A hardware POS terminal and a SoftPOS (Tap to Phone) app answer the same compliance questions — can it talk to the card, does it run EMV correctly, can it protect PINs and card data, does it work end-to-end for each brand and acquirer — but through different programmes. This guide generalises the process into phases, maps the work on each track side by side, and shows the approval path, timeline and re-certification triggers for both.
Show the path for
The generalised compliance process
Nine phases, the same for any card-acceptance product. Each row shows the question the phase answers and the programme that answers it on each track — so you can see where a SoftPOS app does the same work as a terminal, similar work under a different programme, or a genuinely different programme. The highlighted column follows the toggle above.
Same workSimilar workDifferent programme
PhaseHardware POS terminalSoftPOS app
1
Scope & planWhat exactly are we certifying, for whom, and where?Same work
Hardware POSCertification planBrands, kernels (contact + contactless), markets and acquirers fixed; hardware frozen for testingVendor · Plan + ICS drafts
SoftPOS appCertification planBrands, kernels (contactless only), markets and acquirers fixed; supported phones / OS policy and PIN-on-glass decision madeVendor · Plan + ICS drafts
2
Card-interface conformanceCan the device physically talk to a card?Different programme
Hardware POSEMVCo L1 — contact IFM + contactless PCDThe terminal’s own slot and antenna meet the electrical / RF specsEMVCo-accredited lab → EMVCo · L1 Letters of Approval
SoftPOS appBrand device-eligibility rulesThe phone’s NFC radio, OS level and attestation meet each brand’s Tap to Phone requirements — no per-phone EMVCo L1 approvalVendor against brand rules · Supported-device policy / allow-list
3
Kernel conformanceDoes it run the EMV transaction logic correctly?Same work
Hardware POSEMVCo L2 — contact kernel + contactless productContact kernel and each contactless kernel (C-2 … C-8) behave to specAccredited lab → EMVCo · L2 Letters of Approval
SoftPOS appEMVCo L2 — contactless kernels in the SDKEach contactless kernel in the SDK behaves to spec (no contact kernel)Accredited lab → EMVCo · L2 Letters of Approval
4
Security evaluationCan it protect PINs and card data under attack?Different programme
Hardware POSPCI PTS POI (+ SRED, Open Protocols)Tamper-responsive hardware, secure keypad, key storage, encrypted card readingPTS lab → PCI SSC · PTS approval number
SoftPOS appPCI MPoCSoftware protection of the SDK, a live attestation & monitoring back-end, and (optionally) secure PIN on glassMPoC lab → PCI SSC · MPoC listing
5
Brand programme onboardingHas each card brand accepted the product into its programme?Similar work
Hardware POSScheme reader programmese.g. Mastercard TQM label and contactless reader approval before M-TIPBrands / their auditors · TQM label, scheme LoAs
SoftPOS appBrand Tap to Phone programmesLicences and onboarding (e.g. Mastercard Tap on Phone), COTS-specific requirementsBrands · Programme approvals / licences
6
Brand integration testing (L3)Does the finished product with its real configuration work end-to-end per brand?Similar work
Hardware POSBrand L3 — Visa Global L3 Test Set, M-TIP, Amex, Discover E2E…Terminal + app + config + acquirer, on EMVCo-qualified L3 toolsAcquirer / vendor → brand · M-TIP LoA and brand sign-offs
SoftPOS appBrand L3 under the Tap to Phone programmesSame test approach, run on eligible phones, plus COTS-specific casesAcquirer / vendor → brand · Brand sign-offs
7
Acquirer host certificationDo we speak the acquirer’s message dialect?Same work
SoftPOS appContinuous complianceMonthly OS updates, new phone models, SDK releases through the MPoC change process, 24/7 monitoring operationsVendor + monitoring operator · Updated MPoC listing, device policy
The two tracks share phases 3, 6 and 7 almost unchanged. The real differences sit in the card interface (EMVCo L1 vs brand device-eligibility rules), security (PCI PTS POI hardware tests vs PCI MPoC software protection plus live monitoring) and staying compliant (occasional firmware deltas vs continuous OS, device and SDK change).
Deep dive: the terminal stack, layer by layer
Bottom to top: the interface that touches the card, the kernel that runs EMV, the application and configuration that brands test end-to-end, and the acquirer host. PCI PTS wraps the hardware; the programmes on the right apply depending on what and where you ship.
L1
Level 1 — Contact & contactless interface
L1 is the electrical and radio layer: the contact card slot (the Interface Module, IFM) and the contactless reader (the Proximity Coupling Device, PCD) with its antenna. It knows nothing about payments — it only has to power a card, keep timing inside tolerance, and move bytes reliably so the kernel above it can exchange APDUs.
