Certification Testing Services

Ready-to-adapt copy covering EMV, scheme, payment gateway and tokenization certification across every payment channel and sector. Sections are written so they can be lifted onto individual web pages or combined into a single services page.

OVERVIEW

Bringing a payment product to market means proving it behaves correctly and securely at every layer from the physical device, through the payment application, and all the way to a live, brand-approved transaction with the acquirer and card schemes. Certification testing is how that proof is established and formally recognised by EMVCo, the payment brands and the acquiring community.

Certification is rarely a single hurdle. It is a sequence of dependent stages, each with its own specifications, tooling and approval bodies and a delay at any one of them pushes back everything downstream. Verinite helps you navigate the full journey: planning the right tests, running them efficiently, resolving issues early, and getting you to approval without avoidable re-tests.

One partner, end to end. We cover card-present and card-not-present acceptance, the banking host side, and the security and tokenization layers that underpin them — across retail, fuel, e-commerce, direct marketing and banking.

Our certification services at a glance

A summary of the areas we cover. Each is described in detail in the sections that follow.

Service What it covers
EMV Level 1 — Device certification Physical and electrical conformance of the payment device interface (contact and contactless).
EMV Level 2 — Kernel certification Conformance of the payment application (the EMV kernel) to the EMV specifications.
EMV Level 3 — End-to-end certification Integration of an approved device with a live acquirer host and the card brands.
Scheme & brand certification Brand-specific approvals across the global networks, fleet/fuel cards and regional debit.
Payment gateway certification Gateway-to-acquirer/scheme integration and full transaction processing.
Tokenization certification Secure token generation, provisioning and lifecycle for network and merchant tokenization.
Digital wallet acceptance Contactless, NFC and tokenised acceptance for Apple Pay, Google Pay and Samsung Pay.
PCI & security Device and data-security programmes (PTS, PIN, P2PE, DSS) as applicable.

EMV certification

EMV certification is organised into three levels, each testing a different layer of the solution. They build on one another: a device must pass the lower levels before it can be validated at the next. In EMVCo terms, Level 1 is device certification and Level 2 is kernel certification; together they form a Terminal Type Approval, which Level 3 then exercises end to end.

EMV Level 1 — Device certification (physical & electrical)

Level 1 proves the interface between the card or contactless device and the terminal — the hardware and transport layer, independent of the payment application. This is what is often referred to as device certification.

  • Contact interface: Electromechanical characteristics, electrical signalling and transmission protocols (T=0 / T=1) per ISO/IEC 7816.
  • Contactless interface: Analogue and digital testing against ISO/IEC 14443 and the EMVCo contactless communication protocol.
  • Analogue performance: RF field strength, waveform and load-modulation behaviour across the operating volume.
  • Approval outcome: Results submitted to EMVCo, which issues a Letter of Approval for the Level 1 component.

Because Level 1 sits at the hardware layer, defects found here are the most expensive to fix late in a programme — which is why early, well-planned testing matters most at this stage. Device certification is often paired with PCI PTS security evaluation for the same hardware.

EMV Level 2 — Kernel certification (application)

Level 2 tests the payment application — the EMV kernel — for correct processing of contact and contactless transactions against the EMV specifications. This is what is often referred to as kernel certification.

  • Kernel coverage: The contact kernel plus the scheme-aligned contactless kernels defined by EMVCo.
  • Transaction flow: Data handling, terminal risk management and transaction decisioning under the specification.
  • Cryptographic processing: Correct handling of authentication, verification and secure messaging.
  • Approval outcome: A separate EMVCo Letter of Approval for the kernel / application component.

Terminal Type Approval

An approved Level 1 device component and an approved Level 2 kernel are combined into an approved terminal configuration. This EMVCo Type Approval is what allows a device to be recognised as EMV-compliant before it is deployed into any specific acquiring environment. It is the foundation every later stage depends on.

EMV Level 3 — End-to-end & acquirer certification

Level 3 takes an already-approved (Level 1 + Level 2) terminal and validates it in a real acquiring context — integrated with a specific acquirer or processor host and exercised end to end. It is also known as end-to-end testing, acquirer certification or host certification.

