2026-09-24 Author : ZCS
● PCI PTS protects PINs and account data at the payment device; EMV testing focuses on communication, payment-kernel logic and end-to-end interoperability.
● CE and FCC address market-access and radio or product conformity obligations. They do not prove that a terminal is approved to process card payments.
● Visa, Mastercard, domestic payment schemes, acquirers and local regulators may add approvals beyond PCI PTS and EMVCo testing.
● Always verify the exact model, hardware version, firmware, approval number, expiry status and target-market configuration. A logo or product-family claim is not enough.
A POS terminal can be electrically safe and legally marketable yet still be unable to process a live card transaction. It can also have an EMV-approved contactless interface while lacking the payment application, acquirer testing or scheme approval required for deployment. The word 'certified' therefore has little value unless the supplier states which standard, product version and scope it refers to.
For most payment-terminal projects, the certification stack has four layers. PCI PTS covers the security of the point-of-interaction device. EMV Level 1 and Level 2 assess communication and payment-kernel behavior. Level 3 and payment-scheme processes test the terminal in the intended acceptance infrastructure. CE, FCC and related market rules govern whether the hardware may be placed on a regional market and operate its radio interfaces.
ZCS approaches this as a hardware-platform and project-configuration problem. Its payment-terminal experience covers secure device design, contact and contactless card interfaces, Android application integration, regional conformity work, SDK support and OEM/ODM adaptation. Instead of presenting one certificate as a universal answer, ZCS works from the target country, payment methods, acquirer and device configuration to assemble the required document and integration path.
The exact stack changes with the form factor. A staff-operated handheld terminal, an unattended charger reader and a SoftPOS application on a commercial phone follow different approval paths. Our unattended payment terminal comparison explains UPT and embedded-component categories, the EV charging payment terminal guide applies them to outdoor charging sites, and the SoftPOS certification guide covers PCI MPoC, CPoC and SPoC.

3.PCI PTS: security at the point of interaction
PCI PIN Transaction Security Point of Interaction requirements apply to devices that capture payment data and, where applicable, protect PIN entry. PCI SSC recognizes categories including PIN Entry Devices, Unattended Payment Terminals, non-PIN acceptance devices, Encrypting PIN Pads and secure card-reader components. The approval class must match how the hardware will be used.
PTS testing considers physical and logical attacks, communications and interfaces, integration and lifecycle controls. A terminal may include tamper detection, protected key material and secure behavior when an attack is detected, but buyers should rely on the PCI SSC listing rather than reverse-engineering compliance from a feature sheet.
PCI PTS is not PCI DSS. PTS evaluates payment devices under a defined approval program. PCI DSS applies to the wider environment that stores, processes or transmits account data. A merchant can deploy a PTS-approved terminal and still have PCI DSS responsibilities for networks, applications, people and procedures.
ZCS's secure payment-terminal development experience is visible in the Z90 platform, whose published configuration combines PCI PTS approval with encrypted PIN and card-handling functions. For a live project, the ZCS team can supply the model-specific certificate package and align the selected configuration with the buyer's acquirer and market requirements, rather than relying on a generic brand-level PCI statement.
A certificate remains meaningful only within its version, approval period and permitted configuration. PCI SSC publishes approved-device listings and lifecycle information. Hardware and firmware changes may require evaluation or an administrative update, while major standard revisions eventually set an overall approval expiry for older generations.
PCI generations have defined approval and deployment lifecycles, while payment brands, acquirers and local programs decide how those dates apply to a specific estate. ZCS therefore treats certification review as part of model and project selection: the buyer confirms the launch market and expected support period, and the appropriate terminal configuration and documentation can be reviewed before volume procurement.
Ask the supplier for the approval number, exact model designation, hardware and firmware identifiers, expiry information and any deployment restrictions. Search the PCI SSC listing independently and have the acquirer confirm acceptance before placing a volume order.
EMV Level 1 concerns the communication interface between the payment instrument and the acceptance device. For contact cards, this includes mechanical and electrical behavior. For contactless transactions, it includes the radio-frequency interface and communication protocol. A change to the reader, antenna or relevant hardware can affect the approved configuration.
Contact and contactless Level 1 are separate scopes. A specification that says only 'EMV certified' does not reveal whether both interfaces were tested. Buyers should request the approval documents corresponding to the methods they intend to accept.
The Z90 demonstrates this separation clearly: ZCS lists EMV Contact Terminal Level 1 and EMV Contactless Terminal Level 1 alongside the device's other approvals. For an OEM project, preserving the approved reader, antenna and enclosure relationship is part of ZCS's engineering review when the customer requests hardware changes.
