Ensuring your mobile payment app meets EMVCo’s SBMP (Software-Based Mobile Payment) security standards is essential for compliance, user trust, and effective fraud prevention. This guide outlines the evaluation process, answers common questions, and offers practical tips for developers and businesses.
EMVCo SBMP certification demonstrates that your app is resilient against hacking, tampering, and data breaches—critical for mobile payment solutions. Certification is often mandatory or strongly recommended for apps handling sensitive payment data, and it enables collaboration with major payment schemes such as Visa and Mastercard.
SBMP evaluation must be performed by an EMVCo-accredited laboratory. Accredited labs, such as Applus+, guide clients from product registration through the final evaluation report.
The evaluation follows a rigorous, multi-stage process:
How long does SBMP evaluation take?
Typically 4–12 weeks, depending on product complexity, documentation, and remediation needs.
What if my app fails a test?
Developers receive detailed feedback and can pause the evaluation to implement fixes. After changes, the lab re-evaluates and repeats the test.
Are third-party libraries evaluated?
Only public vulnerabilities in third-party libraries are checked. Their impact on the final product is considered, but their code is not directly reviewed unless it’s a COTS (commercial off-the-shelf) tool, which may skip full SCR.
What’s the difference between PT and VT?
PT: Actively exploits vulnerabilities. VT: Validates security defences (e.g., anti-tampering).
Do I need to provide physical devices?
No. Labs test on their own devices. Only binaries, source code, and documentation are required.
How often should I re-certify?
Annually or after major updates introducing new security features.
Do I need to provide source code?
Yes. SBMP methodology requires white-box evaluation, so access to source code is mandatory during the process.
What version of the test application should I provide?
Use the most secure version available, ideally a production build. Developer or debug builds may not be sufficient.
As an accredited laboratory with extensive experience in security evaluations, we guide you through every step of the SBMP certification process. Our experts ensure high-quality services, helping you achieve and maintain compliance with industry standards.
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy.
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy.
Based on your behavior on the website (where you click, how long you browse, etc.) we establish parameters and a profile for you to display ads that correspond to your interests. See the cookies we store in our Cookies Policy.