Bringing a payment product to market means proving it behaves correctly and securely at every layer from the physical device, through the payment application, and all the way to a live, brand-approved transaction with the acquirer and card schemes. Certification testing is how that proof is established and formally recognised by EMVCo, the payment brands and the acquiring community.
Certification is rarely a single hurdle. It is a sequence of dependent stages, each with its own specifications, tooling and approval bodies and a delay at any one of them pushes back everything downstream. Verinite helps you navigate the full journey: planning the right tests, running them efficiently, resolving issues early, and getting you to approval without avoidable re-tests.
One partner, end to end. We cover card-present and card-not-present acceptance, the banking host side, and the security and tokenization layers that underpin them — across retail, fuel, e-commerce, direct marketing and banking.
A summary of the areas we cover. Each is described in detail in the sections that follow.
| Service | What it covers |
|---|---|
| EMV Level 1 — Device certification | Physical and electrical conformance of the payment device interface (contact and contactless). |
| EMV Level 2 — Kernel certification | Conformance of the payment application (the EMV kernel) to the EMV specifications. |
| EMV Level 3 — End-to-end certification | Integration of an approved device with a live acquirer host and the card brands. |
| Scheme & brand certification | Brand-specific approvals across the global networks, fleet/fuel cards and regional debit. |
| Payment gateway certification | Gateway-to-acquirer/scheme integration and full transaction processing. |
| Tokenization certification | Secure token generation, provisioning and lifecycle for network and merchant tokenization. |
| Digital wallet acceptance | Contactless, NFC and tokenised acceptance for Apple Pay, Google Pay and Samsung Pay. |
| PCI & security | Device and data-security programmes (PTS, PIN, P2PE, DSS) as applicable. |
EMV certification is organised into three levels, each testing a different layer of the solution. They build on one another: a device must pass the lower levels before it can be validated at the next. In EMVCo terms, Level 1 is device certification and Level 2 is kernel certification; together they form a Terminal Type Approval, which Level 3 then exercises end to end.
Level 1 proves the interface between the card or contactless device and the terminal — the hardware and transport layer, independent of the payment application. This is what is often referred to as device certification.
Because Level 1 sits at the hardware layer, defects found here are the most expensive to fix late in a programme — which is why early, well-planned testing matters most at this stage. Device certification is often paired with PCI PTS security evaluation for the same hardware.
Level 2 tests the payment application — the EMV kernel — for correct processing of contact and contactless transactions against the EMV specifications. This is what is often referred to as kernel certification.
An approved Level 1 device component and an approved Level 2 kernel are combined into an approved terminal configuration. This EMVCo Type Approval is what allows a device to be recognised as EMV-compliant before it is deployed into any specific acquiring environment. It is the foundation every later stage depends on.
Level 3 takes an already-approved (Level 1 + Level 2) terminal and validates it in a real acquiring context — integrated with a specific acquirer or processor host and exercised end to end. It is also known as end-to-end testing, acquirer certification or host certification.
Level 3 is the stage most projects underestimate. A device can hold every EMVCo approval and still fail here because of integration specifics — which is exactly where experienced end-to-end support pays for itself.
On top of EMV, each card brand runs its own certification, with its own test tools, scripts and approval process. Supporting a device across multiple brands means managing several parallel programmes — and breadth of coverage is often what sets a capable partner apart. We manage these alongside your EMV and gateway work so requirements are met once, efficiently, rather than discovered one brand at a time.
A payment gateway sits between the merchant’s POS or e-commerce environment and the acquirer, processor and card schemes, routing and translating transaction messages. Before a gateway can process live transactions, its integration must be certified with the acquirer or processor and, where required, the schemes. We plan and run that certification and take you through to sign-off.
What we validate:
Outcome: acquirer / scheme sign-off that clears the gateway to process live transactions in the certified configuration.
Tokenization replaces sensitive card data (the PAN) with a non-sensitive token, reducing risk and cutting the scope of PCI compliance. Certification requirements depend on the tokenization model in use, and we support both.
Tokens issued through the card schemes’ Token Service Providers under the EMVCo Payment Tokenisation framework — for example the Visa Token Service (VTS), Mastercard Digital Enablement Service (MDES) and American Express tokenization. This model underpins digital wallets and secure card-on-file.
Tokens used to protect stored card data in a merchant or gateway environment, primarily to reduce PCI DSS scope and secure card-on-file transactions.
We validate tokenised, NFC-based mobile wallet transactions across the major providers — Apple Pay, Google Pay and Samsung Pay — confirming that contactless and tokenised acceptance works correctly alongside contact and dip transactions. This ties directly to the contactless kernel (Level 2) and network tokenization work above.
Modern acceptance solutions rarely stop at EMV. Clients increasingly want a single partner across the wider compliance landscape.
Our certification services span every acceptance channel and the banking host side.
Retail POS terminals:Verifone, Ingenico, PAX and Nexgo.
Automated Fuel Dispensers (AFD): Verinite provides certification testing services for AFD payment solutions, including host certification, scheme certification, , EMV Level 3, and end-to-end transaction validation.
End-to-end (Level 3) and payment gateway certification are performed against live acquirer and processor hosts. We certify your solution against the host you will actually deploy on, so approval reflects your production environment.
Processors we work with: Fiserv and TSYS [add any other acquirers and processors you support].
We run certification using industry-standard, brand-recognised test tools and simulators — the same platforms accepted across the payments industry — so results are reliable and submissions are accepted first time.
A structured process keeps certification predictable and removes surprises.
[Replace these with your genuine, verifiable differentiators.]
What is the difference between device and kernel certification?
Device certification is EMV Level 1 — the physical and electrical interface. Kernel certification is EMV Level 2 — the payment application. Both are required, and together they form a Terminal Type Approval.
Do I need Level 3 if I already have EMVCo approval?
Yes. EMVCo approval (Levels 1 and 2) proves the device itself is compliant, but Level 3 validates it end to end with your specific acquirer or processor host before it can go live.
Is payment gateway certification the same as EMV Level 3?
They overlap but are not identical. Both involve host integration; gateway certification focuses on the gateway’s connection to the acquirer/processor and schemes across the full transaction set, including card-not-present flows.
When do I need tokenization certification?
When you issue, provision or process network tokens (for wallets or card-on-file), or when you implement merchant/gateway tokenization to reduce PCI scope.
Ready to certify with confidence? Talk to our team about EMV, scheme, gateway and tokenization certification for your retail, fuel, e-commerce, direct marketing and banking solutions.
Contact: Verinite