Payment Certification Levels
A practical guide to EMVCo L1 / L2 / L3 terminal certifications, PCI DSS merchant compliance tiers, and the standards that govern every card-present transaction.
EMV Payment Tokenization
Replaces the cardholder's real card number (FPAN — Funding PAN) with a surrogate token (DPAN — Device/Digital PAN) of the same length and format. The DPAN is domain-restricted and can only be used with the specific device, wallet, or merchant it was issued for. Defined in EMVCo Payment Tokenization Specification.
FPAN vs DPAN
Real PAN embossed on the physical card. If stolen, it can be used anywhere the card is accepted. Changing it requires physical card reissuance and disrupts all active subscriptions.
Token generated by the Token Service Provider (TSP). Same 16-digit length, passes Luhn check. Domain-restricted: locked to a specific device, merchant, or use case. Compromise means deactivate that token only — FPAN is unaffected.
Token Ecosystem Players
Owns the real card. Initiates provisioning by adding card to wallet or consenting to token issuance.
Merchant, wallet app, or payment facilitator that requests the token. Each TR receives a unique Token Requestor ID (TRID) from the scheme.
Generates and manages tokens. Acts as trusted intermediary between the TR and issuer. Maintains the FPAN-to-DPAN mapping vault.
Approves token provisioning, controls Token Assurance Level requirements, and receives the DPAN in authorization messages (de-tokenizes internally).
Visa (VTS), Mastercard (MDES), Amex (AEIPS) operate the TSP function for their respective scheme.
Major Token Services
Token BIN starts with 4. Supports push and pull provisioning. Powers Apple Pay, Google Pay, Samsung Pay for Visa cards. Token validation via TAVV cryptogram.
Token BIN may differ from FPAN BIN (separate BIN range). Uses DSRP cryptogram for CNP tokenized transactions. Full EMV-like cryptogram from device secure element.
15-digit tokens matching Amex PAN length. Manages provisioning for Amex cards in Apple Pay and Google Pay. CAVV equivalent for e-commerce tokenized flows.
Token Lifecycle
Transaction Cryptograms
Push vs Pull Provisioning
Bank pushes eligible cards to the customer's wallet app automatically. Customer sees the card in wallet after login without manual entry. Requires deep bank-wallet integration. Common in banking apps.
Customer manually photographs card or enters PAN in wallet app. TSP validates identity via OTP or call center. No prior bank-wallet integration needed. Common for adding cards to Apple Pay / Google Pay.
Token Assurance Level (TAL)
Related Tools
Use these tools to work with the cryptographic primitives that underpin terminal and card security.