What is EMV?

If you subscribe to a service from a link on this page, Reeves and Sons Limited may earn a commission. See our ethics statement.

Quick answer:

EMV is the global chip card standard that authenticates in-person card payments, originally built by Europay, Mastercard and Visa. Every transaction where a chip is inserted or a card is tapped runs on it, and EMVCo reports that more than 90% of all card-present transactions worldwide now use the standard.

You do not buy EMV itself. You buy a terminal that is certified to support it. The headline worth paying attention to is the liability shift: if a customer hands you a chip card and your hardware can only swipe, the fraud loss that follows may belong to you rather than to the issuing bank.

Most store owners first spot EMV on a spec sheet. They meet it properly when a disputed transaction arrives and no one else picks up the bill.

The standard itself is straightforward. What gets complicated are the policies built on top of it, and those policies are set by four separate card networks, not by one central authority. Here is what the chip does, who owns it, what the liability shift actually changed for your store, and what it leaves exposed.

What is EMV? The Basics

EMV stands for Europay, Mastercard and Visa, the three companies that jointly drafted the specification in the early 1990s. The name remained even after the ownership group expanded.

That specification is now maintained by EMVCo, which is collectively owned by six card networks: American Express, Discover, JCB, Mastercard, UnionPay and Visa. Each network holds two seats on the board.

One structural fact about EMVCo explains most of what follows on this page. EMVCo publishes and tests the chip specifications, but it does not mandate the adoption of EMV and it does not enforce compliance. Those decisions stay with each individual card network.

Scale helps put it in context: EMVCo counts nearly 12 billion chip-enabled credit and debit cards in circulation globally. A store that cannot read a chip is no longer accommodating a corner case.

How an EMV Chip Transaction Works

The gap between a chip and a magnetic stripe is a single idea: static data versus data that changes with every purchase.

A stripe holds the same information from swipe to swipe. Copy it once and every copy works, which is why stripe data was worth harvesting in bulk and why counterfeit cards were so cheap to produce.

A chip transaction runs differently because the chip is a small processor, not a storage medium:

  1. The card and the terminal exchange information. The chip responds to the terminal rather than simply handing over a fixed data file.
  2. The chip generates a one-time cryptogram tied to that specific purchase, using a key stored inside the chip that never leaves it.
  3. That cryptogram travels with the authorization request to your processor, through the card network and on to the issuing bank.
  4. The issuer validates the cryptogram and approves or declines. A code from an earlier transaction will not pass this check.

That single-use code is what kills counterfeit cloning. Intercepting a chip transaction gives a fraudster a code that has already been spent, so there is nothing useful left to replay. The same mechanism works whether the chip is inserted, tapped, or presented from a phone or watch acting as a contactless card.

Chip and PIN vs Chip and Signature

Both are EMV chip transactions. The only difference is how the person holding the card confirms they are the cardholder, a step the industry calls cardholder verification.

Chip and PIN asks for a PIN. Chip and signature asks for a signature. The card and the terminal negotiate which one to use, not the cashier and not the store.

The split has always been regional. Much of Europe standardized on PIN early. In the US, most debit cards default to PIN while credit cards defaulted to signature, which is why American travelers used to get handed a receipt to sign in countries where nobody else was signing anything.

That gap has largely disappeared. Visa stopped requiring EMV-enabled merchants to collect and verify signatures in 2018, and the other major networks moved in the same direction. In practice many US chip and contactless transactions today require neither a PIN nor a signature, especially below a certain amount.

The practical takeaway for a retailer is small: verification behavior is not something your store configures. A terminal prompting differently between two customers is normal, not a sign that something is broken.

The Liability Shift: The Part That Costs You Money

The liability shift is a rule about who pays when a card-present transaction turns out to be fraudulent. Before it, the card issuer generally absorbed counterfeit fraud. After it, the party using the less secure technology absorbs it.

