Scheme · Finance & Payment

EMVCo — the security evaluation the payment world runs on

No EMVCo approval, no payment product — it is that simple for chips, cards and increasingly for software-based mobile payment solutions. The craft is making one hardware evaluation serve EMVCo, Common Criteria and your customers' schemes at once.

At a glance

Owner

EMVCo

Jointly owned by the international payment networks

Type

Product approval scheme

Security evaluation by EMVCo-recognised laboratories

Hardware track

ICs & platforms

Attack-potential-based evaluation of payment chips and secure platforms

Software track

SBMP

Software-based mobile payment: wallets and SoftPOS-class solutions

Validity

Time-limited approvals

Renewals track the evolving attack state of the art

Neighbours

PCI SSC, scheme programmes

PCI PTS/P2PE for acceptance devices; card schemes’ own approvals ride on EMVCo results

What it is

Attack-rated assurance, kept permanently current

EMVCo security evaluation certifies that payment products resist attackers rated in the smartcard tradition: recognised labs attack the target — chip, platform or software solution — and score feasibility against attack-potential tables that EMVCo recalibrates as techniques evolve. Approvals are time-limited by design; a product that passed three years ago must still resist today’s published state of the art to keep its approval alive. That perpetual-motion quality is the scheme’s defining discipline — and the reason payment silicon teams never really finish certifying.

The hardware track (payment ICs and platforms) shares labs, methodology DNA and attack ratings with Common Criteria’s smartcard world — most payment chips carry both an EMVCo approval and a CC/EUCC certificate, built from substantially overlapping evidence. The software track, SBMP, extends the logic to software-based mobile payments where no secure element is guaranteed: white-box cryptography, runtime protections and back-end monitoring evaluated as a system, with shorter renewal cycles reflecting the softer target.

Around EMVCo sits the wider payment approval economy: PCI SSC programmes (PTS for terminals, P2PE, and related) govern the acceptance side, and the card schemes layer their own functional and security approvals on top of EMVCo results. For a product roadmap, EMVCo is rarely the only gate — but it is almost always the first one the others reference.

When it's the right tool

If payments touch your product, this scheme touches you

Payment silicon: mandatory, and plan the pairing

Payment ICs need EMVCo approval and usually CC/EUCC too. One evidence base, two submissions — or two full projects, if you plan it badly.

Wallets & SoftPOS: SBMP is the route

Software payment solutions without dedicated hardware live on SBMP evaluations plus scheme approvals — with renewal cycles your release cadence must absorb.

Renewals are strategy, not paperwork

Attack ratings move; approvals expire. Products designed with security margin renew cheaply; products that scraped through renew expensively or die early.

Don't confuse the gates

EMVCo, PCI and scheme approvals answer different questions on different clocks. Map all the gates before committing the roadmap to any one of them.

Where it matters

EMVCo in your industry

The payment silicon pairing

EMVCo approvals built on the same evidence as EUCC certificates — the composition strategy that halves the cost of payment chips’ assurance.

Payments meet the wallet

EUDI wallets carrying payment credentials pull EMVCo-evaluated components into eIDAS-certified architectures — two trust chains, one device.

Payment-enabled devices

Wearables and connected devices with payment functions stack EMVCo approval onto RED and CRA conformity — shared platform evidence keeps it sane.

The scheme benchmark

Time-limited approvals tracking live attack ratings — the scheme-design pattern others copy when they say “continuous assurance”.

Expert notes

What we tell clients before they commit

Build the EMVCo–CC evidence bridge deliberately

Payment chips face both worlds: EMVCo approval for the payment networks, CC/EUCC certification for governments, wallets and composition customers. The labs overlap, the attack ratings rhyme, and perhaps 70% of the evidence can be common — if the documentation architecture is designed for dual consumption from the start. Run them as separate projects and you pay twice and risk divergent security claims that a sharp customer will notice.

Our position: one security architecture document, one attack analysis, two submission wrappers. We structure the evidence tree so EMVCo and EUCC each read what they need from the same trunk.

Software-based payment approvals are won on protection engineering but kept on operations: monitoring obligations, attack-response commitments and renewal evaluations on cycles far shorter than hardware’s. Teams budget the first evaluation and forget the treadmill — then discover their release process and their approval process fight each other quarterly. The viable SBMP products are the ones whose CI/CD, monitoring and evaluation evidence share one pipeline.

Our position: before entering SBMP, model three years of renewals against your release cadence. If the model doesn’t close, fix the architecture (or the cadence) first — the scheme will not bend.

Payment approvals without paying twice

EMVCo–CC evidence bridges, SBMP feasibility, renewal strategy, lab selection — thirty minutes to a plan.

Contact us

Request this document

We’ll send you access by email.