EMV Co
What is EMVCo?
EMVCo is the technical body that writes and maintains the EMV specifications, the standards that let chip cards, payment terminals and online checkouts work together securely across borders. It's collectively owned by six : American Express, Discover, JCB, Mastercard, UnionPay and Visa.
The name comes from Europay, Mastercard and Visa, the three companies that formed the organization in 1999, and it's still often written EMV Co. Europay was later absorbed into Mastercard and the ownership group widened, so EMV now names the specifications themselves rather than the original trio. EMVCo publishes those specifications and runs the testing programs that certify products against them, but it doesn't police who follows them.
Key facts
- Formed: 1999, by Europay International, Mastercard and Visa
- Owned by: American Express, Discover, JCB, Mastercard, UnionPay and Visa, collectively
- Also written: EMV Co, EMVCo LLC
- Governance: a Board of Managers with two representatives from each member network, supported by EMVCo Associates from across the industry who feed into the working groups
- What it doesn't do: EMVCo doesn't mandate or enforce EMV compliance. Each network sets its own implementation rules and liability terms for its , and merchants
Types
EMV started as a contact chip specification and now covers several technology families, each with its own specification set and testing program:
- Contact chip – the original chip-and-PIN interface used in
- Contactless – tap-to-pay at the terminal, the layer underneath and mobile wallets
- Payment tokenization – replacing the card number with a network token, the framework behind schemes like
- 3-D Secure – the messaging protocol behind authentication in
- Secure Remote Commerce – a shared click-to-pay checkout across participating networks
- QR Code – merchant-presented and consumer-presented QR payment formats
Why it matters
EMVCo is why a card issued in Brazil works at a terminal in Poland, and why a 3DS request built by one gateway is readable by any issuer's access control server. One specification per technology means acquirers, terminal vendors and processors build against a single target instead of a separate one per network.
The chip specification also changed how card is committed and who absorbs it. A chip generates a unique cryptogram for every transaction, so data copied from one payment won't authorize the next one. Counterfeit fraud moved toward remote channels in response, and the networks answered with rules that assign liability to whichever party skipped the stronger authentication method.
How it compares
Three bodies get mixed up because all three publish payments rules, and each covers a different layer.
| Body | Covers | Enforces? |
| EMVCo | EMV specifications and type approval for chip, contactless, and 3DS | No, it publishes and certifies only |
| PCI Security Standards Council | Cardholder data security standards, including | No, the networks enforce through acquirers |
| Card networks | Operating rules, fees, liability terms and monitoring programs | Yes, through acquirer contracts |


