, it is valid as long as the following applies:

  • The approval is not revoked by EMVCo.
  • The LoA is valid for the period of approval duration 2.2.5 Derivative Request of Approval Some changes are allowed in the Product as per section 2.2.3.2. The updated Product submitted to Laboratory shall be submitted with a Contactless Level 1 (PCD) complete with a valid LoA and must be representative of final deployment. The Letter of Approval(s) will be granted to the submitted changes only. After the Letter of Approval has been granted, it is valid as long as the following applies:
  • The approval is not revoked by EMVCo.
  • The LoA is valid for the period of approval duration 2.2.6 Renewal Request for Approval A Product approval is valid for 4 years. The starting date is the date of the initial approval or the date of the Derivative approval. EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview / 60 Every 4 years, EMVCo evaluates whether the product demonstrates sufficient compliance to the current EMV Contactless Specifications. If the evaluation results are positive then EMVCo grants an extension to the Product Letter of Approval. The following rules will apply to Renewal Request:
  • The Kernels(s) ongoing LoA is still valid at the time of renewal.
  • The Level 1 LoA of all PCD(s) listed in the Product must be valid at the time of renewal. In case some PCD(s) LoAs are no longer valid, these concerned PCD(s) will be removed from the renewed Contactless Product LoA.
  • All EMV Contactless Specifications are still valid (Books A, B and C-n)
  • Renewal per Kernel LOA may be request (to address different Kernel expiration dates) After the renewal date, Products not passing renewal testing nor applying for renewal testing will be removed from the approved list and their Letter of Approval will be considered revoked.

2.2.7 Laboratories testing procedures The Laboratories must perform the following testing procedure depending on the type of submission:

  • For Initial submission the testing procedure is described in section 4.3.1.1
  • For Derivative submission the testing procedure is described in section 4.3.5
  • For Renewal submission the testing procedure is described in section 4.4.1.1 Transaction Type Testing: Section IV of the Contactless Product ICS, requests the transaction type(s) ‘supported and activated’ for each Kernel present in the Contactless Product. When a transaction type is supported and activated at a kernel level then it is considered supported and activated at the product level and the related tests shall be executed. Note: ‘Support and Activation’ of the transaction type implementation depends on each Kernel, for example for C-3 if the transaction type is supported it is automatically activated.

2.3 Contactless Type Approval Life Cycle Concept The following sections identify the type approval life cycle which is a logical concept regarding the design and key approval milestones of a Contactless Product.

2.3.1 Contactless Product Life Cycle and Type Approval Milestones Type Approval shall be done on a sample that is representative of future production. Therefore, the Type Approval milestone shall occur at a particular moment in the Product Life cycle:

EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview Figure 1 - Life cycle of Contactless Product

/ 60 2.3.2 Product Design Phase The Product is developed by the Product Provider or an entity directly related to the Product Provider. Most importantly, Product design and development must be in accordance with the EMV Contactless Specifications, as well as any other applicable specifications (e.g. government standards).

2.3.3 Product Debugging Phase The Product design is checked and tested against all related specifications. EMVCo recommends that compliance testing against the EMV Contactless Specifications is conducted on the representative sample before proceeding to type approval, preferably with tools equivalent to those used for type approval tests. The Product Provider must identify which options its Product design has incorporated from the EMV Contactless Specifications and gather the information to be submitted in the Type Approval process.

2.3.4 Product Approval Phase EMVCo assesses compliance (see section 4.3) of the Product design against the EMV Contactless Specifications. To determine compliance, reference implementations of the Product must undergo predefined tests in a specified test environment (EMVCo Recognised Laboratory). The Product submitted for approval shall be complete with a valid EMVCo Level 1 Letter of Approval and must be representative of final deployment. After the Letter of Approval has been granted, it is valid as long as the following applies:

  • The approval is not revoked by EMVCo.
  • The LoA is valid for the period of approval duration. Any change to the Product creates a new Product, whether it occurs before, during, or after deployment. Type Approval of that new Product is not presumed. EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview / 60 Derivative Submission Approval At any time after initial approval, the Product Provider may decide to update the Product or to create a new Family Member. This will result in an additional approval called Derivative Submission.

2.3.5 Product Approval Renewal Phase Prior to the renewal date, Product Providers may request a renewal by submitting the original approved product to EMVCo for Renewal testing (see section 4.4). The purpose of this renewal testing is to ensure that products pass the most current EMVCo testing. At the time of submission, the product submitted for approval shall be complete with valid EMVCo Level 1 Letter of Approval.

EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview 2.4 ICS Submission rules

/ 60 2.4.1

  • ICS Submission The initial ICS submission to the EMVCo is free of charge. The ICS submitted must be the ICS in pdf format, capable of importing/exporting XML format and shall be digitally signed by the Product Provider and the Laboratory at the time of submission to EMVCo. The Laboratory supplies the signed copy of the vendor-supplied ICS to EMVCo for review prior to the start of the type approval testing process. EMVCo will review and approve the ICS by returning the ICS in pdf digitally signed and with the official ICS number. In case the ICS is incorrectly filled, decline fee applies to Laboratory. ICS submission shall be done using the latest version of the ICS available at the time of the submission on EMVCo website. During the migration period, former version of the ICS available on the website may be used.

2.4.2 ICS replacement

  • One free ICS replacement is allowed during the ICS life cycle. Any Derivative ICS replacement requested will be charged to the Product Provider.
  • Same submission process applies as for initial ICS submission (Laboratory submits the changed ICS).
  • This applies to any change in the ICS after the official approval of the ICS by EMVCo.
  • After the start of the test session of the Product, ICS replacements (following the rules of the previous bullet) are only allowed for administrative information update (such as name of product) but not are not allowed for technical information update.
  • Laboratory shall ensure that any ICS change requested is not made to hide a bug in the product (such as deactivation a function because this function is not working properly).
  • ICS replacement is no more allowed after Test Report submission to EMVCo. Note: ICS decline process remains and any error reported by EMVCo will be charged to the Laboratory (as Laboratory is responsible of reviewing the ICS provided by the Product Provider). ICS decline process applies to the initial ICS submission and also to any other ICS replacement (charged or not charged to the Product Provider). EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Overview 2.5 EMVCo type approval fee structure The following fee structures apply:
  • Modular Label
  • Modular Label Renewal (same fee as Modular Label)
  • Initial submission
  • Derivative submission for a software change
  • Derivative submission for a new/change PCD
  • Administrative LoO request submission
  • ICS Replacement (starting at 2nd Replacement)
  • Product renewal
  • Declined ICS/Report
  • LoA reissuance / 60 Note: The amount of fees for each are published in Terminal Type Approval Bulletin 185. EMV® Type Approval Terminal Contactless Product Administrative Process Roles & Responsibilities / 60 3 Roles & Responsibilities The following sections define the roles and responsibilities of the various participants in the type approval process.

3.1 EMVCo EMVCo defines type approval contactless requirements and evaluates operational results. EMVCo provides the following services:

  • Defines the Administrative Process.
  • Operates the Approval Process.
  • Defines mandatory auditor qualification requirements.
  • Qualifies companies that perform audits to establish Laboratory recognition.
  • Qualifies companies that perform audits to establish the compliance with Modular Architecture.
  • Defines Laboratory recognitionrequirements.
  • Evaluates Laboratory audit results and determines if the EMVCo recognitionshould be granted to a Laboratory.
  • Defines Tool Qualification Process.
  • Qualifies Test Tool and maintains a list of Qualified Test Tools on the EMVCo web site.
  • Coordinates with the Payment Systems for the Kernels C-n testing.
  • Manages Laboratory appeals process and resolves recognitiondisputes.
  • Manages Product Provider’s appeals process and resolves Modular Architecture compliance disputes.
  • Defines appropriate test cases to test compliance with EMVCo Contactless Specifications.
  • Defines procedures used to perform testing, submits test results for evaluation, and communicates evaluation results.
  • Defines the test tools and evaluation criteria thereof.
  • Evaluates Modular Architecture audit results and determines if the EMVCo compliance of that architecture should be granted.
  • Evaluates Product approval test results to determine whether approval should be granted.
  • Evaluates Product renewal tests results to determine whether a renewal should be granted.
  • Notifies appropriate EMVCo working group of warranted specification corrections, clarifications, and enhancements where appropriate.
  • Evaluates terminal and card failure complaints to determine if type approval revocation for a particular Product is appropriate. EMV® Type Approval Terminal Contactless Product Administrative Process Roles & Responsibilities / 60
  • Provides result response to Product Provider’s type approval test result evaluation request.
  • Maintains and publishes (via EMVCo web-site) a list of Products that have received EMVCo type approval notification.
  • Issue the Letter of Approval.
  • Issue the Modular Label.