  • Host integration: Terminal-to-acquirer/processor host messaging validated for the production configuration.
  • Scheme test scripts: Brand-supplied scripts and simulators exercise the full range of transaction scenarios.
  • Full chain: Transactions run terminal → acquirer host → scheme, confirming true end-to-end behaviour.
  • Processor coverage: Certified against your live acquirer/processor host, including major processors such as Fiserv and TSYS.

Level 3 is the stage most projects underestimate. A device can hold every EMVCo approval and still fail here because of integration specifics — which is exactly where experienced end-to-end support pays for itself.

Scheme & brand certifications

On top of EMV, each card brand runs its own certification, with its own test tools, scripts and approval process. Supporting a device across multiple brands means managing several parallel programmes — and breadth of coverage is often what sets a capable partner apart. We manage these alongside your EMV and gateway work so requirements are met once, efficiently, rather than discovered one brand at a time.

  • Global card networks: Visa, Mastercard, American Express, Discover, Diners Club, JCB and UnionPay.
  • Fleet & fuel cards: WEX and Voyager — purpose-built acceptance for the forecourt.
  • Regional & domestic debit: Interac

Payment gateway certification

A payment gateway sits between the merchant’s POS or e-commerce environment and the acquirer, processor and card schemes, routing and translating transaction messages. Before a gateway can process live transactions, its integration must be certified with the acquirer or processor and, where required, the schemes. We plan and run that certification and take you through to sign-off.

What we validate:

  • Host connectivity: Connectivity and message formatting to the acquirer/processor host — including major processors such as Fiserv and TSYS — using ISO 8583 or the processor’s API specification.
  • Transaction set: Authorisation, capture, refund, reversal/void, and settlement / batch processing.
  • Channel coverage: Both card-present and card-not-present message flows and data elements.
  • Authentication: EMV 3-D Secure (EMV 3DS) integration for e-commerce cardholder authentication.
  • Tokenization & security: Correct handling of tokens and sensitive data through the gateway.
  • Error & edge cases: Timeouts, declines, partial approvals, reversals and other exception paths.
  • Reconciliation: Accurate clearing, settlement and reconciliation against the host.

Outcome: acquirer / scheme sign-off that clears the gateway to process live transactions in the certified configuration.

Tokenization certification

Tokenization replaces sensitive card data (the PAN) with a non-sensitive token, reducing risk and cutting the scope of PCI compliance. Certification requirements depend on the tokenization model in use, and we support both.

Network / payment tokenization

Tokens issued through the card schemes’ Token Service Providers under the EMVCo Payment Tokenisation framework — for example the Visa Token Service (VTS), Mastercard Digital Enablement Service (MDES) and American Express tokenization. This model underpins digital wallets and secure card-on-file.

  • Token provisioning, cryptogram generation and validation.
  • Domain restriction controls that bind a token to a specific use.
  • Lifecycle events — suspend, resume, update and delete.
  • Conformance to EMVCo and individual scheme tokenization requirements.

Acquirer / gateway (merchant) tokenization

Tokens used to protect stored card data in a merchant or gateway environment, primarily to reduce PCI DSS scope and secure card-on-file transactions.

  • Correct token generation and secure mapping to the underlying card data.
  • De-tokenization controls and access restrictions.
  • Behaviour of tokens through the authorisation and settlement flow.

Digital wallet acceptance

We validate tokenised, NFC-based mobile wallet transactions across the major providers — Apple Pay, Google Pay and Samsung Pay — confirming that contactless and tokenised acceptance works correctly alongside contact and dip transactions. This ties directly to the contactless kernel (Level 2) and network tokenization work above.

Related certifications

Modern acceptance solutions rarely stop at EMV. Clients increasingly want a single partner across the wider compliance landscape.

  • PCI programmes: PTS (device security), PIN (secure PIN management), P2PE (validated point-to-point encryption) and DSS (data security) — as applicable to your product.
  • SoftPOS / PIN-on-COTS: software-based acceptance on commercial off-the-shelf devices under the MPoC framework (which consolidates the earlier CPoC
  • Contactless, mobile & tokenisation: NFC acceptance, mobile wallet support and tokenised transaction handling.

