EMV QR Codes
EMV QR Codes are two-dimensional, machine-readable barcodes used to initiate payments, commonly at the point of sale or for mobile payments. They follow a common specification set by EMVCo so that a single QR code can support a range of payment options for a merchant's customers.
EMV QR Codes are QR code payment specifications maintained by EMVCo that standardize the data format used to initiate QR-based transactions, promoting interoperability across payment methods and providers. EMVCo defines two models: a Merchant-Presented Mode (MPM), in which the merchant displays a QR code that the consumer scans, and a Consumer-Presented Mode (CPM), in which the consumer displays a code the merchant scans; per the evidence, the MPM specification can support both account-based and card-based payment. As a data-format and interoperability standard, EMV QR Codes govern how transaction data is encoded and exchanged, but they are distinct from PCI DSS and related PCI standards that govern the protection of cardholder data and sensitive authentication data; implementers should confirm scope, security, and data-handling obligations against the applicable PCI standards and the current EMVCo specifications rather than assuming any single label implies a given security outcome.
Why it matters
QR code payments have become an increasingly common way to facilitate mobile payments at the point of sale, and fragmentation across proprietary QR formats can create friction for merchants and consumers. EMV QR Codes address this by providing a common EMVCo specification so that a single QR code can support a range of payment options for a merchant's customers, promoting interoperability across payment methods and providers rather than locking a merchant into one wallet or scheme.
For payment teams, the practical significance is that EMV QR Codes standardize how transaction data is encoded and exchanged, but they do not by themselves define how cardholder data or sensitive authentication data must be protected. It is important not to assume that adopting the EMV QR Code label implies a particular security outcome. The specification is distinct from PCI DSS and related PCI standards, and the security and data-handling obligations for a given deployment depend on implementation and the applicable standards, not on the format label alone.
Because EMVCo defines two operating models — Merchant-Presented Mode and Consumer-Presented Mode — the data flow and the party that scans differs, which can affect where transaction data is handled. Implementers should confirm scope, security, and data-handling obligations against the current EMVCo specifications and the applicable PCI standards rather than treating interoperability and security as the same thing.
Who it's relevant to
Inside EMV QR Codes
Common questions
Answers to the questions practitioners most commonly ask about EMV QR Codes.