3.2 EMVCo Type Approval Secretariat (CATA) The EMVCo Terminal Type Approval Secretariat (CATA) is responsible for managing the EMVCo Type Approval contactless process. This includes the administrative functions associated with Product Provider’s registration, completion of contracts, processing approval requests and fees, issuing letters of approval letters of compliance or decline, etc. The role also includes communicating type approval status to third parties and the maintenance of a database that provides the following:

  • Coordinate with the Payment Systems.
  • Qualified Auditors.
  • Recognised Laboratories.
  • Qualified EMVCo Tools.
  • Type approval and compliance requirements and test cases.
  • Approved EMV contact & contactless Products.

3.3 Auditors Two types of auditors are required for contactless process:

  • Laboratory Auditor: The Laboratory Auditor is in charge of auditing the Laboratory for recognition purpose.
  • Compliance Auditor: The Compliance Auditor is in charge of auditing the Modular Architecture provided by the Product Provider, checking the compliance of the Product Modular Architecture with EMVCo Modular Requirements (see document [TA Archi]). He also provides the signed audit report to EMVCo when approved by the Product Provider.

3.4 EMVCo Recognised Laboratories The Laboratory is a test facility recognised by EMVCo to conduct testing of the Product or part of the Product in accordance with the EMVCo type approval requirements and test cases. It shall also:

  • Verify the Implementation Conformance Statement provided by the Product Provider
  • Extract the set of test case depending on: EMV® Type Approval Terminal Contactless Product Administrative Process Roles & Responsibilities / 60
  • The version of Entry Point,
  • The version of each Kernel,
  • If it is an initial or derivative submission,
  • If it is a renewal approval.
  • Perform the test session
  • Checksum values of each module and sub modules; as well as untested modules shall be retrieved form the Contactless Product submitted and checked by the Laboratory against value declared by the Product Provider.
  • Analyze the test results.
  • Communicate the results to the Product Provider.
  • Send to EMVCo the result of the test session(s) after Product Provider approval.
  • Eventually send the Request for Approval on behalf of the Product Provider.

3.5 Product Provider 3.5.1 Modular Compliance Request (optional) The Product Provider shall

  • Sign appropriate contracts.
  • Select one Auditor to perform the Audit.
  • Submit to the Auditor the Modular Architecture documents for review.
  • Verify and approve the audit report provided by the Auditor.
  • Fill out the Request for Compliance Form.
  • Submit to EMVCo the Request for Compliance form.