How it works at runtime
Contact: applies VCC and clock, drives RST, receives the ATR and negotiates T=0 / T=1 (ISO/IEC 7816-3).
Contactless: raises the 13.56 MHz field, polls for Type A / Type B cards, runs anti-collision and activation, and signals a collision if two cards are in the field (ISO/IEC 14443, EMV Book D).
Hands a clean APDU pipe to L2. Framing errors, timeouts and field-strength problems surface here — not in the kernel.
Who is involved
Spec
EMV contact interface specification (Book 1, ISO/IEC 7816-3); EMV Contactless Book D (ISO/IEC 14443)
Tested by
EMVCo-accredited L1 laboratory with qualified test benches — contactless has separate analogue (RF) and digital (protocol) benches
Approved by
EMVCo — Letter of Approval (LoA), listed under Approved Products on emvco.com
Submitted by
Terminal or reader-module manufacturer
Approval unit
A specific IFM (contact) or PCD (contactless) hardware + firmware revision
Validity
Printed on the LoA. Contact IFM: 4 years, with one “restricted renewal” before it finally expires. Contactless PCD: set by EMVCo bulletin — check the LoA date
Typical duration
≈ 2–4 weeks lab time for contact, 4–8 weeks for contactless, plus 2–4 weeks EMVCo review (industry estimates)
Path to approval
1
Design to the spec & pre-testVendor
Characterise antenna tuning, field strength and waveforms in-house or with a lab pre-test; most L1 failures are antenna / matching issues found late.
2
Register with EMVCoVendor → EMVCo
Register as a vendor, obtain the test specifications, and choose an EMVCo-accredited laboratory.
3
Submit ICS, RFA and samplesVendor → Lab / EMVCo
Provide production-representative samples, the Implementation Conformance Statement declaring the options (Type A/B, voltage classes, protocols…) and the Request for Approval form; fees are paid before review.
4
Lab testingAccredited lab
Contact: electrical and protocol tests. Contactless: analogue tests (RF power, modulation, timing across the operating volume) and digital tests (protocol, anti-collision) — plus interoperability testing for PCDs.
5
Test report to EMVCoLab → EMVCo
The lab sends the report; failures go back to the vendor for a fix and re-test cycle.
6
Letter of Approval & listingEMVCo
EMVCo reviews the report and issues the L1 LoA. The LoA is valid while its approval number is posted on the EMVCo website.
Re-test when you change…
Any change to the reader module, antenna, matching circuit or PCB layout around it
Enclosure changes that move metal or the landing zone relative to the antenna
New firmware in the contact / contactless front-end controller
Common pitfalls
Testing with non-production housings: the plastic and any metal trim detune the antenna.
Treating the L1 approval of a bought-in reader module as covering the final terminal — integration into your enclosure can still break RF performance, and schemes test the finished device in L3.
Why the certifications are split the way they are: each step of a contactless purchase is owned by exactly one layer, and that layer's certification is what proves the step works.
L1Field on, card detected, anti-collision, ISO 14443 activationL1 contactless (PCD) approval
L2Entry Point selects the AID from the PPSE and hands off to kernel C-xL2 approval of Entry Point + that kernel
L2GPO / READ RECORD, offline data authentication, CVM decision, GENERATE AC → ARQCL2 kernel approval
PTSOnline PIN (if required) entered and encrypted into a PIN block; SRED encrypts card dataPCI PTS POI (Core + SRED)
L3App builds the authorization with DE55, entry mode 07, terminal capabilities from its configBrand L3 (Visa Global L3 Test Set, Mastercard M-TIP …)
HOSTAcquirer host receives 0100 / 0200, routes to the network, returns response + ARPCAcquirer host certification
An indicative programme for a new countertop terminal. Hardware tracks (PTS, L1, radio) start as soon as production-representative hardware exists; L2 needs a stable interface; L3 needs everything below it plus the acquirer's final configuration. Durations are industry estimates and depend heavily on lab availability and first-pass success.
0w4w8w12w16w20w24w28w32w
Radio / safety (CE, FCC…)Needs final hardware
PCI PTS POI evaluationLab evaluation + PCI SSC review
L1 contact + contactlessPre-test, lab, LoA
L2 contact kernelCan start once L1 is stable
L2 contactless kernels (parallel)PCD + Entry Point + kernels
Mastercard TQM labelQuality audit, after the L1 LoA
Critical path is usually PTS → L3. Starting the PTS evaluation late, or changing hardware after L1, is what turns a 6–8 month programme into a 12-month one.
