Payments Engineering · Certification
EMV Level 2 Certification, Explained
Every chip-card transaction you have ever tapped or inserted passed through a piece of software you never see: the EMV kernel. Level 2 certification is what proves that kernel works correctly before a terminal ever touches a live card.
It sits in the middle of a three-stage framework, and understanding where it fits is the fastest way to make sense of the entire certification landscape. So let's place it, explain exactly what it validates, and then get to where the real project work lives.
The three levels, briefly
EMV certification validates a payment terminal from the silicon up, in three stages that build on each other.
Certifies the physical chip-card reader and its electrical interface. It governs how the card and terminal physically communicate, and is normally handled by the terminal manufacturer before the device ever ships.
Certifies the EMV kernel, the embedded software that actually talks to the chip on the card. It validates correct reading of application data, cardholder verification, risk management, and cryptogram generation.
Certifies the complete payment application and its end-to-end integration with each specific processor and card brand. This is the stage that gets a terminal approved for live traffic on an acquirer network.
What Level 2 actually validates
The EMV kernel is the brain of the chip transaction. When a card is inserted or tapped, the kernel selects the payment application, exchanges data with the chip, decides how the cardholder should be verified, applies the terminal and issuer risk rules, and requests the cryptogram that either approves the transaction offline or routes it to the issuer.
Level 2 certification, administered under EMVCo, confirms that this kernel behaves exactly as the specifications require across a large battery of test cases. The testing walks the full transaction lifecycle:
- Application selection and data authentication
- Processing restrictions and cardholder verification method handling
- Terminal risk management and action analysis
- The GENERATE AC command that produces the transaction cryptogram
A kernel that passes has demonstrated it will interoperate correctly with cards issued anywhere in the world. And here is the practical part: like Level 1, Level 2 is usually pre-certified at the hardware layer before the device reaches you. When you buy a certified PAX, Ingenico, Clover, or ID TECH terminal, the L1 and L2 approvals typically already exist. That is by design. It lets solution builders spend their certification effort where the real integration work lives.
Where the real work begins: Level 3
Here is the distinction that trips up most teams. Levels 1 and 2 certify the device. Level 3 certifies your solution. You can own perfectly good L2-certified hardware and still be unable to process a single chip transaction, because Level 3 is what validates your complete payment application against a specific processor and card brand. Without it, the terminal cannot process chip transactions through an acquirer network. Full stop.
Level 3 is also processor-specific. Certifying against TSYS does nothing for your Worldpay integration. Each processor and each card brand carries its own test suite and approval flow, which is exactly why L3 is where projects stall, budgets balloon, and roadmaps slip.
That is the layer Mojave, now Paying.co, was built to own.
Paying.co's certification expertise
We run the full EMV Level 3 lifecycle in-house, and we have done it 132 times across five regions. The same engineers who carried those projects across the finish line are the ones who run yours.
That footprint matters more than the number alone. EMV Level 3 is not the same job in every country. Card scheme requirements, regional debit networks like Interac in Canada, the language of the processor's test plan, and which test tools the local certification body will accept all vary by market. We have shipped real cutovers in every region we serve, which is why we can certify against regional schemes most US shops will not touch.
Three services carry that expertise, depending on how much you want to hand off.
EMV Level 3 Certification
The complete lifecycle, run for you: scoping, application build, full FIME, MV, and ICC test suites on tooling we own outright, and card brand submission through final acquirer sign-off. Because we own our test tools rather than renting shared lab time, we compress the industry-standard 18 to 24 month timeline down to roughly 5 to 12 months, on fixed-scope statements of work with milestone billing.
Managed Certification
For teams that want the certification without giving up their codebase. We run the entire L3 process against your specifications and interfaces, on our own PCI DSS-compliant infrastructure, and hand back a certified result. Your IP and architecture stay entirely yours.
MPoC Certification Program
Takes tap-to-phone solutions through PCI MPoC, the toughest security spec PCI has issued, covering all 192 requirements across five domains with accredited labs and the mandatory annual pen test handled end to end. We deliver in 90 days, backed by a written guarantee: if we miss the date on our side, we keep working at no additional cost until you are on the PCI approved list.
The takeaway
Level 2 certification proves the kernel inside your terminal speaks EMV correctly, and for most solution builders it is already handled by the hardware you buy. The work that determines whether your product actually ships, and when, lives at Level 3. That is the layer where a certification partner earns their keep, and it is the layer where 132 completed certifications across five regions turns a process that wrecks roadmaps into infrastructure that runs quietly in the background.
Have a processor, a terminal, and a region in mind?
Tell us what you are certifying. We will come back with a fixed scope and a realistic timeline, and you will hear back from a payments engineer, not a sales rep.
Book time with our team →