3.5.2 Type Approval Request The Product Provider shall provide the Product to be tested by the Laboratory:

  • Sign appropriate contracts.
  • Fill out the Request for Approval and Implementation Conformance Statement Forms.
  • Submit to the Laboratory the ICS for review.
  • Submit to EMVCo the Request for Approval form (or the Laboratory can submit on behalf of the Product Provider).
  • Select one or several Laboratories to run the tests session(s).
  • Submits the final Product to the Laboratories for testing.
  • Verify and approve the test results provided by the Laboratories.
  • Manage the Family of Product. EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Procedure / 60 4 Type Approval Procedure The type approval procedure applied by Product Providers, Laboratories, auditors and EMVCo includes the following:
  • Product provider obtains registration information from the EMVCo web site or from an EMVCo recognised laboratory
  • Product provider submits a completed registration template to the EMVCo Type Approval Secretariat
  • Product provider obtains the Level 2 EMVCo/vendor contract from EMVCo, the EMVCo web site or from an EMVCo recognised laboratory
  • Product Providers conclude the contract with EMVCo. This contract covers Product Approval and Modular Label (if needed). A contract between EMVCo and the Product Providers must be signed before test results are submitted to EMVCo for evaluation and potential type approval.
  • In case of ‘Modular Label’ optional request see Appendix C: Modular Label Request (optional).
  • Product Providers select one or several recognised Laboratories from the list of recognised Laboratories published on the EMVCo web site. The Laboratory performing Books A & B testing, Independency testing is referenced as the Main Laboratory.
  • Product Providers conclude a contract with the Laboratories selected in respect of the Product to be tested.
  • Product Providers and selected Laboratories shall fill out the ICS; one ICS for the overall Product (called Contactless Product ICS) and one ICS for each Kernel C-n present. The Contactless Product ICS is managed by the Main Laboratory and it is the responsibility to share this ICS (after EMVCo Approval of the ICS) with the other selected Laboratories (if any).
  • The Laboratory reviews for accuracy the ICS received from the Product Provider and then archived for later comparison. Laboratories submit a validated copy of the completed ICS to EMVCo prior performing testing. This ICS must be in pdf format, capable of importing/exporting XML format and shall be digitally signed by the Application Provider and by the Laboratory (both signatures on the same ICS submitted) as paper copy or scanned copy are no more accepted.
  • The EMVCo CATA Secretariat will respond with a confirmation that all the submitted ICSs are acceptable for testing to the Main Laboratory.
  • If the submitted ICS is acceptable the Secretariat responds back to the Laboratory and return at the same time the approved ICS in.pdf format digitally signed
  • If the submitted ICS is unacceptable the Secretariat inform the Laboratory and apply the “Decline fees” (see Bulletin)
  • All Laboratories perform appropriate testing of the submitted Product against the published test requirements and test cases.
  • On Product Provider’s request, the Laboratories submit the ICSs and test results (with checksum of the modules tested) to the EMVCo CATA Secretariat.
  • Product Providers submit a completed Request for Approval form to EMVCo. Based on the RFA form EMVCo will provide Product Provider with an invoice. EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Procedure / 60
  • Based on the received invoice the Product Provider shall settle the administrative fees with EMVCo.
  • If the fee payment is confirmed by EMVCo Financial Secretariat, analysis of the ICS and test report by EMVCo will start and, if appropriate, approval notified. Note that payment cannot be refunded after the RFA form is received.
  • Type approved contactless Products are posted on the EMVCo web site after approval notification.
  • Approved products are retained by the Laboratory for a period of the LoA validity + 1 year as of the date of approval. The Product Provider is responsible for providing support as necessary to maintain the Product in an operational state to accommodate any testing or analysis that may be deemed necessary by EMVCo. Note: An Approved Contactless Product ICS is valid 6 months. If the related Request for Approval and the associated report is not submitted and the invoice is not paid within that period, all related documents to this approval request are no more valid (ICS, RFA, report) and a new process shall be restarted. Note that in this case the invoice is not reimbursed. Figures 8 below shows the diagram of Type Approval Process EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Procedure Figure 2 - Contactless Product Type Approval Procedure / 60 EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Procedure / 60 4.1 Registration Registration provides the Product Provider with entry to the EMVCo approval process in order to make the Product Provider aware of all formalities that need to be finalized prior to submitting their final test report to EMVCo for approval. The registration process is composed of the following steps:
  • The Product Provider enters registration information on the EMVCo Registration Web page.
  • The Product Provider will receive a confirmation email from EMVCo Type Approval Secretariat with the following additional information:
  • Link to the EMVCo Test Contract (DocuSign)
  • Appropriate contact information
  • The Product Provider shall sign the EMVCo Test Contract with DocuSign.
  • When the EMVCo Test Contract is countersigned by the EMVCo, the EMVCo Test Contract is sent back to the Product Provider by DocuSign.
  • A unique Registration Number is assigned and shared with the Product Provider.

4.2 Contract with EMVCo The Product Provider must complete and sign the EMVCo defined contract before final test results or Modular Compliancy are submitted to EMVCo for evaluation and possible approval. This contract governs the relationship between EMVCo and the Product Provider and includes the Product Provider’s acceptance of all specifications, procedures, terms and conditions governing EMVCo Contactless Product Type Approval and Modular Label. The contract is standard for all Product Providers to ensure consistent requirements for all participants. Contract customization for individual Product Providers is not possible. The Product Provider must also complete and sign the: ‘Contactless Marks Trademark License Agreement - Vendor and Brand versions EMVCo’ available at EMVCo website. The agreement has to be signed with EMVCo prior to submission of a product.

4.3 Request For Approval 4.3.1 Product Provider and Laboratory Operations The following operations are performed by the Product Provider and the Laboratory as they relate to the type approval procedure:

  • The Product Provider is free to select any EMVCo recognised Laboratories on purpose of achieving EMVCo Contactless type approval. A list of recognised Laboratories is published on the EMVCo web site. Once Laboratories have been selected, the Product Provider and Laboratories sign a contract defining the rights and obligations of the contracting parties. The provisions of Product EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Procedure / 60 Provider/Laboratory contract are up to the contracting entities and entirely out of EMVCo’s scope. Any fees payable to the Laboratory in respect of the tests to be performed are solely at the discretion of the Laboratory.
  • In case that the Product Provider has selected multiple Laboratories, the Laboratory performing Books A & B testing, Independency testing is defined as the Main Laboratory for EMVCo.
  • Product Provider sends the appropriate Implementation Conformance Statement (ICS) to the chosen Laboratory(ies) for each Product that it submits for testing. The ICS format and content requirements are determined by EMVCo.
  • Each Laboratory validates the Product Provider’s-supplied ICSs and supplies a copy to the EMVCo CATA Secretariat for approval prior to the start of the type approval testing process.
  • The Laboratory(ies) tests the Products in accordance with EMVCo test procedures.
  • The Product Provider prepares the Request for Approval form and submits it to the EMVCo CATA Secretariat. EMVCo then issues the invoice to the Product Provider.
  • Product Provider submits payment to EMVCo based on the received invoice.
  • The Laboratory(ies) sends the final test reports to the Product Provider being the owner of the test results. The Laboratory(ies) must advise EMVCo of any failures that have been encountered during testing.
  • The Laboratory(ies) submits an original copy of the test results report to the EMVCo CATA Secretariat, and ensures that the Product Provider has already submitted his completed Request For Approval form.

