Can Testing and Certification Be Made More Efficient? · Can Testing and Certification Be Made More...

16
Can Testing and Certification Be Made More Efficient? Cindy Kohler Visa Inc. Co-Chair EMV Migration Forum Testing & Certification Committee

Transcript of Can Testing and Certification Be Made More Efficient? · Can Testing and Certification Be Made More...

Can Testing and Certification Be Made More Efficient?

Cindy Kohler

Visa Inc.

Co-Chair EMV Migration Forum Testing &

Certification Committee

Agenda • Background On Why Do We Need To Test • Current Industry Efforts • Next Steps and Potential Solutions

Can Testing and Certification Be Made More Efficient?

2

Can Testing and Certification Be Made More Efficient?

3

Background On Why We Need To Test • Chip offers many options and flexible capabilities with

card personalization and terminal configuration • Host system impacts • Country-specific payment implementations • Multi-application solutions

Can Testing and Certification Be Made More Efficient?

All add

complexity and

opportunities

for error

leading to

interoperability

issues 4

Can Testing and Certification Be Made More Efficient?

Background On Why We Need To Test

After EMV Chip began deploying globally in the 90’s, the industry began to notice an increase in reported terminal-related interoperability issues

• Incorrect terminal configuration settings (especially post EMV Level 1 and 2 approval)

• Poor interpretation of EMV and payment brand specifications

• Tailoring of terminal to domestic market without consideration for global usage

• Terminal deployment prior to formal EMV Level 1 and 2 approval process

5

Background on Why We Need To Test Interoperability Issue - Any situation where the interaction between an EMV chip card and terminal fails to meet client or cardholder expectations globally

Issues may be the result (or combination) of:

• Incorrect card personalization, terminal configuration or host/network options chosen during the implementation phase of the program

• Incorrect product specifications or misinterpretation of specifications by product vendors

• Misinterpretation of best practices and scheme policies

• Coexistence of EMV and Domestic Applications or Proprietary Applications

Can Testing and Certification Be Made More Efficient?

6

Provide US Acquirers with tools to assist:

• Minimize deployment of terminals globally that would cause interoperability problems

• Maintain and ensure the integrity of the infrastructure and allow for frictionless cardholder acceptance experience

• Payment Brand testing takes place after EMVCo Level 1 and 2 Type Approvals and are global requirements

Enforce and validate industry best practice terminal settings to ensure acceptance of domestically and globally issued

cards

Can Testing and Certification Be Made More Efficient?

Background on Why We Need To Test

7

Can Testing and Certification Be Made More Efficient?

Interoperability Testing

8

Can Testing and Certification Be Made More Efficient?

• Variations in

Payment Brand

rules related to

device testing

Process

• Millions of retailer

systems

• 3rd Party Acquirer

processors

supporting

multiple clients

• 1000’s of VARs

without Chip

experience

Volume/Scale

• Experienced EMV resources are limited and spread broadly within many organizations

Resourcing

• Industry

implementation

timeline

pressures on

clients

Timelines/

Duration

Current process faces constraints due to significant

implementation challenges in the US market:

9

EMV Migration Forum (EMF) • Testing and Certification Working Committee established

• Developed the “EMV Testing and Certification White Paper: Current U.S. Payment Brand Requirements for the Acquiring Community”

• Recognize the US market is unique and complex • Reviewed existing processes and modified and tailored our solutions

as required to ensure efficiency in costs, scale and time to market

• Acquirer Subcommittee – Streamline Merchant EMV Chip and Contactless Terminal Testing Process

• Resource Center, through SCA/EMF Website

Can Testing and Certification Be Made More Efficient?

Current Industry Efforts

10

EMVCo Terminal Integration Task Force • Newly formed task force • Goal to review the varied acquirer processes encountered

across each payment system globally for an approved EMVCo terminal.

• Identify whether or not there is the ability to create a single process managed by EMVCo, and if so, present a proposal for review by the Board.

Can Testing and Certification Be Made More Efficient?

Current Industry Efforts

11

Can Testing and Certification Be Made More Efficient?

