Skip to main content
Category: Transaction Processing

EMV Level 3 Testing

Also known as: EMV L3 Testing, Level 3 Testing, L3 Testing, Level 3 Terminal Integration Testing, EMV L3 Certification
Simply put

EMV Level 3 Testing is a stage of testing that checks whether an EMV chip-card acceptance device, such as a point-of-sale terminal, mPOS, ATM, or tap-to-phone device, works correctly when connected to the wider payment acceptance infrastructure. It is intended to confirm that the terminal and its supporting systems can process chip transactions together as expected. Card networks such as Visa may require this testing as part of bringing a terminal into service.

Formal definition

EMV Level 3 (L3) testing validates the integration of an EMV acceptance device with its acceptance infrastructure to help ensure that chip transactions are processed correctly end to end. EMVCo manages an EMV L3 Testing Framework and the qualification process for related EMV L3 test tools, while individual card networks operate their own L3 testing programs; for example, Visa Global L3 Testing is described as a mandatory phase of terminal testing covering device types including POS, mPOS, ATM, Transit, Tap to Phone, and Fleet. L3 testing is distinct from EMVCo Level 1 (hardware/electromechanical) and Level 2 (kernel software) testing, and adoption of the EMV L3 Testing Framework is undertaken by participant systems within the payments ecosystem. Specific network requirements, mandated status, and covered device categories vary by card brand and region, so practitioners should confirm current requirements against the relevant network's published L3 testing program.

Why it matters

EMV chip acceptance depends on more than a certified terminal in isolation. A device may pass hardware and kernel-level testing yet still fail to process chip transactions correctly once it is connected to the acquirer's systems and the wider acceptance infrastructure. EMV Level 3 testing addresses this integration gap: it is intended to confirm that the terminal and its supporting systems process chip transactions together as expected before the device is brought into service. Without this validation, integration defects can surface only in production, where they may cause declined transactions, incorrect transaction handling, or a degraded acceptance experience.

Because card networks operate their own L3 testing programs, the requirement to complete this testing can be a gating condition for deployment. For example, Visa describes its Visa Global L3 Testing as a mandatory phase of terminal testing covering device types including POS, mPOS, ATM, Transit, Tap to Phone, and Fleet. Practitioners planning terminal rollouts should treat L3 testing as a scheduled milestone rather than an afterthought, since a failed or incomplete L3 phase can delay deployment.

The specific requirements, mandated status, and covered device categories vary by card brand and region, and programs change over time. L3 testing helps reduce integration errors, but it is one stage of a broader qualification process and does not by itself address hardware conformance, kernel behavior, fraud controls, or the security obligations governed by separate standards. Teams should confirm current requirements against the relevant network's published L3 testing program rather than assuming a fixed set of obligations.

Who it's relevant to

Terminal and Device Manufacturers
Vendors building POS, mPOS, ATM, Transit, Tap to Phone, and Fleet devices need to plan for L3 integration testing as part of bringing a product to market. Because L3 validates integration with the acceptance infrastructure rather than device hardware or kernel behavior alone, manufacturers should coordinate with acquirers and networks and confirm which programs and device categories apply.
Acquirers and Payment Processors
Acquirers and processors are central to the acceptance infrastructure that L3 testing exercises, since chip transactions must be processed correctly end to end through their systems. They are often involved in supporting or coordinating a merchant's or vendor's L3 testing and in confirming that network requirements are met before a terminal goes live.
Merchant Deployment and Integration Teams
Teams responsible for deploying chip-card acceptance devices should treat L3 testing as a deployment milestone, since a card network such as Visa may require it before a terminal is brought into service. Confirming current network requirements early helps reduce the risk of rollout delays caused by an incomplete L3 phase.
Payment Testing and Certification Specialists
Practitioners managing EMV qualification need to distinguish L3 integration testing from EMVCo Level 1 and Level 2 testing and to track the EMV L3 Testing Framework alongside individual network programs. They should verify covered device types, mandated status, and procedures against the relevant network's published program, as these vary by brand and region.

Inside EMV L3 Testing

End-to-End Transaction Testing
EMV Level 3 (L3) testing validates the complete payment application and its integration with the acquirer host and payment network, exercising full transaction flows between an EMV-approved terminal (kernel and contact/contactless hardware validated at Levels 1 and 2) and the processing environment.
Relationship to Level 1 and Level 2
Level 1 addresses terminal hardware and interface compliance, and Level 2 addresses the EMV kernel software. Level 3 assumes both are already approved and instead focuses on the end-to-end integration and configuration of the deployed acceptance solution.
Acquirer and Network Test Scripts
Testing is typically driven by test cases or scripts provided by the acquirer or payment network, covering transaction types, card ranges, and configuration parameters specific to the acquiring environment and the card brands supported.
Configuration and Parameter Validation
L3 testing checks that terminal and host configuration values, such as supported application identifiers, transaction types, and processing options, are correctly set for the intended acceptance scenarios.
Certification Outcome
Successful L3 testing supports the acquirer's or network's readiness sign-off for deploying the integrated solution into production, though specific certification requirements and acceptance criteria vary by acquirer, network, and region.