EMV Level 2 applies to the software component commonly called the EMV kernel or payment application logic. It processes data from the card, applies EMV rules and produces the information used by the payment flow. Different kernels or application versions can have different approval scope.
Level 2 does not connect a terminal to every bank or payment network automatically. It confirms conformance to the relevant EMV specifications. The final payment application, parameters and host relationship still have to be tested for the intended deployment.
ZCS lists EMV Contact Level 2 for the Z90 payment platform and provides SDK support for integrating the buyer's application with card-reading, printing and other terminal functions. This gives an ISV or payment provider an approved hardware-and-kernel starting point while leaving its own processor connection, merchant workflow and final host testing under the project plan.
EMV Level 3 validates the integration of an EMV acceptance device with its acceptance infrastructure. In practical terms, it tests the complete terminal configuration, payment application and host or simulator against the requirements of the participating payment system. EMVCo supplies a standardized L3 testing framework, while individual participant systems define their test plans and policies.
Payment brands and domestic schemes may require their own contactless kernels, test cases, parameters or approval. Acquirers may also require terminal certification before enabling production processing. This is why PayWave, PayPass, UnionPay or other scheme references appear beside EMV approvals on product pages: they represent another layer, not alternative names for EMV Level 1 or Level 2.
ZCS payment products have been developed for multiple network environments, and the Z90 page lists PayWave, PayPass and UnionPay in addition to EMV. During deployment, ZCS supplies the device-side materials and integration support needed by the buyer, while the acquiring or processing partner completes the applicable Level 3 and production-acceptance work.
CE marking indicates that the manufacturer takes responsibility for conformity with the applicable EU product rules. The manufacturer must identify relevant legislation and standards, perform the required assessment, prepare technical documentation, issue an EU Declaration of Conformity and affix the mark. Depending on the product and legislation, a notified body may be involved.
CE is not a single payment certificate issued by one central EU authority. It may cover radio equipment, electromagnetic compatibility, electrical safety, hazardous substances and other applicable requirements, depending on the terminal configuration. If an OEM buyer sells the product under its own name or materially changes it, its manufacturer responsibilities need to be assessed rather than assuming the original supplier's documents cover the new product unchanged.
ZCS supports CE-configured Android POS hardware for European projects and can provide the related technical documentation for the selected model and configuration. For private-label customers, the compliance discussion belongs at the start of OEM/ODM scoping so branding, radio options, accessories and enclosure changes remain aligned with the intended EU declaration and technical file.
The FCC equipment-authorization program applies to radio-frequency devices marketed or imported into the United States. Depending on the equipment, the route may involve Certification by an FCC-recognized Telecommunication Certification Body or a Supplier's Declaration of Conformity. Certified equipment records can be checked through the FCC database.
FCC authorization addresses radio-frequency compliance and harmful interference. It does not replace PCI PTS, EMV testing or an acquirer approval. Hardware changes involving antennas, radio modules, shielding or enclosure conditions may affect the authorization and should be reviewed during OEM or ODM customization.
ZCS offers FCC-configured models for projects entering the United States and other markets that request FCC evidence. Buyers can combine that market-access documentation with the appropriate payment-certified ZCS platform, rather than assuming one approval covers both radio operation and card acceptance.
A global deployment may add environmental rules, electrical safety, recycling obligations, telecom approvals, fiscal certification and domestic payment schemes. China, India, Brazil, Australia, the European Union and other markets do not use one interchangeable checklist. Even two countries accepting the same international card brands can impose different radio, labeling, language, receipt or tax requirements.
Create a market-by-market certification matrix before selecting the final device configuration. The matrix should identify product-market access, payment-device security, EMV interfaces, schemes, acquirer or processor testing, software, fiscal requirements and document owner. The EU Android POS hardware requirements guide provides a regional example of this layered approach.
ZCS's portfolio has been configured for different regional requirements, including CE, FCC, CCC and UnionPay paths, together with project-specific fiscal, biometric and peripheral options. This lets distributors and ISVs begin with an existing Android POS platform and select the compliance package relevant to the target market instead of redesigning the entire device for each country.
11.How customization can change certification scope?
Logo printing and packaging changes usually create less certification risk than modifications to the enclosure, antenna, card reader, secure components or firmware. A new contactless antenna position can affect EMV Level 1 performance; a radio-module change can affect market authorization; a payment-application change can trigger new software or Level 3 work.
