← Payment Reference GuidesCompliance & Certification

POS & SoftPOS Compliance: The Certification Path

A hardware POS terminal and a SoftPOS (Tap to Phone) app answer the same compliance questions — can it talk to the card, does it run EMV correctly, can it protect PINs and card data, does it work end-to-end for each brand and acquirer — but through different programmes. This guide generalises the process into phases, maps the work on each track side by side, and shows the approval path, timeline and re-certification triggers for both.

Show the path for

The generalised compliance process

Nine phases, the same for any card-acceptance product. Each row shows the question the phase answers and the programme that answers it on each track — so you can see where a SoftPOS app does the same work as a terminal, similar work under a different programme, or a genuinely different programme. The highlighted column follows the toggle above.

Same workSimilar workDifferent programme
1
Scope & planWhat exactly are we certifying, for whom, and where?Same work
Hardware POSCertification planBrands, kernels (contact + contactless), markets and acquirers fixed; hardware frozen for testingVendor · Plan + ICS drafts
SoftPOS appCertification planBrands, kernels (contactless only), markets and acquirers fixed; supported phones / OS policy and PIN-on-glass decision madeVendor · Plan + ICS drafts
2
Card-interface conformanceCan the device physically talk to a card?Different programme
Hardware POSEMVCo L1 — contact IFM + contactless PCDThe terminal’s own slot and antenna meet the electrical / RF specsEMVCo-accredited lab → EMVCo · L1 Letters of Approval
SoftPOS appBrand device-eligibility rulesThe phone’s NFC radio, OS level and attestation meet each brand’s Tap to Phone requirements — no per-phone EMVCo L1 approvalVendor against brand rules · Supported-device policy / allow-list
3
Kernel conformanceDoes it run the EMV transaction logic correctly?Same work
Hardware POSEMVCo L2 — contact kernel + contactless productContact kernel and each contactless kernel (C-2 … C-8) behave to specAccredited lab → EMVCo · L2 Letters of Approval
SoftPOS appEMVCo L2 — contactless kernels in the SDKEach contactless kernel in the SDK behaves to spec (no contact kernel)Accredited lab → EMVCo · L2 Letters of Approval
4
Security evaluationCan it protect PINs and card data under attack?Different programme
Hardware POSPCI PTS POI (+ SRED, Open Protocols)Tamper-responsive hardware, secure keypad, key storage, encrypted card readingPTS lab → PCI SSC · PTS approval number
SoftPOS appPCI MPoCSoftware protection of the SDK, a live attestation & monitoring back-end, and (optionally) secure PIN on glassMPoC lab → PCI SSC · MPoC listing
5
Brand programme onboardingHas each card brand accepted the product into its programme?Similar work
Hardware POSScheme reader programmese.g. Mastercard TQM label and contactless reader approval before M-TIPBrands / their auditors · TQM label, scheme LoAs
SoftPOS appBrand Tap to Phone programmesLicences and onboarding (e.g. Mastercard Tap on Phone), COTS-specific requirementsBrands · Programme approvals / licences
6
Brand integration testing (L3)Does the finished product with its real configuration work end-to-end per brand?Similar work
Hardware POSBrand L3 — Visa Global L3 Test Set, M-TIP, Amex, Discover E2E…Terminal + app + config + acquirer, on EMVCo-qualified L3 toolsAcquirer / vendor → brand · M-TIP LoA and brand sign-offs
SoftPOS appBrand L3 under the Tap to Phone programmesSame test approach, run on eligible phones, plus COTS-specific casesAcquirer / vendor → brand · Brand sign-offs
7
Acquirer host certificationDo we speak the acquirer’s message dialect?Same work
Hardware POSAcquirer host certificationISO 8583 / nexo messages, reversals, batch, key managementAcquirer · Certification letter
SoftPOS appAcquirer host certificationSame — usually via the SoftPOS provider’s gatewayAcquirer · Certification letter
8
Pilot & go-liveDoes it work with live cards at real merchants?Similar work
Hardware POSPilot + deploymentKeys injected at a key injection facility, terminals shipped, controlled pilotAcquirer + vendor · Pilot sign-off
SoftPOS appPilot + app-store releaseMonitoring back-end live, app published, merchant onboarding with device checks, controlled pilotAcquirer + vendor · Pilot sign-off
9
Stay compliantWhat keeps the approvals valid over time?Different programme
Hardware POSChange & expiry managementFirmware deltas on the PTS listing, L1 / L2 / PTS expiry dates, hardware refresh cyclesVendor · Updated listings
SoftPOS appContinuous complianceMonthly OS updates, new phone models, SDK releases through the MPoC change process, 24/7 monitoring operationsVendor + monitoring operator · Updated MPoC listing, device policy

The two tracks share phases 3, 6 and 7 almost unchanged. The real differences sit in the card interface (EMVCo L1 vs brand device-eligibility rules), security (PCI PTS POI hardware tests vs PCI MPoC software protection plus live monitoring) and staying compliant (occasional firmware deltas vs continuous OS, device and SDK change).