I changed something — what do I re-certify? hardware POS terminal
Pick a change to see its impact. This is a planning aid based on how the programmes are structured; the lab, EMVCo, PCI SSC, the brands and your acquirer make the final call.
Full new approval Delta delta / regression Maybe depends on the change — not affected
Change
PTS
L1
L2
L3
Host
New antenna, reader module or PCB around the reader
Maybe
Full
Delta
Maybe
—
Enclosure, keypad or display redesign
Delta
Maybe
—
—
—
Security-relevant firmware / OS update
Delta
—
—
—
—
Kernel bug fix or new kernel version
Maybe
—
Full
Delta
—
Enable a new contactless kernel (e.g. add C-6 Discover or C-8)
Host message change (new DE, new tags, AES DUKPT / key blocks)
Maybe
—
—
Maybe
Full
Same terminal, new acquirer
—
—
—
Full
Full
L1 / L2 approval reaches expiry
—
Maybe
Maybe
—
—
New antenna, reader module or PCB around the reader: New L1 approval for the IFM / PCD. A contactless product LoA names its PCD, so it has to be updated onto the new one; Mastercard contactless reader approval and TQM follow the hardware too, and brands may want contactless L3 cases re-run. PTS delta if the change touches the secure area.
Validity, expiry and what an expired approval means
Approval
Issued by
Lifetime
After expiry
EMVCo L1 contact (IFM)
EMVCo
4 years, plus one restricted renewal
Cannot be renewed again — new deployments need a current approval
EMVCo L1 contactless (PCD)
EMVCo
Per EMVCo bulletin — read the date on the LoA
Renew, or re-approve on the current spec
EMVCo L2 contact kernel
EMVCo
4 years, plus one restricted renewal
New deployments need a current kernel; plan to replace expired kernels in the field
EMVCo contactless product (PCD + Entry Point + kernels)
EMVCo
3 years
Renew, or re-approve on the current spec
Brand L3
Card brand (via acquirer)
Tied to the terminal / app / config / acquirer combination
Re-run when any of those change or the brand issues new mandatory test cases
Acquirer host certification
Acquirer / processor
Per app version, by acquirer policy
Re-certify on host spec or app changes
PCI PTS POI device
PCI SSC
Fixed date per POI version (v5: 30 April 2027); firmware approvals from v6 on: 3 years
No new deployments; installed devices may stay in service subject to brand / acquirer sunset rules
Mastercard TQM label
Mastercard (via TQM auditor)
Maintained by periodic vendor audits
No label, no M-TIP for new products
PCI MPoC listing (SoftPOS)
PCI SSC
Listing kept current through the MPoC change process
No new deployments on an expired or withdrawn listing; CPoC / SPoC sunset ends 31 October 2026
PCI Secure Software / P2PE
PCI SSC
Listing with periodic re-validation
Removed from list if not revalidated
Expiry is about new deployments. Installed terminals normally keep working until the brands, PCI SSC or your acquirer set a sunset date — plan hardware refreshes around those dates, not around the Letter of Approval alone.
The paperwork you end up holding
Artefact
Layer
What it is
ICS — Implementation Conformance Statement
L2
Declares every option the product supports; drives which test cases apply at L1 and L2.
EMVCo Letter of Approval (L1)
L1
Names the IFM / PCD hardware and firmware revision and its approval number.
EMVCo Letter of Approval (L2)
L2
Contact kernel LoA, Terminal Contactless Product LoA (PCD + Entry Point + kernels) or stand-alone C-8 kernel LoA — with version, checksum and configurations.
Mastercard TQM label
L3
Proof the vendor’s manufacturing and configuration control passed Mastercard’s quality audit; needed before M-TIP.
Brand L3 approval / acknowledgement
L3
Mastercard M-TIP LoA, Visa / Amex / Discover L3 sign-offs — per terminal, app, configuration and acquirer.
Acquirer certification letter
HOST
Confirms the host protocol implementation for a given app version.
PCI PTS approval number
PTS
Listing with approved hardware and firmware versions and modules (Core, SRED, OP).
PCI SSC listing (SSF / P2PE)
SW
Validated software or P2PE solution on the PCI SSC website.
PCI MPoC listing
COTS
SoftPOS equivalent of the PTS approval: the listed MPoC software / solution and its versions.
Supported-device policy
COTS
SoftPOS equivalent of the L1 LoA: which phone models and OS versions meet the brands’ eligibility rules.
Readiness checklist — hardware POS terminal
Tick off the prerequisites to see what you can start next. Nothing is stored or sent anywhere.
Next: Freeze hardware — PTS, L1 and radio testing all need production-representative samples.