Testing Services
Industry
EU CRAFDA & MDRPayment & FinanceNewsAbout Us
EN繁中
Contact Us
EMVCo · PCI SSC · Payment Security

PAYMENT SECURITY TESTING

From hardware terminal to software checkout — tested and certified in one lab.

What we test & certify

The full payment stack, one accredited lab.

Terminals, kernels, online transactions and phone-as-terminal software — across the EMVCo and PCI SSC programs that apply.

Terminal & kernel certification

EMVCo Level 1–3

Contact and contactless: hardware (L1), kernel software (L2), brand-network integration (L3).

Contact · ContactlessKernelsBrand networks
See what each level tests →
Payment environment assessment

PCI DSS & 3DS

QSA-led DSS assessments and 3-D Secure transaction testing in one engagement.

DSS v4.03DSROC · AOC
Physical terminal security

PCI PTS

Tamper-resistance and firmware testing for card terminals and point-of-interaction devices.

Tamper resistanceFirmware
PIN transaction protection

PIN Security

Logical assessment of PIN-entry devices, PIN management and key handling.

PEDKey management
Phone as terminal

PCI MPoC

Software security testing for COTS smartphones used as payment terminals.

COTSSoftPOS
Continuous compliance

PCI ASV Scanning

Quarterly external vulnerability scanning by an Approved Scanning Vendor, reports included.

QuarterlyExternal scan
Terminals contain digital elements, so the EU Cyber Resilience Act applies too — your PTS / MPoC evidence is the head start. See the CRA pathway →
Category 01 · In depth

EMVCo Level 1–3 — from silicon to network.

Three approvals, in order. A terminal cannot skip one.

The same three-level ladder, before any terminal can process a transaction
Select a level
Why this lab

Why Manufacturers Choose SVS Lab

Who requires this, and why it stalls
EMVCo · the card brands

No approval, no acceptance

Hardware, kernel and network integration each need a separate approval — and the submissions queue.

PCI SSC · acquirers

The assessment your acquirer asks for

DSS, PIN Security, 3DS and quarterly ASV scans are contractual conditions of processing, renewed every year.

EU · from December 2027

And now CRA conformity too

A terminal is a product with digital elements, so EU market access adds a CRA file.

Four bodies, one device. Run them through one lab — one evidence set, packaged for each program.

Why manufacturers choose SVS Lab
Accreditation

PCI SSC-accredited QSA & ASV — DSS assessments and quarterly scans in-house, in an ISO/IEC 17025-accredited Taipei lab.

Alliance partner

EMVCo and PCI capacity through Applus+ Laboratories, including its EMVCo-recognised labs and EU Notified Bodies NB 3121 and NB 2764.

Local track record

Taiwan’s payment-security leader — 300+ enterprises certified annually, 70% domestic market share.

Next step

Not sure where to start? Join a training session.

Taught by EU-certified experts who review real submissions every week. Our EU CRA, MDR and ISO 13485 courses drill the same evidence discipline payment schemes demand.

FAQ

Common Questions

Where should I start with certification?

Start with a scoping consultation. Depending on which layer your product sits in — hardware, firmware, software, or system — we help you plan the right combination of certifications.

How long does certification typically take?

It varies by product type and certification level. Engaging the lab early in development helps shorten time to market — the gap analysis finds the failures before the formal assessment clock starts.

Can I get PCI DSS / 3DS / PIN Security / ASV done here too?

Yes — all four. As a PCI SSC-accredited QSA and ASV, we run QSA-led DSS assessments, 3DS testing, PIN Security assessment and ASV scanning, so hardware, firmware, software and process stay with one provider.

What is SVS Lab's relationship with Applus+ Laboratories?

SVS Lab is an Applus+ Laboratories Alliance Partner and Recognized Laboratory. One engagement covers the stack; your PTS and MPoC evidence carries into DSS scope.