Creditcall CTO Jeremy Gumbley looks at the problems and solutions how the EMV Migration bottleneck of the vigorous, slow and costly EMV certification processes can be bypassed, the complexity, risk and cost of EMV certification removed, and PCI DSS requirements – including major security concerns – and compliance demands reduced. Diagnosis and discussion is pertinent as all of these topics will play an enormous role in the run up to the October 2015 EMV Migration deadline. For more information, go to www.creditcall.com/ChipDNA
Five EMV Migration Pain Points
1. Choose PINpad, develop and perfect driver
2. Update each processor interface for new EMV messages
3. Certify for each PINpad and each processor (M-TIP/ADVT/AEIPS/D-PAS)
4. Adapt or create a Terminal Managament System (TMS)
5. Maintain PCI P2PE certifications
Unleash Your Potential - Namagunga Girls Coding Club
Diagnosing the EMV Migration Pain Points
1. Diagnosing the EMV Migration Pain Points:
How to Make the Bitter EMV Migration Pill
Easier to Swallow
Jeremy Gumbley, CTO
Creditcall North America
Cartes America 2014, May 13-15
7. FACTORS TO CONSIDER
a) Attended or Unattended?
→ How important is PIN Debit to you?
b) What CVMs do you need to support?
Booth #1615
www.creditcall.com/ChipDNA
jeremy.gumbley@creditcall.com
Linkedin.com/in/jgumbley
1. SELECT PINPAD, CREATE RELIABLE AND
ROBUST DRIVER…………………………………………………………………………………………………………………………………………………….
11. Booth #1615
www.creditcall.com/ChipDNA
jeremy.gumbley@creditcall.com
Linkedin.com/in/jgumbley
2. UPDATE PROCESSOR INTERFACES TO SUPPORT
EMV MESSAGING
…………………………………………………………………………………………………………………………………………………….
TIME MANAGEMENT
• Have you allocated enough time to the project
considering the Processors will probably be
inundated with support requests?
• Do the same for every Processor interface
SUPPORT
• Will the Processor have enough resource to
support you?
13. Booth #1615
www.creditcall.com/ChipDNA
jeremy.gumbley@creditcall.com
Linkedin.com/in/jgumbley
3. CERTIFY EACH PINPAD WITH EACH PROCESSOR
…………………………………………………………………………………………………………………………………………………….
LAYERS OF BRAND CERTIFICATION
• Each PINpad and processor combination
requires various layers of brand certification –
M-TIP/ADVT/D-PAS
• Rinse and repeat for each Processor you need
to support!
• A certification requires costly test cards and
testing tools
14. Booth #1615
www.creditcall.com/ChipDNA
jeremy.gumbley@creditcall.com
Linkedin.com/in/jgumbley
3. CERTIFY EACH PINPAD WITH EACH PROCESSOR
…………………………………………………………………………………………………………………………………………………….
BUDGET ENOUGH TIME
• In mature markets like the UK it takes 10-16 weeks per certification
• Repeat every time the EMV Level 2 certification expires
• Will the processor have enough time to support
you?
• What will the processor charge you to certify?
• Don’t forget changes in receipting to show some
additional EMV fields such as the AID!
• Allow extra time for a first certification for documentation
interpretation errors, unforeseen technical issues and test host
availability.
16. Booth #1615
www.creditcall.com/ChipDNA
jeremy.gumbley@creditcall.com
Linkedin.com/in/jgumbley
4. WHAT ABOUT TERMINAL MANAGEMENT?…………………………………………………………………………………………………………………………………………………….
TERMINAL ESTATE MANAGEMENT
• Now that you have successfully updated
your application to support EMV, how will
you manage all the additional data elements
required by EMV?
• How will you update the firmware in your
PINpad estate?
17. 5. WHAT ABOUT
PCI P2PE?
Booth #1615
www.creditcall.com/ChipDNA
jeremy.gumbley@creditcall.com
Linkedin.com/in/jgumbley