EMV (Europay, Mastercard, and Visa)

EMV is the global standard for chip-based payment cards, named for Europay, Mastercard and Visa, the three companies that created it, and now managed by EMVCo. Its defining property is simple: the chip generates a unique cryptogram for every single transaction, so data captured from one payment cannot be replayed to authorize another.

Stands for Europay, Mastercard, Visa
Managed by EMVCo
Contact interface ISO/IEC 7816
Contactless interface ISO/IEC 14443
Core mechanism A unique application cryptogram per transaction
Card type Microprocessor smart card
Replaced Magnetic stripe as the primary card-present method

How EMV works

A magnetic stripe is static. Everything needed to authorize a payment is written on it in the clear, which means anyone who reads it once can reproduce it forever. That single property is what made skimming such a profitable business.

An EMV chip inverts the model. At each transaction the terminal sends the chip details of the payment, and the chip returns a cryptogram computed with a key that has never left the silicon. The cryptogram is valid for that transaction and no other. Capture it, replay it, and it fails.

The chip also authenticates itself to the terminal, which is what defeats a counterfeit card carrying copied data. Contactless EMV runs the same logic over the ISO/IEC 14443 radio interface rather than the contact pads.

Magnetic stripe vs EMV

Magnetic stripe EMV chip
Data Static, identical every time Unique cryptogram per transaction
Replay attack Trivial Fails
Card authentication None Cryptographic
Cloning Cheap and reliable Impractical
Skimming exposure High Low

Why EMV matters — and what it moved rather than solved

EMV worked. Counterfeit card-present fraud fell sharply in every market that adopted it, because the economics of copying a card stopped making sense.

What it did not do was reduce fraud overall. It relocated it. The chip protects the transaction at the terminal, but the card number, expiry date, and security code are still printed on the plastic and still typed into checkout forms. Fraud followed the path of least resistance into card-not-present channels, where no chip is involved and no cryptogram is generated.

That is the practical consequence for anyone building payment risk: a chip in the customer’s wallet does nothing for an online transaction. The verification has to happen on the card data itself and on the person submitting it, which is why card capture, fraud signals, and identity checks increasingly run in the same step.

What EMV can’t do

It does not protect online payments. The cryptogram requires a physical chip and a terminal. E-commerce transactions have neither, so the entire EMV security model is absent from the channel where most fraud now happens.

It does not verify the cardholder. EMV proves the card is genuine. Whether the person holding it is the legitimate owner is a separate question answered by PIN, biometrics, or step-up verification.

The PAN is still exposed. The card number remains printed, embossed, and readable. EMV secured the transaction, not the credential printed on the card.

Fallback weakens it. Many cards still carry a magnetic stripe for compatibility, and forced-fallback attacks deliberately trigger it. The stripe is the weakest link that has been kept for convenience.

Frequently asked questions

What does EMV stand for?

Europay, Mastercard and Visa — the three companies that developed the original specification. It is now maintained by EMVCo, whose membership has expanded well beyond those three.

Is contactless payment the same as EMV?

Contactless payment is EMV running over a radio interface instead of contact pads. The same per-transaction cryptogram is generated either way; only the physical layer differs.

Did EMV reduce fraud?

It sharply reduced counterfeit card-present fraud in adopting markets. Total fraud did not fall by the same amount, because activity shifted into card-not-present channels where the chip plays no part.

Why do EMV cards still have a magnetic stripe?

Backward compatibility with terminals and regions that have not migrated. It is a known weakness — forced-fallback attacks deliberately induce stripe use to bypass the chip.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.