Sectors we serve

Our certification services span every acceptance channel and the banking host side.

  • Retail: In-store card-present acceptance across attended and unattended POS. (EMV Level 1 / 2 / 3.)
  • Fuel & forecourt: Automated fuel dispensers (AFD) and outdoor payment terminals, with their own cardholder-activated (CAT / OPT) requirements. (Including WEX and Voyager fleet cards.)
  • E-commerce: Online, card-not-present payments and authentication. (EMV 3DS, gateway and tokenization.)
  • Direct marketing: Mail order and telephone order (MOTO) card-not-present flows.
  • Banking: Issuer, acquirer and ATM host certification and card-level testing.

Devices & platforms we support

Retail POS terminals:Verifone, Ingenico, PAX and Nexgo.

Automated Fuel Dispensers (AFD): Verinite provides certification testing services for AFD payment solutions, including host certification, scheme certification, , EMV Level 3, and end-to-end transaction validation.

Acquirers & processors

End-to-end (Level 3) and payment gateway certification are performed against live acquirer and processor hosts. We certify your solution against the host you will actually deploy on, so approval reflects your production environment.

Processors we work with: Fiserv and TSYS [add any other acquirers and processors you support].

Test tools & platforms

We run certification using industry-standard, brand-recognised test tools and simulators — the same platforms accepted across the payments industry — so results are reliable and submissions are accepted first time.

  • ICC Solutions: EMV Level 2 and Level 3 / end-to-end test tools and simulators.
  • Collis: Brand and contactless test tooling (part of UL Solutions).
  • FIME: EMV, contactless and mobile test tools and certification platforms.

How we work

A structured process keeps certification predictable and removes surprises.

  1. Assess: We review your product, target markets, and the channels, schemes and standards in scope.
  2. Plan: We map the full set of required certifications and sequence them to protect your timeline.
  3. Execute: We run the testing across the relevant levels, brands, gateway and tokenization requirements.
  4. Remediate: Issues are identified early and resolved before formal submission, minimising costly re-tests.
  5. Certify: We manage submissions to EMVCo, the schemes and other bodies through to formal approval.
  6. Ongoing support: Delta testing for product changes, specification updates and renewals.

Why partner with us

[Replace these with your genuine, verifiable differentiators.]

  • Full-stack coverage: EMV Levels 1–3, scheme certification, payment gateway, tokenization and wallet acceptance under one roof.
  • Retail & fuel expertise: Countertop POS and AFD / forecourt environments, including fleet card acceptance.
  • Broad brand reach: Global networks, regional debit and the major digital wallets in a single programme.
  • Speed to approval: Early issue detection and clean submissions that reduce costly re-tests and delays.
  • Recognised tooling & processors: Certification run on the industry-standard ICC Solutions, Collis and FIME platforms, against major processor hosts including Fiserv and TSYS.
  • Credentials: [Accreditations, recognitions, years in operation, devices certified, regions covered].

Frequently asked questions

What is the difference between device and kernel certification?

Device certification is EMV Level 1 — the physical and electrical interface. Kernel certification is EMV Level 2 — the payment application. Both are required, and together they form a Terminal Type Approval.

Do I need Level 3 if I already have EMVCo approval?

Yes. EMVCo approval (Levels 1 and 2) proves the device itself is compliant, but Level 3 validates it end to end with your specific acquirer or processor host before it can go live.

Is payment gateway certification the same as EMV Level 3?

They overlap but are not identical. Both involve host integration; gateway certification focuses on the gateway’s connection to the acquirer/processor and schemes across the full transaction set, including card-not-present flows.

When do I need tokenization certification?

When you issue, provision or process network tokens (for wallets or card-on-file), or when you implement merchant/gateway tokenization to reduce PCI scope.

Get in touch

Ready to certify with confidence? Talk to our team about EMV, scheme, gateway and tokenization certification for your retail, fuel, e-commerce, direct marketing and banking solutions.

Contact: Verinite

Your journey Starts Here!

We promise you something extra
Contact Us