Blog

Will EMV Make You PCI Compliant?

Date Published:
June 1, 2015

VikingCloud Team

SHARE ON

Understanding EMV’s capabilities with the concepts of data security and PCI compliance.

Many merchant acquirers, payment processors and Independent Sales Organizations (ISOs) have been reaching out to business owners to alert them of America’s 2015 migration from magstripe (i.e., “swipe”) credit/debit cards to EMV (i.e., “chip”) payment cards.

The new EMV cards will have much-needed, enhanced anti-fraud capabilities at the physical point of sale. So, when your customer presents a card for payment, it will be much easier to tell if that card actually belongs to them.

While EMV represents a significant improvement in the way credit/debit card fraud is detected and prevented, some have confused EMV’s capabilities with the concepts of data security and PCI compliance.

Does EMV override PCI?

The short answer is no, EMV technology does not satisfy any PCI requirements, nor does it reduce PCI scope.

What EMV is:

• It is counterfeit card fraud protection – it makes it more difficult for bad guys to make use of stolen card data

What EMV is not:

• It is not encryption – EMV does not encrypt the Primary Account Number (PAN) and therefore the card data must still be protected according to PCI guidelines

• It is not helpful for ecommerce transactions – EMV only works for card present transactions

So, if your business accepts credit or debit cards in a physical store (or other face-to-face setting), you will need to implement the EMV technology and PCI standards in a layered fashion. For example, as you upgrade your terminals for EMV, consider adding point-to-point encryption (P2PE) capabilities to reduce PCI scope and protect data end to end. In addition, using tokens after authorization can prevent the card data from being used, should it be stolen.

Even if 100% of your payment transactions are ecommerce (i.e. card-not-present), you’ll want to take a closer look at your payment acceptance methods as well as the security of your web applications. That’s because as EMV takes effect, you will see a shift in fraud from card-present transactions to ecommerce. This happened in Europe and it’s expected to happen in the U.S. as well.

SHARE ON

Related Blogs

Stay up-to-date on the latest happenings in Cybersecurity and PCI Compliance.

Sep 3, 2026
Blog
Risk Management
Web Risk Monitoring
Cybersecurity
Blog
Sep 3, 2026

Third-Party Vendors Already Have Access to Your Stores. Are You Managing the Risk?

Learn More
Aug 13, 2026
Blog
HIPAA Compliance
Blog
Aug 13, 2026

What is a HIPAA Security Rule Gap Analysis and Why It Matters Now

Learn More
Aug 18, 2026
Blog
HIPAA Compliance
Penetration Testing
Blog
Aug 18, 2026

HIPAA Penetration Testing: A Complete Compliance Guide

Learn More