Deep dive: the terminal stack, layer by layer

Bottom to top: the interface that touches the card, the kernel that runs EMV, the application and configuration that brands test end-to-end, and the acquirer host. PCI PTS wraps the hardware; the programmes on the right apply depending on what and where you ship.

L1

Level 1 — Contact & contactless interface

L1 is the electrical and radio layer: the contact card slot (the Interface Module, IFM) and the contactless reader (the Proximity Coupling Device, PCD) with its antenna. It knows nothing about payments — it only has to power a card, keep timing inside tolerance, and move bytes reliably so the kernel above it can exchange APDUs.

How it works at runtime

  • Contact: applies VCC and clock, drives RST, receives the ATR and negotiates T=0 / T=1 (ISO/IEC 7816-3).
  • Contactless: raises the 13.56 MHz field, polls for Type A / Type B cards, runs anti-collision and activation, and signals a collision if two cards are in the field (ISO/IEC 14443, EMV Book D).
  • Hands a clean APDU pipe to L2. Framing errors, timeouts and field-strength problems surface here — not in the kernel.

Who is involved

Spec
EMV contact interface specification (Book 1, ISO/IEC 7816-3); EMV Contactless Book D (ISO/IEC 14443)
Tested by
EMVCo-accredited L1 laboratory with qualified test benches — contactless has separate analogue (RF) and digital (protocol) benches
Approved by
EMVCo — Letter of Approval (LoA), listed under Approved Products on emvco.com
Submitted by
Terminal or reader-module manufacturer
Approval unit
A specific IFM (contact) or PCD (contactless) hardware + firmware revision
Validity
Printed on the LoA. Contact IFM: 4 years, with one “restricted renewal” before it finally expires. Contactless PCD: set by EMVCo bulletin — check the LoA date
Typical duration
≈ 2–4 weeks lab time for contact, 4–8 weeks for contactless, plus 2–4 weeks EMVCo review (industry estimates)

Path to approval

  1. 1
    Design to the spec & pre-testVendor

    Characterise antenna tuning, field strength and waveforms in-house or with a lab pre-test; most L1 failures are antenna / matching issues found late.

  2. 2
    Register with EMVCoVendor → EMVCo

    Register as a vendor, obtain the test specifications, and choose an EMVCo-accredited laboratory.

  3. 3
    Submit ICS, RFA and samplesVendor → Lab / EMVCo

    Provide production-representative samples, the Implementation Conformance Statement declaring the options (Type A/B, voltage classes, protocols…) and the Request for Approval form; fees are paid before review.

  4. 4
    Lab testingAccredited lab

    Contact: electrical and protocol tests. Contactless: analogue tests (RF power, modulation, timing across the operating volume) and digital tests (protocol, anti-collision) — plus interoperability testing for PCDs.

  5. 5
    Test report to EMVCoLab → EMVCo

    The lab sends the report; failures go back to the vendor for a fix and re-test cycle.

  6. 6
    Letter of Approval & listingEMVCo

    EMVCo reviews the report and issues the L1 LoA. The LoA is valid while its approval number is posted on the EMVCo website.

Re-test when you change…

  • Any change to the reader module, antenna, matching circuit or PCB layout around it
  • Enclosure changes that move metal or the landing zone relative to the antenna
  • New firmware in the contact / contactless front-end controller

Common pitfalls

  • Testing with non-production housings: the plastic and any metal trim detune the antenna.
  • Treating the L1 approval of a bought-in reader module as covering the final terminal — integration into your enclosure can still break RF performance, and schemes test the finished device in L3.

Related: NFC payment flow · APDU protocol · APDU responses

One tap, every layer

Why the certifications are split the way they are: each step of a contactless purchase is owned by exactly one layer, and that layer's certification is what proves the step works.

  1. L1Field on, card detected, anti-collision, ISO 14443 activationL1 contactless (PCD) approval
  2. L2Entry Point selects the AID from the PPSE and hands off to kernel C-xL2 approval of Entry Point + that kernel
  3. L2GPO / READ RECORD, offline data authentication, CVM decision, GENERATE AC → ARQCL2 kernel approval
  4. PTSOnline PIN (if required) entered and encrypted into a PIN block; SRED encrypts card dataPCI PTS POI (Core + SRED)
  5. L3App builds the authorization with DE55, entry mode 07, terminal capabilities from its configBrand L3 (Visa Global L3 Test Set, Mastercard M-TIP …)
  6. HOSTAcquirer host receives 0100 / 0200, routes to the network, returns response + ARPCAcquirer host certification
  7. L3Receipt, reversal on failure, batch & clearing recordBrand L3 + host certification

What runs in parallel — hardware POS terminal

An indicative programme for a new countertop terminal. Hardware tracks (PTS, L1, radio) start as soon as production-representative hardware exists; L2 needs a stable interface; L3 needs everything below it plus the acquirer's final configuration. Durations are industry estimates and depend heavily on lab availability and first-pass success.

