The EMVCo Security Evaluation Process is how the payment industry establishes that the silicon underneath a transaction holds up against a determined attacker. EMVCo has worked with recognized independent laboratories since 2005 to evaluate EMV Integrated Circuit (IC), Platform, and Integrated Circuit Card (ICC) products, and has since extended the scope to embedded Secure Elements (eSE), System on Chips (SoC), and IoT payment hardware. The evaluation is adversarial by design: a laboratory studies your design and implementation, builds a vulnerability analysis, and then executes a penetration test campaign to determine whether the product resists an attacker with high attack potential. The report goes to EMVCo, which issues an ICCN for an IC product or a PCN for a platform.

Keysight runs that process end to end. We are accredited to perform IC and platform evaluations and crypto library assessments, and all major payment systems — Visa, Mastercard, American Express, and Cartes Bancaires — accredit us to conduct ICC evaluations. We take you from scoping and pre-evaluation through the formal campaign and the report EMVCo needs to certify.

emvco logo
Your Path to EMVCo Certification
red icon with a grid

Discovery and Scoping

We establish which evaluation applies to what you have built — IC, Platform, or ICC — and where the boundary of the target sits. Composite products inherit results from the layer beneath them, so getting the boundary right is what determines whether you are re-testing the chip or reusing its certificate.

red icon with a folder

Design and Documentation Review

Your design documentation, security architecture, and guidance documents are what the evaluation is conducted against. We review them early, while a finding is still a design change rather than a re-spin. For composite evaluations, this is also where we check that you are meeting the conditions set out in the underlying certificate's guidance documents, which is a common source of late surprises.

red icon with a magnifying glass

Vulnerability Analysis

Our evaluators study your design and implementation information and build a structured analysis of where the product is likely to be attackable. This drives everything downstream: the output is a prioritized selection of tests for the penetration campaign, not a generic checklist. It is also the stage where a pre-evaluation delivers the most value, because findings here are cheap to act on.

red icon with a masked figure

Penetration Testing

The attack campaign itself, run in our laboratory against an attacker profile with high attack potential. Side-channel analysis, fault injection, invasive and semi-invasive techniques, and logical attacks on the platform and applications, calibrated to the attack methods and rating scales EMVCo currently recognizes.

red icon with a certificate

Reporting and Certification

We produce the evaluation report and submit it to EMVCo, then work through any questions raised during review until the report meets the requirements and EMVCo issues your ICCN or PCN. You get one point of contact for the submission rather than managing the exchange yourself.

red icon with two circular arrows

Maintenance and Renewal

Certificates carry expiry dates, and product changes, new derivatives, and new mask revisions all have implications for what you hold. We plan the maintenance path at the start — including derivative and delta evaluations — so renewal is a scheduled activity rather than a scramble against a launch date.

EMVCo Evaluation Tiers

The IC evaluation covers the chip hardware together with any software crypto libraries resident on the chip, and results in an ICCN. Many chip vendors run this stage as a Common Criteria evaluation instead of a dedicated EMVCo IC evaluation, because the same silicon typically also serves government, identity, and other regulated domains that require CC. EMVCo recognizes CC results in its IC certification process, so both can be conducted together with minimal duplicated effort. If you are a silicon vendor selling into more than one market, this is usually the decision worth making first.

The platform evaluation covers the operating system running on an already-evaluated chip, and results in a PCN. It is a composite evaluation: it builds on the IC results rather than repeating them, and its scope covers the generic software layer — cryptographic algorithms, memory and lifecycle management, applet isolation, and the platform's own security mechanisms. Composite evaluation is only efficient if the platform correctly honors the guidance attached to the IC certificate, which is where these campaigns most often lose time.

The ICC evaluation covers the complete product: the platform and all applications on it, as it will actually be issued. It reuses the chip evaluation and, where one exists, the platform evaluation. This is the level the payment schemes care about for an issued product, and EMVCo's recognised laboratory list shows Keysight in scope to conduct it.

Certification covers the scope EMVCo defines. Some vendors also want a view of product security risks outside that scope, and we offer evaluation work for that separately. It looks at where attack potential and field threats are developing rather than only at where the current requirements sit, which some teams find useful for roadmap planning on products with long field lifetimes.

Working with Keysight

Focus on advancing your product while Keysight guides you through EMVCo preparation and evaluation.

engineer with magnifying glass

One Lab for Every Level

EMVCo recognizes us at all three hardware levels, covering the chip, the platform, and the finished card, as well as software-based mobile payment. One laboratory can therefore evaluate your current product, the next one on your roadmap, and the mobile solution alongside it.

engineer at a computer

Arrive at Evaluation Ready

Most delays in EMVCo campaigns trace back to incomplete design documentation, or to composite guidance that the platform does not fully implement. Our pre-evaluation surfaces those gaps early, while your team can still address them as design changes.

three engineers examining graphs

Reuse the Evidence

We plan your EMVCo work alongside the other schemes on your roadmap, including Common Criteria and the payment programs. One campaign then covers several components and product variants, and each new derivative costs less to certify than the last.

Learn Resources

Featured Blogs

Our experts regularly share practical insights in our blog. Explore the latest developments in device security.

Frequently Asked Questions