Integrator Registers via web site

Integrator CheckPoint

Approval? Y

Inputs Outputs§ Terminal Specs§ Requirements for Terminal

Certification

§ Initial certification§ Recertification

Request from VAR/Gateway Partner

Integrator Partner, Acquiring Bank

Request from VAR/Gateway Partner

VAR/Gateway Partner, Acquiring Bank

Request from VAR/Gateway Partner

VAR/Gateway Partner, Acquiring Bank

Request from VAR/Gateway Partner

Integrator Partner, Acquiring Bank

Request from VAR/Gateway Partner

Integrator Partner, Acquiring Bank

Class B Certification Process (non-EMV/EMV)

SupplierProcess

CustomersRequest from VAR/

Gateway/System IntegratorApproved Solutions posted

to Web Site

General Testing Conducted against Host

Specs & Testing Requirements Reviewed by IntegratorTesting Profile Built

Welcome Email to Integrator

Lab Analyst Assigned

Test Scripts Provided to Integrator

Formal Certification Scheduled

N

Certification Scripts Run by Integrator

Analyst Review

Certification Successful?

Issues Emailed to Integrator

N Issues Corrected

Y

Integrator notified via email

Certification Complete

Data Saved by Integrator

PCISS Statement Validated

Official Certification

POS Application Certification Process (pre-EMV)

12

Can Testing and Certification Be Made More Efficient?

Integrator Registers via web site

Integrator CheckPoint

Approval? Y

Inputs Outputs

§ Terminal Specs§ Requirements for Terminal

Certification

§ Class B Approved§ Card Brand Certifications§ Recertification

Request from VAR/Gateway Partner

Integrator Partner, Acquiring Bank

Request from VAR/Gateway Partner

VAR/Gateway Partner, Acquiring Bank

Request from VAR/Gateway Partner

VAR/Gateway Partner, Acquiring Bank

Request from VAR/Gateway Partner

Integrator Partner, Acquiring Bank

Request from VAR/Gateway Partner

Integrator Partner, Acquiring Bank

Class B Certification Process (non-EMV/EMV)

SupplierProcess

CustomersRequest from VAR/

Gateway/System IntegratorApproved Solutions posted

to Web Site

General Testing Conducted against Host

Specs & Testing Requirements Reviewed by IntegratorTesting Profile Built

Welcome Email to Integrator

Lab Analyst Assigned

EMV?

Y

Test Scripts Provided to Integrator

Formal Certification Scheduled

N

Certification Scripts Run by Integrator

Analyst Review

Certification Successful?

Issues Emailed to Integrator

N Issues Corrected

Y EMV?

Integrator notified via email

Certification Complete

Data Saved by Integrator

N

N

Y Y

N

N

Y

N

Y

N

PCISS Statement Validated

Official Certification Y

Engage Implementation

Project (IP) Manager

Analyst, IP Manager, and Integrator Review

Project Plan

Checkpoint for Required Test

Documents

MasterCard Certification

Certification Successful?

Visa Certification

Correct IssuesCertification Successful?

American Express Certification

Correct Issues

Certification Successful?

Correct IssuesDiscover

CertificationCertification Successful?

Correct Issues

New Process for EMV

13

Can Testing and Certification Be Made More Efficient?

Next Steps and Solutions

EMV Migration Forum (EMF) • Testing and Certification Working Committee

• Acquirer Subcommittee – Streamline Merchant EMV Chip and Contactless Terminal Testing Process

• Develop process for review/approval target by March • Finalize and publish approved process target by May

• Resource Center, through SCA/EMF Website

EMVCo Terminal Integration Task Force • Ongoing Global Efforts

14

15

Next Steps and Solutions

Recommendations for Acquirers • Determine where payments exist in your system • Reduce the number of touch points – isolate the payment

components • Review current merchant testing requirements to develop

acquirer recertification needs • Determine tools that fit your testing needs • Implement a Terminal Management System • Plan to manage deployment of dial-up terminals – more

difficult to upgrade/change

Can Testing and Certification Be Made More Efficient?

Can Testing and Certification Be Made More Efficient?

16