Skip to main content
Category: Transaction Processing

Contactless EMV

Also known as: EMV Contactless, EMV Contactless Chip, Contactless EMV Payments
Simply put

Contactless EMV is a way to pay by tapping or hovering an EMV chip card or an NFC-enabled mobile device near a point-of-sale terminal, without inserting the card or making physical contact. It uses the same chip-based technology as inserted EMV transactions but communicates wirelessly over a short distance. It is intended to make in-person payments faster while retaining chip-based security features.

Formal definition

Contactless EMV refers to EMV chip transactions conducted over a near field communication (NFC) interface between a contactless-capable payment device (a dual-interface chip card or an NFC-enabled mobile device) and a point-of-sale terminal, without physical insertion of the card. Transaction processing on the terminal side is handled by an EMV contactless kernel, the software controlling the terminal's contactless operating functions per EMVCo specifications. Contactless EMV is a card-present acceptance method and is distinct from card-not-present flows and from separate authentication standards such as 3-D Secure; its role in fraud liability and its interaction with cardholder data and sensitive authentication data handling depend on card brand rules and PCI DSS controls that apply to the broader acceptance environment, which practitioners should confirm against current published standards and network rules.

Why it matters

Contactless EMV extends the chip-based security model of inserted EMV transactions to a tap-based interface, which matters because it changes how in-person payments are accepted without moving those transactions into card-not-present flows. It remains a card-present acceptance method, using the same underlying EMV chip technology while communicating over near field communication (NFC). Understanding this distinction is important for risk and compliance teams, because the fraud liability, cardholder data handling, and applicable controls follow card-present rules and the broader acceptance environment rather than card-not-present assumptions.

Because contactless EMV supports both dual-interface chip cards and NFC-enabled mobile devices, it broadens the range of payment devices a merchant must support and account for in scope assessments. The role of contactless EMV in fraud liability depends on card brand and network rules, which vary by region and change over time, so practitioners should not assume a fixed liability outcome from the acceptance method alone. Its interaction with cardholder data and sensitive authentication data handling is governed by the PCI DSS controls that apply to the surrounding environment, which should be confirmed against the current published standard.

Contactless EMV is intended to make in-person payments faster while retaining chip-based security features, but it is not a standalone fraud control and should not be confused with separate authentication standards such as 3-D Secure, which addresses card-not-present risk. Teams evaluating contactless acceptance should treat it as one component of a card-present acceptance model rather than a control that eliminates fraud on its own.

Who it's relevant to

Merchant Risk and Acceptance Teams
Teams responsible for in-person payment acceptance need to treat contactless EMV as a card-present method distinct from card-not-present flows, and to account for both dual-interface cards and NFC-enabled mobile devices in their acceptance model. The fraud liability associated with contactless transactions depends on card brand and network rules that vary by region and change over time, so these should be confirmed rather than assumed.
Compliance Officers
Compliance staff should recognize that the handling of cardholder data and sensitive authentication data in a contactless EMV environment is governed by the PCI DSS controls that apply to the broader acceptance environment. Requirement wording and numbering differ between PCI DSS versions, so applicable controls should be confirmed against the current published standard rather than assumed from the acceptance method.
Point-of-Sale and Terminal Engineers
Engineers implementing or maintaining contactless-capable terminals work with the EMV contactless kernel, the software that controls the terminal's contactless operating functions per EMVCo specifications. Understanding the kernel's role is relevant when validating that terminals correctly process NFC-based EMV transactions and integrate with the surrounding acceptance environment.
Fraud Analysts
Fraud teams should distinguish contactless EMV, a card-present acceptance method, from card-not-present flows and from separate authentication standards such as 3-D Secure. Contactless EMV retains chip-based security features but is not a standalone fraud control, and its effect on fraud outcomes depends on the broader controls and network rules in place.

Inside Contactless EMV

Contactless interface
The NFC-based communication channel between a chip card or mobile device and a contactless-capable reader, allowing a transaction to be initiated by tapping rather than inserting or swiping. The physical interface differs from contact EMV, though both may rely on EMV chip authentication principles.
EMV chip authentication
Cryptographic processing performed by the chip (or its emulation on a device) that generates a transaction-specific cryptogram. This is intended to help validate that a genuine chip is present and to make card counterfeiting more difficult in card-present scenarios; it does not by itself address card-not-present fraud.
Cardholder data exchanged
Contactless EMV transactions can involve cardholder data such as PAN, expiration date, and service code. This data must be handled under the controls defined by PCI DSS. The applicable cardholder data elements should be confirmed against the current published standard and the specific implementation.
Sensitive authentication data considerations
Elements analogous to track data may be present during a contactless transaction. Sensitive authentication data must not be stored after authorization, even when encrypted. Confirm what data is transmitted and how it is protected in your specific deployment.
Tokenization on mobile devices
Contactless transactions initiated from mobile wallets frequently use device-specific tokens in place of the actual PAN. Tokenization transforms the data differently from encryption, truncation, masking, or hashing, and its effect on PCI DSS scope depends on implementation and validation rather than the label alone.
Reader and acceptance environment
The contactless-capable terminal, its firmware, and its acceptance configuration determine how the contactless EMV transaction is processed. PIN handling, where applicable, may fall under PCI PIN, and point-to-point encryption implementations may fall under PCI P2PE, which are separate from PCI DSS.

