測試服務技術測試諮詢與驗證
Industry
EU CRAFDA & MDR支付與金融新聞關於我們
EN繁中
聯絡我們
EMVCo · PCI SSC · Payment Security

PAYMENT SECURITY TESTING

From hardware terminal to software checkout — tested and certified in one lab.

What we test & certify

The full payment stack, one accredited lab.

Terminals, kernels, online transactions and phone-as-terminal software — across the EMVCo and PCI SSC programs that apply.

Terminal & kernel certification

EMVCo Level 1–3

Contact and contactless: hardware (L1), kernel software (L2), brand-network integration (L3).

Contact · ContactlessKernelsBrand networks
See what each level tests →
Payment environment assessment

PCI DSS & 3DS

QSA-led DSS assessments and 3-D Secure transaction testing in one engagement.

DSS v4.03DSROC · AOC
Physical terminal security

PCI PTS

Tamper-resistance and firmware testing for card terminals and point-of-interaction devices.

Tamper resistanceFirmware
PIN transaction protection

PIN Security

Logical assessment of PIN-entry devices, PIN management and key handling.

PEDKey management
Phone as terminal

PCI MPoC

Software security testing for COTS smartphones used as payment terminals.

COTSSoftPOS
Continuous compliance

PCI ASV Scanning

Quarterly external vulnerability scanning by an Approved Scanning Vendor, reports included.

QuarterlyExternal scan
支付終端含有數位元件,EU Cyber Resilience Act 同樣適用 — 您既有的 PTS / MPoC 證據就是起跑優勢。查看 CRA 途徑 →
Category 01 · In depth

EMVCo Level 1–3 — from silicon to network.

Three approvals, in order. A terminal cannot skip one.

The same three-level ladder, before any terminal can process a transaction
Select a level
為何選擇本實驗室

製造商為何選擇 SVS Lab

Who requires this, and why it stalls
EMVCo · the card brands

No approval, no acceptance

Hardware, kernel and network integration each need a separate approval — and the submissions queue.

PCI SSC · acquirers

The assessment your acquirer asks for

DSS, PIN Security, 3DS and quarterly ASV scans are contractual conditions of processing, renewed every year.

EU · from December 2027

And now CRA conformity too

A terminal is a product with digital elements, so EU market access adds a CRA file.

Four bodies, one device. Run them through one lab — one evidence set, packaged for each program.

Why manufacturers choose SVS Lab
Accreditation

PCI SSC-accredited QSA & ASV — DSS assessments and quarterly scans in-house, in an ISO/IEC 17025-accredited Taipei lab.

Alliance partner

EMVCo and PCI capacity through Applus+ Laboratories, including its EMVCo-recognised labs and EU Notified Bodies NB 3121 and NB 2764.

Local track record

Taiwan’s payment-security leader — 300+ enterprises certified annually, 70% domestic market share.

Next step

不確定從何著手?歡迎參加教育訓練課程。

由每週實際審閱送件案件的歐盟認證專家授課。我們的 EU CRA、MDR 與 ISO 13485 課程,訓練的正是支付驗證方案所要求的同一套證據紀律。

FAQ

常見問題

驗證應該從哪裡開始?

建議先從範圍界定諮詢開始。依據您的產品所處的層級 — 硬體、韌體、軟體或系統 — 我們協助您規劃合適的驗證組合。

驗證通常需要多久時間?

時程視產品類型與驗證等級而定。在開發早期即與實驗室合作,有助於縮短上市時程 — 差距分析會在正式審查計時開始前就找出不符合項。

PCI DSS / 3DS / PIN Security / ASV 也能在這裡一併完成嗎?

是的,四項皆可。我們是 PCI SSC 認證的 QSA 與 ASV,可執行 QSA 主導的 DSS 審查、3DS 測試、PIN Security 審查與 ASV 掃描,讓硬體、韌體、軟體與流程都由同一家服務單位負責。

SVS Lab 與 Applus+ Laboratories 的關係為何?

SVS Lab 是 Applus+ Laboratories 的聯盟夥伴與認可實驗室。一次委託即可涵蓋整個技術層級;您的 PTS 與 MPoC 證據可延用至 DSS 範圍。