KL Bulletin nº30: EMVCo Annual Public Key Lengths Assessment

General Bulletin
ChipContactContactless Acceptance DeviceCardChip & PlatformNFC Consumer Device

EMV SWG N Q47r2 © 1994-20 26 EMVCo, LLC. All rights reserved. Any and all uses of the EMV Specifications shall be permitted only pursuant to the terms and conditions of the license agreement between the user and EMVCo found at www.emvco.com. EMV® is a registered trademark or trademark of EMVCo, LLC in the United States and other countries.

Notice Bulletin No. 30 July 2026 EMVCo Annual Public Key Lengths Assessment EMVCo, LLC (“EMVCo”) has completed its annual review of the Certification Authority Public Key lengths and expiry dates for chip-based payments and makes the following recommendations to EMV® -based payment systems. For RSA keys:

  • 1408- bit keys are recommended to have expired 31 December 2024.
  • 1984- bit keys are recommended to have an anticipated lifetime to at least 31 December 2036. EMVCo does not project beyond a 10 -year horizon. For ECC keys:
  • As noted in Book 2 v4.4 and Book E v1.1, new ECC payment system keys may be introduced into terminals.
  • 256-bit and 521- bit ECC keys are recommended to have an anticipated lifetime beyond 31 December 2036. Although EMVCo does not project beyond a 10-year horizon, in general 256- bit ECC keys are considered much more robust than 1984- bit RSA keys.
  • 521-bit ECC keys are included in EMV specifications for contingency purposes only. Payment systems will decide individually whether to adopt the recommendations made in this Bulletin and will notify their members of their final decision. EMVCo is aware of on -going advances in quantum computing and its potential impact on RSA and ECC public key cryptography. More information regarding this can be found in EMVCo’s Q&A: Quantum Computing and EMV® Chip – What’s the Threat? | EMVCo. Note that no certificate should be issued that expires later than the expiry date of the CA key.