The U.S. payments industry is bracing for the October liability shift for EMV adoption. Though the U.S. market accounts for more than half of the world’s payment transactions, it is an unregulated market with an array of players: merchants, processors and payment terminal manufacturers, independent software vendors, merchant banks, credit and debit card issuers and more. The scope and uniqueness of this market makes the pending migration to EMV particularly complex.
As U.S. merchants and issuers begin to adopt EMV, there are frequent reports that large numbers of U.S. merchants are not ready for EMV. Industry trade groups are contesting different aspects of the U.S. EMV liability shift, processors need more staff to process certifications and, as it turns out, EMV won’t solve all of today’s security problems, namely the data breaches that retailers and others have been plagued with in recent years.
Dazed and Confused About EMV
Confusion abounds regarding EMV migration, thanks in no small part to EMV marketing ploys that have capitalized on the Target (News - Alert) and Home Depot breaches. And, as the EMV liability shift date gets closer—which at this time is absolutely not a mandate—the various parties pressuring merchants to immediately adopt EMV are creating a misplaced sense of panic, leading merchants to adopt the quickest EMV solution possible, not necessarily the correct solution.
For instance, merchants are being urged in some cases to adopt EMV solutions that don’t incorporate point-to-point encryption (P2PE) or tokenization. These technologies help prevent breaches and simplify PCI (News - Alert) compliance. Further, they can help prevent sensitive payment card data from being stolen in the first place, which is the primary source of counterfeit cards. Additionally, the implementation of systems that can’t employ EMV with P2PE and tokenization may in fact put merchants in harm’s way, as it may expose their networks and other POS infrastructures to card data and change their PCI-DSS landscape.
In fact, some merchants are feeling the heat about moving to EMV so strongly that they’ve been pressured to transition from an integrated payment solution to a standalone solution, simply because an organization they work with has certified for EMV with a standalone payment terminal, but not an integrated payment terminal. This move may get them ready for EMV by the liability shift, but is sacrificing key integrated payment functionalities that save them significant time and money worth it?
In either of the above cases of EMV implementation, merchants need to consider the benefit compared with the cost. How could an EMV implementation that further exposes their environment to breaches be considered a move forward? Why would they even consider sacrificing the key time- and money-saving accounting and security functionalities of an integrated payment solution that contribute to the success of their business operations? The possibility of moving to an implementation of EMV that does not strategically support an organization’s business operations is especially concerning when all merchants get in return is protection from a very specific segment of fraud that they may not be liable for anyway.
After all, a merchant’s current contract with their acquiring bank or merchant services provider (MSP) may not even take EMV into account. It is entirely possible that this type of fraud was traditionally considered “zero liability” (which is liability that was just part of the issuer doing business) and that a merchant’s agreements do not reflect or even anticipate this type of fraud. This means that, based on a merchant’s current contracts, it may not even be possible for the merchant to shoulder the responsibility for that fraud—unless that merchant signs a new contract that waives their protection from it. This is one very important reason why merchants need to be wary of any proposals that require them to re-sign a contract or get into a new contract with their MSP related to updates for EMV; any new or updated contract may also be asking the merchant to sign up for more liability than their current contract outlines.
Bearing the Burden
There are three groups likely to shoulder the greatest burden as the liability shift deadline approaches: merchants, small card issuers, and small merchant banks. Merchants must invest in EMV-compliant terminals and system solutions at a substantial cost. Small issuers and co-issuers are also burdened with the costly retooling of the cards they issue. EMV cards are much more expensive to produce than traditional magnetic stripe cards. And, if they issue contactless EMV cards, these can cost up to two times more than a typical EMV card. Finally, small merchant banks, independent sales organizations (ISOs) and agents have very little control or say over the makeup of the payments industry and stand to lose the most by this liability shift if they cannot influence change or get their merchant customers prepared for EMV.
Implementing EMV Correctly
EMV technology was created more than 20 years ago, and doesn’t account for the proficiency with which hackers, some of who are now working in large groups and are backed by nation-states, are compromising payment systems today.
This means that a well-constructed EMV solution requires the use of layered security to protect sensitive cardholder data. Here are three crucial elements to implement during your EMV migration:
Amidst all the confusion, questionable marketing, and fear-mongering surrounding EMV adoption, merchants need to keep a clear head and take the time to find the best solution for their business. Merchants should focus on adding P2PE and tokenization to any EMV solution, which will enable your implementation to not only authenticate cards but also help lower your breach profile. A levelheaded plan that involves layered security will best prepare you for years to come.
About the Author: J.D. Oder serves double duty as Shift4's Senior Vice President, Research and Development and Chief Technology Officer. J.D. is a Certified Network Engineer with more than 15 years of experience. He leads Shift4's system operations and development efforts as well as the security and compliance teams. J.D. is the overall architect of the DOLLARS ON THE NET (News
- Alert)® solution. He was also an early adopter/member of the PCI Security Standards Council.