We establish what you are certifying and how it will be evaluated. You may evaluate a single component, evaluate several and integrate the results, or take a complete solution through as one product. That decision shapes cost, timelines, and how much of the work you can reuse later, which is why we settle it first.
You register as an EMVCo Vendor, then sign a Security Evaluation Agreement with EMVCo's Security Evaluation Working Group. Next, you submit the SBMP registration questionnaire and pay the EMVCo invoice. We can advise on the scoping choices that the questionnaire locks in.
SBMP evaluation is a white-box exercise. Our evaluators review your design documentation and your source code to understand how the product protects keys, code, and data at rest, in use, and in transit. Teams frequently underestimate this stage, because a mobile product's real security posture depends heavily on implementation detail that documentation alone does not reveal.
We build a structured analysis of where the product is attackable, then test it. The campaign covers static and dynamic analysis, reverse engineering, hooking and instrumentation, tampering and repackaging, rooted and jailbroken device scenarios, and attacks against cryptographic implementations, including white-box cryptography.
We produce the evaluation report and send it to EMVCo once you have paid the registration invoice. EMVCo reviews the report and issues your Security Evaluation Certificate, published with a SECN. We handle questions raised during the review until the report satisfies the requirements.
Mobile products ship on a release cadence that certification has to keep up with. We plan for updates, new versions, and additional payment scheme submissions from the start, and we structure component evaluations so their results carry into the solutions built on top of them.
A solution evaluation covers the complete mobile payment product as it will reach users. Where the solution incorporates components that already hold certificates, the evaluation draws on those results rather than repeating them. This route suits wallet providers, issuers, and OEMs. The efficiency depends on how well your integration honors the conditions attached to each component certificate, which is the most common source of avoidable work.
An EMVCo SBMP certificate and a payment scheme approval are related but separate. Schemes including Visa, Mastercard, American Express, Discover, JCB, Cartes Bancaires, Bancontact Payconiq, and MIR each maintain their own requirements for software-based mobile payment. We evaluate against EMVCo SBMP requirements and scheme program requirements together, which removes duplicated testing from your schedule.
Certification covers the scope EMVCo defines. Some vendors also want a view of risks outside that scope, such as backend and provisioning security or fraud paths that a certified component does not address, and we offer evaluation work for that separately. It sits alongside certification as an option, and has no bearing on your certificate.
Mobile payment applications run in an environment their providers do not control, on consumer devices that may be rooted or compromised, while attackers keep sharpening their tooling. Written with Promon, this article sets out the three reasons providers take their solutions through EMVCo SBMP certification, and why the software protection tool you choose shapes how that process goes.
Focus on advancing your product while Keysight guides you through SBMP preparation and evaluation.
We evaluate every layer of a software-based mobile payment solution, from software protection tools and TEEs through CDCVM and attestation to the complete wallet. One laboratory can therefore assess your component today and the solution that integrates it tomorrow.
Most delays in SBMP projects trace back to protection mechanisms that do not hold up under review, or to integration conditions that a component certificate imposed and the solution did not meet. Our training and pre-certification testing surface those gaps while your team can still address them in a normal release cycle.
We plan your EMVCo work alongside the payment scheme programs and other schemes on your roadmap. One campaign then covers several components and product versions, and each new submission costs less than the last.
SBMP is EMVCo's security evaluation process for software-based mobile payment products. EMVCo introduced it in 2018 to give the industry a consistent way to assess mobile payment solutions that protect payment assets in software rather than in a hardware secure element. A recognized laboratory evaluates the product and submits a report, and EMVCo issues a Security Evaluation Certificate.
Components and complete solutions. Components include software development kits, trusted execution environments, consumer device cardholder verification methods such as biometrics and authenticators, attestation mechanisms, and software protection tools. Full mobile payment applications assembled from these parts can also be evaluated.
A component evaluation covers one part of the layered defense on its own. An integration or solution evaluation covers the complete product, drawing on the certificates held by the components inside it. Technology vendors typically pursue the first route, while wallet providers and OEMs typically pursue the second.
The schemes maintain their own approval requirements, and vendors commonly use an EMVCo SBMP certificate to demonstrate security to them. In practice, vendors selling into wallet providers and issuers find that certification is expected commercially, whether or not a specific scheme mandates it in a given market.
You must be registered as an EMVCo Vendor, and you must have signed a Security Evaluation Agreement with EMVCo's Security Evaluation Working Group, which you trigger by contacting the SBMP Security Evaluation Secretariat. You then submit the SBMP registration questionnaire to the Secretariat and pay the invoice EMVCo raises.
Documentation review, source code review, vulnerability analysis, and penetration testing. The testing covers static and dynamic analysis, reverse engineering, hooking and instrumentation, tampering and repackaging, rooted and jailbroken device scenarios, and attacks on cryptographic implementations including white-box cryptography.
White-box implementations are a common protection in mobile payment products and a common source of findings. Our team has published extensively on practical attacks against obfuscated ciphers, and evaluation includes testing whether a white-box implementation resists key extraction rather than only confirming that one is present.
It depends on the scope you choose, the complexity of the product, and the readiness of your documentation and source code. Component evaluations are generally shorter and more predictable than full solution evaluations. Pre-certification testing is the most reliable way to keep the formal campaign on schedule.
There are two separate costs. The evaluation itself is scoped and quoted by the laboratory, and EMVCo charges its own registration fee per submission, covering new products, certificate renewals, and updates.
Yes. Keysight holds EMVCo recognition for IC, Platform, and ICC evaluations as well as SBMP. See our EMVCo smart card certification page.
What are you looking for?