Common questions

Answers to the questions practitioners most commonly ask about EMV L3 Testing.

Does passing EMV Level 3 testing mean my terminal is fully PCI compliant?
No. EMV Level 3 testing validates that an integrated payment application and terminal correctly complete EMV chip transactions end-to-end with a specific acquirer and payment network, using approved kernels and hardware. It addresses transaction interoperability and acceptance, not the broader control set of PCI DSS, which governs how cardholder data is protected across people, processes, and systems. It is also separate from PCI PIN, PCI P2PE, and the PCI Software Security Framework. Level 3 acceptance and PCI compliance are distinct validations, and each must be confirmed independently against its own applicable standard and current requirements.
Does completing EMV Level 3 testing prevent card fraud on my terminal?
No. EMV chip authentication is intended to help reduce counterfeit card-present fraud by making card data harder to clone, and Level 3 testing confirms the transaction flow works correctly. It does not address card-not-present fraud, account takeover, friendly or first-party fraud, or synthetic identity fraud, and it does not by itself determine chargeback liability, which is governed by card brand and network rules that vary by region and change over time. No single control eliminates fraud; Level 3 testing verifies interoperability, not fraud outcomes.
How does EMV Level 3 testing differ from Level 1 and Level 2 testing?
The levels address different layers. Level 1 concerns the physical and electrical characteristics and lower-level protocol between the card and terminal hardware. Level 2 concerns the EMV kernel software that processes the application-level transaction logic. Level 3 validates the integration of an approved terminal and kernel with a specific payment application, acquirer host, and network, confirming the complete transaction flow behaves correctly in the target acceptance environment. Because Level 3 depends on the particular acquirer and network configuration, results are specific to that integration rather than universally portable.
Who typically initiates and coordinates EMV Level 3 testing?
Level 3 testing is generally coordinated between the merchant or solution provider integrating the payment application, the acquirer or processor whose host environment is being tested against, and the applicable payment networks that define the acceptance test scripts. The party responsible for the integration usually drives the effort, but the acquirer and network define the specific test cases and sign-off criteria. Because roles and procedures vary by acquirer and region, confirm the exact process and required test suites with the relevant acquirer and networks before starting.
When during a deployment should EMV Level 3 testing be performed?
Level 3 testing is typically performed before a new integrated payment solution goes live, and again when changes to the payment application, kernel, terminal configuration, acquirer host connection, or supported networks could affect the transaction flow. Because it validates a specific integration, material changes to any element in that chain may warrant re-testing. Confirm the specific triggers and re-certification requirements with your acquirer and the applicable networks, as these vary.
How does EMV Level 3 testing relate to protecting cardholder data during a transaction?
EMV Level 3 testing focuses on correct transaction interoperability and acceptance, not on how cardholder data or sensitive authentication data are protected. Data protection obligations are governed separately, primarily under PCI DSS and related standards. In particular, sensitive authentication data such as full track data, card verification values, and PIN blocks must not be stored after authorization, even when encrypted, regardless of Level 3 test results. Treat data protection controls as a separate workstream validated against the current published standards rather than assuming Level 3 acceptance addresses them.

Common misconceptions

Passing EMV Level 3 testing means the payment solution is PCI DSS compliant.
EMV Level 3 testing validates EMV transaction integration and acceptance behavior; it does not assess PCI DSS controls over cardholder data, nor does it address separate standards such as PCI P2PE, PCI PIN, or the PCI Software Security Framework. EMV chip authentication and PCI compliance address different objectives and must be evaluated independently.
EMV Level 3 certification eliminates card fraud at the point of acceptance.
EMV chip authentication is intended to help reduce certain card-present counterfeit and skimming fraud, but it does not address card-not-present fraud, account takeover, or other fraud types. Liability outcomes depend on card brand and network rules, which vary by region and change over time.
Once Level 1 and Level 2 approvals are obtained, Level 3 testing is a formality.
Level 3 focuses on integration and configuration in the specific acquiring environment, where misconfiguration or host integration issues can cause failures even with approved hardware and kernels. It is a distinct validation step, not an automatic pass.

Best practices

Confirm that terminal hardware (Level 1) and kernel (Level 2) approvals are current before beginning Level 3 testing, and verify the specific test cases and acceptance criteria required by your acquirer and each supported card brand, as these vary by region.
Execute the acquirer- and network-provided test scripts across all transaction types, card ranges, and configuration options you intend to support in production, rather than only a representative subset.
Validate terminal and host configuration parameters explicitly, since configuration errors are a common cause of Level 3 failures even when hardware and kernels are already approved.
Treat EMV Level 3 testing as separate from PCI DSS validation and from other PCI standards such as PCI P2PE and PCI PIN, and plan for those assessments independently against the current published standards.
Do not rely on EMV chip authentication alone for fraud mitigation; layer additional controls appropriate to card-not-present and other fraud risks based on your acceptance channels.
Retain evidence of test results and sign-off from the acquirer or network, and re-test when configurations, integrations, or supported transaction types change.