Critical path is usually PTS → L3. Starting the PTS evaluation late, or changing hardware after L1, is what turns a 6–8 month programme into a 12-month one.

I changed something — what do I re-certify? hardware POS terminal

Pick a change to see its impact. This is a planning aid based on how the programmes are structured; the lab, EMVCo, PCI SSC, the brands and your acquirer make the final call.

Full new approval Delta delta / regression Maybe depends on the change — not affected
ChangePTSL1L2L3Host
New antenna, reader module or PCB around the readerMaybeFullDeltaMaybe—
Enclosure, keypad or display redesignDeltaMaybe———
Security-relevant firmware / OS updateDelta————
Kernel bug fix or new kernel versionMaybe—FullDelta—
Enable a new contactless kernel (e.g. add C-6 Discover or C-8)——FullFullMaybe
Configuration change: TACs, floor / CVM / contactless limits, AIDs, CAPKs———Delta—
Payment app release touching EMV flow, DE55, CVM, fallback or receipts———DeltaDelta
Host message change (new DE, new tags, AES DUKPT / key blocks)Maybe——MaybeFull
Same terminal, new acquirer———FullFull
L1 / L2 approval reaches expiry—MaybeMaybe——

New antenna, reader module or PCB around the reader: New L1 approval for the IFM / PCD. A contactless product LoA names its PCD, so it has to be updated onto the new one; Mastercard contactless reader approval and TQM follow the hardware too, and brands may want contactless L3 cases re-run. PTS delta if the change touches the secure area.

Validity, expiry and what an expired approval means

ApprovalIssued byLifetimeAfter expiry
EMVCo L1 contact (IFM)EMVCo4 years, plus one restricted renewalCannot be renewed again — new deployments need a current approval
EMVCo L1 contactless (PCD)EMVCoPer EMVCo bulletin — read the date on the LoARenew, or re-approve on the current spec
EMVCo L2 contact kernelEMVCo4 years, plus one restricted renewalNew deployments need a current kernel; plan to replace expired kernels in the field
EMVCo contactless product (PCD + Entry Point + kernels)EMVCo3 yearsRenew, or re-approve on the current spec
Brand L3Card brand (via acquirer)Tied to the terminal / app / config / acquirer combinationRe-run when any of those change or the brand issues new mandatory test cases
Acquirer host certificationAcquirer / processorPer app version, by acquirer policyRe-certify on host spec or app changes
PCI PTS POI devicePCI SSCFixed date per POI version (v5: 30 April 2027); firmware approvals from v6 on: 3 yearsNo new deployments; installed devices may stay in service subject to brand / acquirer sunset rules
Mastercard TQM labelMastercard (via TQM auditor)Maintained by periodic vendor auditsNo label, no M-TIP for new products
PCI MPoC listing (SoftPOS)PCI SSCListing kept current through the MPoC change processNo new deployments on an expired or withdrawn listing; CPoC / SPoC sunset ends 31 October 2026
PCI Secure Software / P2PEPCI SSCListing with periodic re-validationRemoved from list if not revalidated

Expiry is about new deployments. Installed terminals normally keep working until the brands, PCI SSC or your acquirer set a sunset date — plan hardware refreshes around those dates, not around the Letter of Approval alone.

The paperwork you end up holding

ArtefactLayerWhat it is
ICS — Implementation Conformance StatementL2Declares every option the product supports; drives which test cases apply at L1 and L2.
EMVCo Letter of Approval (L1)L1Names the IFM / PCD hardware and firmware revision and its approval number.
EMVCo Letter of Approval (L2)L2Contact kernel LoA, Terminal Contactless Product LoA (PCD + Entry Point + kernels) or stand-alone C-8 kernel LoA — with version, checksum and configurations.
Mastercard TQM labelL3Proof the vendor’s manufacturing and configuration control passed Mastercard’s quality audit; needed before M-TIP.
Brand L3 approval / acknowledgementL3Mastercard M-TIP LoA, Visa / Amex / Discover L3 sign-offs — per terminal, app, configuration and acquirer.
Acquirer certification letterHOSTConfirms the host protocol implementation for a given app version.
PCI PTS approval numberPTSListing with approved hardware and firmware versions and modules (Core, SRED, OP).
PCI SSC listing (SSF / P2PE)SWValidated software or P2PE solution on the PCI SSC website.
PCI MPoC listingCOTSSoftPOS equivalent of the PTS approval: the listed MPoC software / solution and its versions.
Supported-device policyCOTSSoftPOS equivalent of the L1 LoA: which phone models and OS versions meet the brands’ eligibility rules.

Readiness checklist — hardware POS terminal

Tick off the prerequisites to see what you can start next. Nothing is stored or sent anywhere.

Next: Freeze hardware — PTS, L1 and radio testing all need production-representative samples.

Related reading & tools

EMVCo L1 / L2 / L3 summary · Scheme & Tap to Phone programmes · PCI PTS & SSF · EMV contactless kernels · POS terminal config builder · TVR decoder · ISO 8583 parser

Keep reading

Related articles