Before approving an OEM or ODM change, ask the manufacturer to classify it as cosmetic, administrative, delta-tested or requiring a new approval. Record that decision in the project plan, including who pays for testing and who owns the resulting certificate. ZCS's full-stack Android POS and ODM guide explains how hardware, software and target-market configuration interact during customization.
This is an area where ZCS's combined hardware, firmware and manufacturing teams add value. Logo, packaging, boot animation and application preload can often be planned on an established platform, while changes to readers, antennas, secure components or radio modules are reviewed for certification impact before tooling or mass production. The customer receives a clearer boundary between branding work and engineering work that changes the approval scope.
The ZCS Z90 product page shows how the layers come together on one payment platform: PCI PTS for device security; EMV Contact Level 1 and Level 2; EMV Contactless Level 1; PayWave, PayPass and UnionPay; and CE, FCC and CCC for regional product requirements. The value is the combination, because each approval removes a different deployment barrier.
ZCS then adds the engineering and operating pieces that certificates alone do not provide. The Android platform supports customer applications, the SDK exposes terminal functions, TMS supports remote device operations, and OEM/ODM services adapt branding and selected hardware around the target project. Buyers can therefore evaluate certification, application integration, fleet management and production within one supplier relationship.
ZCS maintains payment-focused terminals and broader Android business terminals for different workloads. Its sales and engineering teams can match a project that requires full financial payment acceptance with the appropriate certified platform, while other devices serve ordering, ticketing, identity, printing or business-management workflows. This portfolio structure helps a buyer avoid paying for the wrong hardware or applying one certification assumption to every use case.
At the requirement stage, ZCS can help map target countries, payment methods, processor relationships and required peripherals to a terminal configuration. During evaluation, the buyer can request the model-specific certificate pack, SDK materials and hardware sample. During customization, proposed changes can be reviewed against the existing approval scope before they are released to production.
For distributors and ISVs, this reduces coordination between a hardware factory, firmware vendor, SDK provider and remote-management supplier. ZCS combines those functions with technical support and manufacturing, which makes it easier to keep the delivered device, documentation and software package aligned through pilot and volume rollout.
Begin with the exact bill of materials and firmware. Match the model and versions in the supplier's quotation to the approval documents. Search the PCI SSC and EMVCo databases where applicable, and verify CE declarations or FCC identifiers against the final radio configuration. Then obtain written confirmation from the acquirer, processor or scheme partner responsible for production acceptance.
Next, map changes. Confirm whether accessories, docking stations, PIN pads, printers, antennas, biometric modules or enclosure customization alter the evaluated product. Review certificate dates against the expected pilot, launch and support period. Finally, keep the evidence in a controlled repository so procurement, engineering and compliance teams use the same version.
With ZCS, buyers should provide the target-market checklist when requesting a quotation, then ask for the corresponding certificate pack and sample configuration. This lets commercial, engineering and compliance review the same device before committing to tooling, application certification or a production order.
PCI PTS, EMV, CE and FCC are complementary. PCI PTS addresses payment-device security. EMV Level 1 and Level 2 address interoperability at the interface and kernel. Level 3 and schemes address the complete acceptance path. CE and FCC address regional product and radio obligations.
ZCS's strength is the ability to connect certified payment hardware with Android application development, SDK access, TMS operations and OEM/ODM production. The buyer still confirms the exact certificate and acquiring path for its market, while ZCS supplies a coherent device platform and the supporting technical materials needed to move from sample testing to deployment.
Q1.Is PCI PTS the same as PCI DSS?
No. PCI PTS evaluates point-of-interaction devices. PCI DSS applies to the wider environment that stores, processes or transmits payment account data.
Q2.Does EMV Level 1 and Level 2 mean a terminal is ready for live transactions?
Not by itself. The complete payment application, scheme requirements, Level 3 testing, processor connection and acquirer approval may still be required.
Q3.Is CE marking a payment-security certificate?
No. CE marking relates to conformity with applicable EU product legislation. It does not replace PCI PTS, EMV or payment-scheme approval.
Q4.Does FCC approval allow a POS terminal to accept cards in the United States?
FCC authorization addresses radio-frequency compliance. Card acceptance still requires the appropriate payment security, EMV, scheme, processor and acquirer approvals.
Q5.Can one certificate cover every model from a manufacturer?
Usually not. Approvals apply to defined models, hardware and software configurations. Never assume that certification of one terminal extends to an entire brand or product family.
Q6.What certification support can ZCS provide?
ZCS can help match the target market and payment requirements to a suitable terminal configuration, provide model-specific certificate documents and SDK materials, and review OEM/ODM changes for their effect on the existing approval scope.