We establish which evaluation applies to what you have built — IC, Platform, or ICC — and where the boundary of the target sits. Composite products inherit results from the layer beneath them, so getting the boundary right is what determines whether you are re-testing the chip or reusing its certificate.
Your design documentation, security architecture, and guidance documents are what the evaluation is conducted against. We review them early, while a finding is still a design change rather than a re-spin. For composite evaluations, this is also where we check that you are meeting the conditions set out in the underlying certificate's guidance documents, which is a common source of late surprises.
Our evaluators study your design and implementation information and build a structured analysis of where the product is likely to be attackable. This drives everything downstream: the output is a prioritized selection of tests for the penetration campaign, not a generic checklist. It is also the stage where a pre-evaluation delivers the most value, because findings here are cheap to act on.
The attack campaign itself, run in our laboratory against an attacker profile with high attack potential. Side-channel analysis, fault injection, invasive and semi-invasive techniques, and logical attacks on the platform and applications, calibrated to the attack methods and rating scales EMVCo currently recognizes.
We produce the evaluation report and submit it to EMVCo, then work through any questions raised during review until the report meets the requirements and EMVCo issues your ICCN or PCN. You get one point of contact for the submission rather than managing the exchange yourself.
Certificates carry expiry dates, and product changes, new derivatives, and new mask revisions all have implications for what you hold. We plan the maintenance path at the start — including derivative and delta evaluations — so renewal is a scheduled activity rather than a scramble against a launch date.
The IC evaluation covers the chip hardware together with any software crypto libraries resident on the chip, and results in an ICCN. Many chip vendors run this stage as a Common Criteria evaluation instead of a dedicated EMVCo IC evaluation, because the same silicon typically also serves government, identity, and other regulated domains that require CC. EMVCo recognizes CC results in its IC certification process, so both can be conducted together with minimal duplicated effort. If you are a silicon vendor selling into more than one market, this is usually the decision worth making first.
The platform evaluation covers the operating system running on an already-evaluated chip, and results in a PCN. It is a composite evaluation: it builds on the IC results rather than repeating them, and its scope covers the generic software layer — cryptographic algorithms, memory and lifecycle management, applet isolation, and the platform's own security mechanisms. Composite evaluation is only efficient if the platform correctly honors the guidance attached to the IC certificate, which is where these campaigns most often lose time.
The ICC evaluation covers the complete product: the platform and all applications on it, as it will actually be issued. It reuses the chip evaluation and, where one exists, the platform evaluation. This is the level the payment schemes care about for an issued product, and EMVCo's recognised laboratory list shows Keysight in scope to conduct it.
Certification covers the scope EMVCo defines. Some vendors also want a view of product security risks outside that scope, and we offer evaluation work for that separately. It looks at where attack potential and field threats are developing rather than only at where the current requirements sit, which some teams find useful for roadmap planning on products with long field lifetimes.
Focus on advancing your product while Keysight guides you through EMVCo preparation and evaluation.
EMVCo recognizes us at all three hardware levels, covering the chip, the platform, and the finished card, as well as software-based mobile payment. One laboratory can therefore evaluate your current product, the next one on your roadmap, and the mobile solution alongside it.
Most delays in EMVCo campaigns trace back to incomplete design documentation, or to composite guidance that the platform does not fully implement. Our pre-evaluation surfaces those gaps early, while your team can still address them as design changes.
We plan your EMVCo work alongside the other schemes on your roadmap, including Common Criteria and the payment programs. One campaign then covers several components and product variants, and each new derivative costs less to certify than the last.
Our experts regularly share practical insights in our blog. Explore the latest developments in device security.
It is the process the payment industry uses to establish that chip-based payment products resist realistic attacks. A recognized independent laboratory performs a vulnerability analysis and a penetration test campaign against the product, then submits an evaluation report to EMVCo. EMVCo reviews the report and, if it is satisfactory, issues a product certificate: an ICCN for an IC product or a PCN for a platform product.
Chip-based payment products, including contact and contactless payment cards, and the secure elements behind mobile and wearable payments in any form factor — SIM, eSE, iSE, SoC, and others. In practice the payment schemes expect the chip underneath a payment application to carry an EMVCo security evaluation, so if you are a silicon, platform, or card vendor selling into payments, the process applies to you somewhere in your stack. Which level applies to you depends on where you sit in it.
IC evaluation covers the chip hardware and its on-chip crypto libraries. Platform evaluation covers the operating system on top of an evaluated chip. ICC evaluation covers the complete card product, platform plus applications, as issued. Platform and ICC evaluations are composite: they build on the results below them rather than starting from scratch.
Yes, and for IC vendors it is usually the efficient path. Most smart card chips are also sold into domains such as government and identity that require Common Criteria, and EMVCo recognizes CC results in its IC certification process. Running both together removes most of the duplicated effort. We can also fold in other schemes you are pursuing.
A pre-evaluation is the vulnerability analysis and testing work run ahead of the formal campaign, with the specific goal of finding problems while you can still fix them cheaply. It is not required, but it is the most reliable way we know to keep a certification timeline intact. We can fully separate pre-evaluation from certification work so the two run on different schedules.
It is the attacker profile the evaluation is calibrated against: a well-resourced, well-informed adversary with access to specialist equipment and the time to use it. Practically, it means the campaign includes invasive and semi-invasive physical attacks, advanced side-channel analysis, and fault injection, not only the attacks a casual adversary could mount.
It depends on the level, the complexity of the target, and how complete your documentation is on day one. Documentation readiness is consistently the largest variable. For composite evaluations, whether the underlying certificate's guidance has been correctly implemented is the second largest.
Yes. Certificates carry an expiry date, and changes to the product, new derivatives, or new hardware revisions can require additional evaluation work. EMVCo documents this in its Certificate Issuance, Renewal and Extension Process. We plan the renewal and derivative path as part of the initial engagement so it lands in your roadmap rather than on top of a launch.
Two things, both on your side and both worth starting early. You must be registered as an EMVCo Vendor through the Card and Mobile Type Approval registration process, and you must have signed a Security Evaluation Agreement with EMVCo's Security Evaluation Working Group. Teams that leave these until the product is ready to test lose weeks to paperwork they could have cleared months earlier.
Development and production sites are also in scope for an EMVCo product approval, and audits may be required against EMVCo's site audit guidelines. If your product is manufactured or personalized across multiple locations, factor this in when you plan the campaign rather than discovering it late.
There are two separate costs. The evaluation itself is scoped and quoted by the laboratory, and EMVCo charges its own registration fee per submission — for new products, renewals, updates, and extensions of expired certificates alike.
Typically your hardware security architect, the OS or platform lead, whoever owns the cryptographic implementation, and someone who owns documentation. Naming a documentation owner at the start is the cheapest thing you can do to protect the schedule.
Yes. Keysight also runs the EMVCo Software Based Mobile Payment (SBMP) program, covering software protection tools, HCE applications and SDKs, trusted execution environments, CDCVM, and OEM payment solutions.
Yes. We provide security evaluation services for product risks outside the mandated EMVCo scope, anticipating developments in attack potential and field threats so you can plan your roadmap against where attackers are going rather than where the requirements currently sit.
What are you looking for?