Walk through a concrete scenario. A boutique operates a countertop terminal that reads only magnetic stripe. A customer pays with a stolen chip card, the cashier swipes it because there is no chip slot, and the sale goes through for $180. Two weeks later the real cardholder disputes the charge as fraud.

Because the card carried a chip and the terminal could not read it, the $180 lands on the merchant. The sale is reversed as a chargeback, the goods are gone, and the processor adds a dispute fee on top. If that same fraudulent card had been inserted into a chip-capable terminal, the same $180 would have fallen on the issuing bank instead.

The shift does not penalize a store for being defrauded. It penalizes a store for accepting a chip card through a weaker method when a stronger method was available and went unused.

The US dates matter because they were never one date:

Transaction typeLiability shift dateSet by
General in-store retailOctober 1, 2015The major card networks
ATMsOctober 21, 2016Mastercard
ATMsOctober 1, 2017Visa
Automated fuel dispensersOriginally October 1, 2017, delayed to October 1, 2020, then to April 16, 2021 for American Express, Discover and Mastercard and April 17, 2021 for VisaEach network separately

This is where the EMVCo distinction earns its keep. EMVCo did not set any of these deadlines. Each card network sets and enforces its own liability policy, which is exactly why Mastercard and Visa shifted ATM liability nearly a year apart and why the fuel pump deadline slipped twice, the second time due to the COVID-19 pandemic.

EMV, Contactless and Tokenization

These three are often presented as competing options. They are actually layers that stack.

Contactless is a communication method, not a separate standard. EMVCo publishes specifications for contact chip and contactless chip as two ways of talking to the same underlying technology, so a tap is an EMV transaction that skips the slot. The consumer-facing detail lives under contactless payment.

Tokenization is the second layer. Chip authentication proves a transaction is genuine; tokenization replaces the actual card number with a constrained-use token tied to a specific merchant, device or transaction context, so a token stolen from one setting generally cannot be spent in another. That is covered under payment tokenization.

Wallet payments use both. When a customer pays with a phone or watch, the transaction carries EMV chip authentication and a token instead of the real card number, which is why tap to pay on iPhone and its equivalents are generally treated as at least as secure as inserting a chip.

What EMV Does Not Protect You From

EMV solved one problem effectively and left several others untouched.

  • Card-not-present fraud is completely unaffected. Online, phone and keyed transactions have no chip to authenticate, so terminal upgrades change nothing about ecommerce fraud liability. See card-present vs card-not-present for how the two tracks separate.
  • Friendly fraud and disputes still happen. A genuine cardholder who disputes a legitimate purchase creates a chargeback regardless of how the card was read.
  • PCI DSS is a separate obligation. EMV governs how one in-person transaction is authenticated and who is liable for certain fraud. PCI DSS compliance governs how your business stores, transmits and processes card data at all. A store can satisfy one and fail the other.

Treat chip hardware as one control among several rather than a finished security program. PCI compliance for small business retailers and POS security features and how to secure your system cover the rest of what needs attention.

Making Sure Your Terminal Is EMV Ready

Three checks settle it. Does a POS terminal on your counter have a chip slot, does it read contactless taps, and is chip actually the method your team uses rather than swiping out of habit?

That third question is the quiet failure point. A chip-capable terminal that gets bypassed at the till puts your store back in the swipe column for liability purposes.

Square has published figures on how quickly its own sellers moved: by the end of 2017, roughly 92% of cards processed on Square were chip cards, and sellers who upgraded hardware saw counterfeit fraud drop by 70% between September 2015 and December 2017. Those are Square’s own numbers from its own seller base rather than independently audited industry data, so treat them as directional, not definitive.

Any current mainstream hardware is EMV and contactless certified out of the box, so this is mostly a question for older equipment. The complete guide to Square POS hardware is a useful reference for what a current certified setup looks like.

Bogdan Rancea

Bogdan is a founding member of Inspired Mag, having accumulated almost 6 years of experience over this period. In his spare time he likes to study classical music and explore visual arts. He’s quite obsessed with fixies as well. He owns 5 already.

shopify first one dollar promo 3 months