Reference

Payment Certification Levels

A practical guide to EMVCo L1 / L2 / L3 terminal certifications, PCI DSS merchant compliance tiers, and the standards that govern every card-present transaction.

EMVCo Terminal Certification Levels

EMVCo defines three progressive levels of certification for payment terminals. Every device that accepts chip cards must pass all three — in sequence. L1 is hardware, L2 is the kernel, L3 ties the whole stack to a specific acquirer.

L1

Contact & Contactless Interface

L1 certifies the physical and electrical interface between the terminal hardware and the chip card (or NFC antenna). It has nothing to do with software — it validates that the reader can correctly power a card, maintain signal timing, and meet the electrical specs defined in ISO/IEC 7816 (contact) and ISO/IEC 14443 (contactless).

What is tested

  • Card slot power supply (VCC, VPP, GND)
  • Clock signal timing and frequency (CLK)
  • Reset signal (RST) behaviour
  • I/O data line signal levels and protocol
  • Contactless RF field strength and waveform (NFC)
  • ESD / EMC immunity and emissions
  • Card insertion / ejection force tolerances
  • Dual-interface reader: contact + contactless coexistence

Key facts

  • StandardsISO/IEC 7816-3, ISO/IEC 14443, EMVCo Book 1
  • Certified byEMVCo-approved test labs (UL, Fime, SGS, BV)
  • Applies toPOS terminals, ATMs, kiosks, mobile readers
  • ValidityTypically 3–5 years; re-certification required on hardware change
  • Who submitsTerminal hardware manufacturer
Practical note: L1 certification is tied to the specific hardware revision. Any change to the card reader module, PCB layout, or antenna design typically requires a new L1 submission.
L2

EMV Kernel (Chip Processing Software)

L2 certifies the EMV kernel software — the transaction processing logic that runs on top of the L1 hardware. The kernel handles application selection, chip communication, offline data authentication, cardholder verification, and the terminal's action analysis. Each payment scheme runs its own certification program for its own kernel.

What is tested

  • Application selection (PSE / PPSE, AID matching)
  • File reading (GPO, Read Record)
  • Offline Data Authentication: SDA, DDA, CDA
  • Terminal Risk Management (velocity checks, floor limit)
  • Cardholder Verification Methods (PIN, signature, no-CVM)
  • Terminal Action Analysis → ARQC / TC / AAC decision
  • Contactless tap flow (CDCVM, Magstripe mode, EMV mode)
  • TVR, TSI, and transaction log correctness

Certification per scheme

  • VisaVisa Contactless Payload / VIS testing (VCPS)
  • MastercardTQM (Terminal Quality Management)
  • AmexExpressPay Approval
  • DiscoverD-PAS Approval
  • JCBJ/Speedy, J/Smart
  • UnionPayQuickPass certification
  • Cartes BancairesCB2A kernel approval
Important: A terminal must obtain L2 approval separately for each payment scheme kernel it wishes to support. A Visa L2 approval does not cover Mastercard — they are independent certifications, often with independent test tools.
L3

Payment Application / Acquirer Integration

L3 certifies the complete payment application against a specific acquirer or payment processor. While L1 and L2 are standardised globally, L3 is performed between the terminal software vendor and each acquirer individually. It validates that the ISO 8583 (or proprietary) messages match the acquirer's host expectations for every transaction type.

What is tested

  • Authorization requests and responses (0100/0110)
  • Completions and reversals (0200/0400)
  • Batch / settlement messages (0500/0510/0520)
  • Decline handling and fallback scenarios
  • ARQC validation on the host side
  • DE55 (EMV data) encoding and field presence
  • Contactless threshold routing and CVM handling
  • Network-specific fields (POS entry mode, terminal capabilities)

Key facts

  • Certification bodyEach acquirer independently — no global standard
  • Also calledTerminal Integration, Acquirer Certification, Host Cert
  • Message formatISO 8583 (1987 or 1993) or acquirer-proprietary protocol
  • Who submitsPayment application / ISV / integration partner
  • ScopeOne certification per acquirer + terminal type combination
  • Re-cert triggersNew transaction type, new DE, major app version
Practical note: A single terminal application deployed across multiple acquirers typically requires an L3 certification with each one. Payment facilitators and ISO integrators often maintain their own certification programs on behalf of their sub-merchants.

Certification Path

1
L1 — HardwareSubmit terminal to EMVCo lab
2
L2 — KernelSubmit per scheme (Visa, MC, …)
3
L3 — AcquirerCertify per acquirer / processor

Each level must be completed before the next can begin. L1 and L2 are reusable across acquirers; L3 is specific to each acquirer relationship.

Related Tools

Use these tools to work with the cryptographic primitives that underpin terminal and card security.