Contactless EMV
Contactless EMV is a way to pay by tapping or hovering an EMV chip card or an NFC-enabled mobile device near a point-of-sale terminal, without inserting the card or making physical contact. It uses the same chip-based technology as inserted EMV transactions but communicates wirelessly over a short distance. It is intended to make in-person payments faster while retaining chip-based security features.
Contactless EMV refers to EMV chip transactions conducted over a near field communication (NFC) interface between a contactless-capable payment device (a dual-interface chip card or an NFC-enabled mobile device) and a point-of-sale terminal, without physical insertion of the card. Transaction processing on the terminal side is handled by an EMV contactless kernel, the software controlling the terminal's contactless operating functions per EMVCo specifications. Contactless EMV is a card-present acceptance method and is distinct from card-not-present flows and from separate authentication standards such as 3-D Secure; its role in fraud liability and its interaction with cardholder data and sensitive authentication data handling depend on card brand rules and PCI DSS controls that apply to the broader acceptance environment, which practitioners should confirm against current published standards and network rules.
Why it matters
Contactless EMV extends the chip-based security model of inserted EMV transactions to a tap-based interface, which matters because it changes how in-person payments are accepted without moving those transactions into card-not-present flows. It remains a card-present acceptance method, using the same underlying EMV chip technology while communicating over near field communication (NFC). Understanding this distinction is important for risk and compliance teams, because the fraud liability, cardholder data handling, and applicable controls follow card-present rules and the broader acceptance environment rather than card-not-present assumptions.
Because contactless EMV supports both dual-interface chip cards and NFC-enabled mobile devices, it broadens the range of payment devices a merchant must support and account for in scope assessments. The role of contactless EMV in fraud liability depends on card brand and network rules, which vary by region and change over time, so practitioners should not assume a fixed liability outcome from the acceptance method alone. Its interaction with cardholder data and sensitive authentication data handling is governed by the PCI DSS controls that apply to the surrounding environment, which should be confirmed against the current published standard.
Contactless EMV is intended to make in-person payments faster while retaining chip-based security features, but it is not a standalone fraud control and should not be confused with separate authentication standards such as 3-D Secure, which addresses card-not-present risk. Teams evaluating contactless acceptance should treat it as one component of a card-present acceptance model rather than a control that eliminates fraud on its own.
Who it's relevant to
Inside Contactless EMV
Common questions
Answers to the questions practitioners most commonly ask about Contactless EMV.