Software-based mobile payment removes the hardware secure element from the equation and asks software to protect the same assets. The application runs on a consumer device that the vendor does not control, alongside untrusted apps, on an operating system that may be rooted or jailbroken. EMVCo introduced its SBMP Security Evaluation Process in 2018 to give the industry one consistent way to assess that layered defense. The process uses a component and integration model, so a trusted execution environment, a biometric authenticator, a software protection tool, or a payment SDK can each be evaluated on its own, and those results can then support the evaluation of the complete solution built from them.

Keysight is a recognized EMVCo security evaluation laboratory, with a recognized scope of Full SBMP alongside IC, Platform, and ICC. Our evaluators review your documentation and source code, run vulnerability analysis, and test your product using the techniques a real adversary applies. We then deliver the evaluation report EMVCo needs to issue your certificate.

emvco logo
Your Path to EMVCo SBMP Certification
red icon with a grid

Scoping

We establish what you are certifying and how it will be evaluated. You may evaluate a single component, evaluate several and integrate the results, or take a complete solution through as one product. That decision shapes cost, timelines, and how much of the work you can reuse later, which is why we settle it first.

red icon with a folder

Registration and Agreements

You register as an EMVCo Vendor, then sign a Security Evaluation Agreement with EMVCo's Security Evaluation Working Group. Next, you submit the SBMP registration questionnaire and pay the EMVCo invoice. We can advise on the scoping choices that the questionnaire locks in.

red icon with a magnifying glass

Documentation and Code Review

SBMP evaluation is a white-box exercise. Our evaluators review your design documentation and your source code to understand how the product protects keys, code, and data at rest, in use, and in transit. Teams frequently underestimate this stage, because a mobile product's real security posture depends heavily on implementation detail that documentation alone does not reveal.

red icon with a masked figure

Vulnerability Analysis and Testing

We build a structured analysis of where the product is attackable, then test it. The campaign covers static and dynamic analysis, reverse engineering, hooking and instrumentation, tampering and repackaging, rooted and jailbroken device scenarios, and attacks against cryptographic implementations, including white-box cryptography.

red icon with a certificate

Reporting and Certification

We produce the evaluation report and send it to EMVCo once you have paid the registration invoice. EMVCo reviews the report and issues your Security Evaluation Certificate, published with a SECN. We handle questions raised during the review until the report satisfies the requirements.

red icon with two circular arrows

Maintenance and Reuse

Mobile products ship on a release cadence that certification has to keep up with. We plan for updates, new versions, and additional payment scheme submissions from the start, and we structure component evaluations so their results carry into the solutions built on top of them.

EMVCo SBMP Evaluation Routes

A component evaluation covers one part of the layered defense: a TEE, a CDCVM implementation, an attestation mechanism, a software protection tool, or an SDK. This route suits technology vendors who sell into wallet providers and OEMs rather than to cardholders. Your certificate becomes a commercial asset, because the integrators building on your component can point to it instead of re-proving your security themselves.

A solution evaluation covers the complete mobile payment product as it will reach users. Where the solution incorporates components that already hold certificates, the evaluation draws on those results rather than repeating them. This route suits wallet providers, issuers, and OEMs. The efficiency depends on how well your integration honors the conditions attached to each component certificate, which is the most common source of avoidable work.

An EMVCo SBMP certificate and a payment scheme approval are related but separate. Schemes including Visa, Mastercard, American Express, Discover, JCB, Cartes Bancaires, Bancontact Payconiq, and MIR each maintain their own requirements for software-based mobile payment. We evaluate against EMVCo SBMP requirements and scheme program requirements together, which removes duplicated testing from your schedule.

Certification covers the scope EMVCo defines. Some vendors also want a view of risks outside that scope, such as backend and provisioning security or fraud paths that a certified component does not address, and we offer evaluation work for that separately. It sits alongside certification as an option, and has no bearing on your certificate.


Three Reasons Why Your Payment App Needs to Get EMVCo Certified

Mobile payment applications run in an environment their providers do not control, on consumer devices that may be rooted or compromised, while attackers keep sharpening their tooling. Written with Promon, this article sets out the three reasons providers take their solutions through EMVCo SBMP certification, and why the software protection tool you choose shapes how that process goes.

mobile phone in hands

Working with Keysight

Focus on advancing your product while Keysight guides you through SBMP preparation and evaluation.

mobile phone with floating globe

Evaluate Across the Whole Stack

We evaluate every layer of a software-based mobile payment solution, from software protection tools and TEEs through CDCVM and attestation to the complete wallet. One laboratory can therefore assess your component today and the solution that integrates it tomorrow.

engineer at a computer

Arrive at Evaluation Ready

Most delays in SBMP projects trace back to protection mechanisms that do not hold up under review, or to integration conditions that a component certificate imposed and the solution did not meet. Our training and pre-certification testing surface those gaps while your team can still address them in a normal release cycle.

three engineers examining graphs

Reuse the Evidence

We plan your EMVCo work alongside the payment scheme programs and other schemes on your roadmap. One campaign then covers several components and product versions, and each new submission costs less than the last.

Learn Resources

Frequently Asked Questions