EMVCo security evaluation certifies that payment products resist attackers rated in the smartcard tradition: recognised labs attack the target — chip, platform or software solution — and score feasibility against attack-potential tables that EMVCo recalibrates as techniques evolve. Approvals are time-limited by design; a product that passed three years ago must still resist today’s published state of the art to keep its approval alive. That perpetual-motion quality is the scheme’s defining discipline — and the reason payment silicon teams never really finish certifying.
The hardware track (payment ICs and platforms) shares labs, methodology DNA and attack ratings with Common Criteria’s smartcard world — most payment chips carry both an EMVCo approval and a CC/EUCC certificate, built from substantially overlapping evidence. The software track, SBMP, extends the logic to software-based mobile payments where no secure element is guaranteed: white-box cryptography, runtime protections and back-end monitoring evaluated as a system, with shorter renewal cycles reflecting the softer target.
Around EMVCo sits the wider payment approval economy: PCI SSC programmes (PTS for terminals, P2PE, and related) govern the acceptance side, and the card schemes layer their own functional and security approvals on top of EMVCo results. For a product roadmap, EMVCo is rarely the only gate — but it is almost always the first one the others reference.