4.3.1.1 Laboratory test procedure for Initial Submission The Laboratories must perform the following testing procedure when the test session is performed for an Initial product Submission: For the Main Laboratory: Before the Test Session:

  • Request the Other Laboratory(ies) (if any) to provide the Kernels C-2 to C-8 ICSs they are in charge of. The ICSs provided by the Other Laboratory(ies) to the Main Laboratory shall have been previously approved by EMVCo.
  • When all ICSs of the submitted Contactless Product have been received by the Main Laboratory, the Main Laboratory sends all ICSs (Contactless ICS and all Kernels ICSs) to each Other Laboratory(ies) involved in this submission. In the Test Session:
  • Book A & Book B testing using [TA A&B] test plan.
  • Kernels C-2 to C-8 testing using the [TA C-n] functional test plans, [TA INT C-n] integration test plans, [TA P] performance test plans and [TA C-8RRP] RRP test plan (for Kernel C-8 only): Main Lab shall test one or several Kernels declared in the ICS and present in the Product submitted (Main Lab shall test at least test one of Kernel present). EMV® Type Approval Terminal Contactless Product Administrative Process Type Approval Procedure / 60
  • Multi-Kernel Independency testing using [TA M], where independency test set for all C Kernel(s) present in Product applies, with the following process:
  • Verify Independency Tests Pass Criteria only for the C kernel(s) the Main Laboratory is performing test as described in previous paragraph.
  • Verify that Independency Tests pass correctly (transactions accepted) for C kernel(s) that the Main Laboratory is not performing kernel test (with [TA C-n]). Note1: all steps above must be run on the final software module versions. If any failures occur in a Module (Kernel or Books A & B), then the whole set of tests of the concerned Module (Kernel or Books A & B) must be re-run until a successful completion is achieved. If the successful completion of a Kernel testing cannot be achieved, but the Books A & B and the other Kernel successfully pass the testing (included Independency and performance) without any change in the final software versions, then the LoA can be issued without the concerned Kernel. Note 2: Checksum values of each module and sub modules, external libraries; as well as untested kernels or modules, shall be retrieved from the Contactless Product submitted and checked by the Laboratory against value declared by the Product Provider. It is not allowed to change any Checksum value during the type approval, as the product submitted shall be the final Product Note3: if only one Kernel C-n is present in the Product, Independency testing is not required. For the Other Laboratory (if any): Before the Test Session:
  • On request from the Main Laboratory, provide the Kernels C-2 to C-8 ICSs it is in charge of. The ICSs provided to the Main Laboratory shall have been previously approved by EMVCo.
  • Receive back from the Main Laboratory all ICSs of the submitted Contactless Product. During the Test Session:
  • Kernels C-2 to C-8 testing using the [TA C-n] functional test plans, [TA INT C-n] integration test plans, [TA P] performance test plans and [TA C-8RRP] RRP test plan (for Kernel C-8 only): Other Lab(s) shall test one or several Kernels declared in the ICS and present in the Product submitted but not tested by the Main Laboratory.
  • Multi-Kernel Independency testing using [TA M], where independency test set for all C Kernel(s) present in Product applies, with the following process:
  • Verify Independency Tests Pass Criteria only for the C kernel(s) the Laboratory is performing test as described in previous paragraph.
  • Verify that Independency Tests pass correctly (transactions accepted) for C kernel(s) that the laboratory is not performing test (with [TA C-n]).
  • Testing must be done with the final product. This means Laboratories must verify the checksum of each module (Entry Point, Kernels C-n present in the product), even for the module(s) not tested. Checksum values of each module and software module shall be retrieved from the Contactless Product submitted and checked by the © 2011-2025 EMVCo, LLC. All rights reserved. Repr

Shown in part. Read the original for the full text.