Common questions

Answers to the questions practitioners most commonly ask about Contactless EMV.

Is contactless EMV the same as mobile wallet payments like Apple Pay or Google Pay?
Not exactly. Contactless EMV refers to the underlying contactless transaction technology based on EMV specifications, which can be presented by a physical card with a contactless interface or by a device such as a phone. Mobile wallets typically use contactless EMV transaction flows but add their own layers, including device-based tokenization and device authentication. Treating the wallet and the contactless EMV rails as identical can lead you to overlook that the wallet may substitute a token for the PAN and add its own cardholder verification, which affects how the transaction and its data are handled.
Does contactless EMV mean cardholder data is transmitted 'in the clear' over the air because there is no physical contact?
No. The contactless interface being wireless does not by itself imply that data is unprotected. Contactless EMV transactions use EMV cryptographic processes intended to authenticate the transaction and protect certain data elements, similar in purpose to contact chip transactions. However, the specific data elements exchanged, and whether any of them fall under cardholder data or sensitive authentication data handling rules, depend on the implementation. You should not assume the interface medium determines the security posture; confirm what data is present and how it is protected in your specific flow.
How does accepting contactless EMV affect the sensitive authentication data I am allowed to store?
The prohibition on storing sensitive authentication data after authorization applies regardless of whether the transaction is contact chip or contactless EMV. Any equivalent track or chip-derived authentication data captured during the transaction is subject to the same rule that sensitive authentication data must not be retained after authorization, even if encrypted. Review your logs, transaction records, and any diagnostic captures to confirm you are not inadvertently persisting such data from contactless transactions. Confirm the specific requirement wording against the current published PCI DSS.
Does deploying contactless EMV acceptance change my PCI DSS scope?
It can, but the effect depends on implementation and validation rather than on the technology label. Whether contactless acceptance increases, decreases, or leaves your scope unchanged depends on how the terminal handles account data, whether tokenization or point-to-point encryption is applied and validated, and where cardholder data flows within your environment. Assess the actual data flows introduced by contactless acceptance and validate any scope-reducing controls rather than assuming contactless is inherently in or out of scope.
What is the relationship between contactless EMV and cardholder verification methods like PIN or on-device authentication?
Contactless EMV is the transaction technology, while cardholder verification is a separate consideration addressing whether and how the cardholder is verified. A contactless transaction may complete with no cardholder verification, with an on-device verification such as a device passcode or biometric in a wallet scenario, or with other methods depending on card brand and network rules, region, and terminal configuration. Do not assume contactless implies a particular verification method or that any single verification approach eliminates fraud; verification rules vary and are governed by card brand and network requirements.
How should I distinguish contactless EMV from other contactless-related PCI standards when scoping a project?
Contactless EMV describes the transaction technology, but the applicable requirements for your project may draw on separate standards. For example, controls around encryption of account data at the point of interaction may involve PCI P2PE, PIN handling may involve PCI PIN, and 3-D Secure components involve PCI 3DS. Identify which standard governs each control in your implementation rather than assuming PCI DSS alone covers everything, and confirm the applicable requirements against each current published standard.

Common misconceptions

Contactless EMV prevents fraud because the chip authenticates the card.
EMV chip authentication is intended to help reduce card-present counterfeit fraud, but it does not eliminate fraud and does not address card-not-present fraud, account takeover, or synthetic identity fraud. Different risks require different controls, and no single control guarantees fraud prevention.
Because contactless transactions can use tokens, they are automatically out of PCI DSS scope.
Tokenization may reduce scope, but the outcome depends on how tokenization is implemented and validated, not on the presence of a token alone. Cardholder data and any sensitive authentication data present in the environment must still be handled under applicable PCI DSS controls, confirmed against the current standard.
Contactless EMV and 3-D Secure provide the same protection.
These address different points in a transaction. EMV chip authentication applies to card-present acceptance, while 3-D Secure is oriented toward card-not-present transactions and is governed by separate PCI 3DS and card brand requirements. They are complementary, not interchangeable.

Best practices

Confirm exactly which cardholder data elements and any sensitive authentication data are transmitted during your contactless EMV transactions, and verify that sensitive authentication data is never stored after authorization, even in encrypted form.
Validate the PCI DSS scope impact of any tokenization used in contactless or mobile-wallet transactions based on your specific implementation and its validation, rather than assuming scope reduction from the use of tokens.
Identify which PCI standard governs each control in your contactless environment, distinguishing PCI DSS from PCI PIN for PIN handling and PCI P2PE for point-to-point encryption implementations.
Verify PCI DSS requirement wording and numbering against the current published standard for your version, since requirements change between versions and should not be assumed from a fixed number.
Treat EMV chip authentication as one layer that helps reduce card-present counterfeit fraud, and pair it with appropriate controls such as 3-D Secure for card-not-present risk, recognizing each addresses different threats.
Keep reader firmware and acceptance configurations maintained and monitored, and evaluate detection controls with awareness of false-positive and false-negative trade-offs rather than expecting any single control to eliminate fraud.