EMV Secure Remote Commerce
EMV Secure Remote Commerce (SRC) is a set of specifications developed by EMVCo that is intended to make online and in-app checkout more consistent and convenient for shoppers and merchants. It acts like a virtual payment terminal that can work across websites and apps, and it is sometimes offered to consumers under the 'Click to Pay' brand. It is designed to help make remote card payments easier to complete without merchants and consumers having to re-enter card details for each transaction.
EMV Secure Remote Commerce (SRC) is an EMVCo specification framework that defines an interoperable approach for card-based remote (card-not-present) payments across websites, apps, and multiple device types, providing what the specifications describe as a virtual payment terminal for online checkout. EMVCo updated the SRC Specifications (announced January 2023) to support more flexible online checkout options for merchants and consumers. SRC is a specification framework maintained by EMVCo and is distinct from PCI DSS and from other EMVCo work such as EMV 3-D Secure; the consumer-facing implementation is often branded 'Click to Pay.' The evidence provided describes SRC's purpose and scope qualitatively and does not establish specific security control details, fraud-reduction figures, or its effect on PCI DSS scope, which would depend on the specific implementation and validation.
Why it matters
Card-not-present checkout has long been fragmented, with each merchant, website, and app collecting and handling card details in its own way. This inconsistency creates friction for consumers, who must re-enter card data across many sites, and it complicates the payment experience for merchants. EMV Secure Remote Commerce (SRC) matters because it offers an EMVCo-maintained specification framework intended to make online and in-app checkout more consistent, convenient, and interoperable across websites, apps, and device types, functioning as what the specifications describe as a virtual payment terminal.
Because SRC is an interoperable specification rather than a single proprietary product, it is designed to work across multiple channels and devices, and the consumer-facing implementation is often presented under the 'Click to Pay' brand. EMVCo announced updates to the SRC Specifications in January 2023 to support more flexible online checkout options for merchants and consumers, reflecting ongoing evolution of the framework rather than a fixed, static specification.
SRC should not be read as a standalone security guarantee. The evidence provided describes SRC's purpose and scope qualitatively but does not establish specific security control details, fraud-reduction figures, or its effect on PCI DSS scope. Any effect on PCI DSS scope, and any fraud or chargeback outcomes, would depend on the specific implementation and its validation, and on separate card brand and network rules that vary by region and change over time. SRC is distinct from PCI DSS and from other EMVCo work such as EMV 3-D Secure, and it is not a substitute for those.
Who it's relevant to
Inside SRC
Common questions
Answers to the questions practitioners most commonly ask about SRC.