Kernel
The EMV kernel is the behaviour of the payment application. It sits above Level 1 digital conformance and carries the core logic of the transaction.







What this layer verifies
The kernel is the logic that actually advances a transaction between card and terminal. What is tested is the branching: application selection, offline data authentication, CVM, risk management, Generate AC and issuer scripts.
| What you want to confirm | Product |
|---|---|
| Whether the kernel branches as the scheme specifies, managed and run with qualified suites | ICCSim TMat |
| Building your own error cards and custom APDUs, beyond what the standard suites cover | ICCSim Dev |
| The runtime for script execution, instrument control, logging and reporting | SCRIPTIS™ |
Contactless means a separate kernel for each scheme
Where contact CT2 is comparatively common across schemes, contactless is handled as an independent kernel per scheme. Supporting another scheme therefore means another kernel to test (L2 contactless kernels).
Who supplies, and who verifies
Two quite different roles sit in this layer. Confusing them leads to the wrong purchasing decision.
| Role | Responsible party | Output |
|---|---|---|
| Supplying the kernel embedded in the terminal | Alcinéo (device under test side) | an implementation built for certification |
| Verifying that kernel | ICC Solutions and others (test side) | Qualified test tools and test scripts |
| Carrying out formal type approval testing | Accredited test laboratory | The test report |
| Issuing the Letter of Approval | Each scheme | The approval |
That a kernel exists in the portfolio, that a particular version is implemented, and that there is a valid Letter of Approval for particular hardware are three distinct things. Porting to a new terminal means type approval is required again for that terminal.
How this differs from the digital layer of Level 1
The digital layer of Level 1 looks at conformance of the lower protocol — frames, state transitions and so on. What Level 2 looks at is the behaviour of the payment application running above it. They are different layers, and neither substitutes for the other.
