Specification & Scheme · Finance & Payment

CPACE — Europe's own contactless kernel, with its own trust chain

Built by the European card payment cooperation so domestic schemes stop depending on the international networks' kernels, CPACE brings a European specification — and a European security evaluation path — to the contactless transaction itself.

At a glance

Owner

ECPC

European Card Payment Cooperation — the European domestic schemes’ joint body

Type

Contactless kernel specification

Card/mobile and terminal-side, with an approval framework around it

Purpose

European kernel independence

Domestic schemes transacting without licensing international networks’ kernels

Security route

Smartcard-tradition evaluation

CC/EUCC-rooted hardware assurance with scheme-level approvals on top

Ecosystem

EMV-interoperable

Lives alongside EMVCo approvals in cards, wallets and terminals

Context

Payment sovereignty agenda

Same current that drives EPI, instant payments and the digital euro debate

What it is

Sovereignty, implemented at kernel level

Most European domestic card schemes historically ran their contactless transactions over kernels specified and licensed by the international networks — a structural dependency in the most political layer of payments. CPACE (Common Payment Application Contactless Extensions) is the European answer: a kernel specification family developed under the ECPC by the domestic schemes themselves, covering the card and mobile application side as well as terminal kernels, EMV-interoperable but European-governed.

For product vendors, CPACE is a certification object like any payment application: the implementation lands on certified secure hardware (the CC/EUCC smartcard tradition), passes functional and security approval for the CPACE ecosystem, and coexists in the same chip or wallet with EMVCo-approved applications. The engineering reality is multi-tenancy — one secure element carrying international and domestic payment applications, each with its own approval chain, all resting on one hardware certificate.

Strategically, CPACE belongs to the same current as EPI, instant payments and the digital euro: European payment infrastructure reclaiming control of its critical components. Vendors who read that current early are building CPACE support into card, wallet and terminal roadmaps now — because domestic schemes’ migration decisions translate directly into issuance and acceptance requirements.

When it's the right tool

Who needs to care, and how much

Card & SE product vendors: roadmap item

If domestic European schemes are in your customer base, CPACE application support — and its approval chain — belongs in your product plan next to EMVCo.

Terminal & SoftPOS vendors: kernel strategy

Terminal-side CPACE kernels change your certification matrix. Decide whether you implement, license or integrate — each has a different approval cost curve.

Domestic schemes & issuers: migration design

Kernel migration is a decade-scale ecosystem move. The security evaluation and approval architecture deserves as much design as the specification choice.

Everyone: reuse the hardware trust

CPACE applications ride the same certified silicon as everything else. The hardware certificate strategy — level, version, composition interface — is where the costs merge or multiply.

Where it matters

CPACE in your industry

Multi-application silicon

One EUCC-certified secure element carrying EMVCo and CPACE applications — the composition strategy that keeps dual approvals affordable.

The sovereignty convergence

European payment kernels and the EUDI wallet ride the same political current — and increasingly the same certified hardware in the same device.

Payment in every form factor

Wearables and connected devices adding domestic-scheme payment stack CPACE approvals onto their RED and CRA obligations.

A scheme being born

CPACE’s approval framework is European scheme-building in real time — instructive for anyone designing certification governance.

Expert notes

What we tell clients before they commit

The approval matrix is the project

A product carrying international and domestic payment applications faces a matrix of approvals — EMVCo security and functional, CPACE-ecosystem approvals, per-scheme requirements, plus the underlying CC/EUCC hardware certificate that all of them lean on. The versions interlock: a hardware certificate update ripples through every application approval sitting on it. Products that map the full matrix before development sequence their evaluations; products that don’t discover the ripples in production.

Our position: we build the approval dependency map first — which certificate feeds which approval, which renewal triggers which re-submission. It is one workshop, and it has paid for itself every time.

CPACE adoption is driven by scheme politics as much as engineering: domestic schemes’ independence agendas, EPI’s trajectory, regulatory pressure for European payment autonomy, and the digital euro’s eventual architecture all shape who mandates CPACE support and when. Vendors treating it as a niche kernel option risk being surprised by an issuance requirement; vendors reading the current can time their investment to their customers’ actual migration windows.

Our position: track the scheme-level decisions, not the specification releases — that is where your CPACE demand curve is actually written. We watch both, professionally.

European payments, certified coherently

Approval matrices, hardware certificate strategy, migration timing — thirty minutes with people who work both sides of the EMVCo/CPACE line.

Contact us

Request this document

We’ll send you access by email.