Payment Certification Levels
A practical guide to EMVCo L1 / L2 / L3 terminal certifications, PCI DSS merchant compliance tiers, and the standards that govern every card-present transaction.
EMVCo Terminal Certification Levels
EMVCo defines three progressive levels of certification for payment terminals. Every device that accepts chip cards must pass all three — in sequence. L1 is hardware, L2 is the kernel, L3 ties the whole stack to a specific acquirer.
Contact & Contactless Interface
L1 certifies the physical and electrical interface between the terminal hardware and the chip card (or NFC antenna). It has nothing to do with software — it validates that the reader can correctly power a card, maintain signal timing, and meet the electrical specs defined in ISO/IEC 7816 (contact) and ISO/IEC 14443 (contactless).
What is tested
- Card slot power supply (VCC, VPP, GND)
- Clock signal timing and frequency (CLK)
- Reset signal (RST) behaviour
- I/O data line signal levels and protocol
- Contactless RF field strength and waveform (NFC)
- ESD / EMC immunity and emissions
- Card insertion / ejection force tolerances
- Dual-interface reader: contact + contactless coexistence
Key facts
EMV Kernel (Chip Processing Software)
L2 certifies the EMV kernel software — the transaction processing logic that runs on top of the L1 hardware. The kernel handles application selection, chip communication, offline data authentication, cardholder verification, and the terminal's action analysis. Each payment scheme runs its own certification program for its own kernel.
What is tested
- Application selection (PSE / PPSE, AID matching)
- File reading (GPO, Read Record)
- Offline Data Authentication: SDA, DDA, CDA
- Terminal Risk Management (velocity checks, floor limit)
- Cardholder Verification Methods (PIN, signature, no-CVM)
- Terminal Action Analysis → ARQC / TC / AAC decision
- Contactless tap flow (CDCVM, Magstripe mode, EMV mode)
- TVR, TSI, and transaction log correctness
Certification per scheme
Payment Application / Acquirer Integration
L3 certifies the complete payment application against a specific acquirer or payment processor. While L1 and L2 are standardised globally, L3 is performed between the terminal software vendor and each acquirer individually. It validates that the ISO 8583 (or proprietary) messages match the acquirer's host expectations for every transaction type.
What is tested
- Authorization requests and responses (0100/0110)
- Completions and reversals (0200/0400)
- Batch / settlement messages (0500/0510/0520)
- Decline handling and fallback scenarios
- ARQC validation on the host side
- DE55 (EMV data) encoding and field presence
- Contactless threshold routing and CVM handling
- Network-specific fields (POS entry mode, terminal capabilities)
Key facts
Certification Path
Each level must be completed before the next can begin. L1 and L2 are reusable across acquirers; L3 is specific to each acquirer relationship.
Related Tools
Use these tools to work with the cryptographic primitives that underpin terminal and card security.