Skip to main content
Northwest Payment Brokers
Payments explained · updated 2026

What is EMV (chip card technology)?

EMV is the small metallic chip embedded in most debit and credit cards. It stands for Europay, Mastercard, and Visa, the three networks that built the standard together. Unlike a magnetic stripe, which stores the same static card data every time, the chip generates a unique one-time code for each transaction, which is what makes chip payments much harder to counterfeit or clone.

Why the chip is more secure than the stripe

A magnetic stripe is a passive strip of data. Whatever is encoded on it comes out the same way every time it's swiped, which means a skimmer that captures it once can replay that same data on a cloned card indefinitely. That was the main path for counterfeit card fraud for decades.

A chip works differently. Each time it's inserted or tapped, it runs a small cryptographic exchange with the terminal and generates a unique, single-use code for that one transaction. Even if someone intercepted that exact code, it's already spent and can't be used again. That single change is why counterfeit card fraud at chip-enabled, chip-read terminals dropped sharply after EMV rolled out in the U.S.

The liability shift, and why merchants actually care

Before October 2015, card-issuing banks generally absorbed the cost of counterfeit card fraud. After that date, the cost shifts to whichever side of the transaction had the weaker technology. A business with an EMV-capable terminal that still swipes stripes, or a business that never upgraded its terminal at all, can end up eating the chargeback on a fraudulent transaction that a properly used chip read would have prevented.

In practice this means two things for a merchant: have a terminal that actually reads chips and contactless, and make sure the counter habit is to use it. A terminal sitting there unused doesn't shift any liability back.

Where EMV fits with the rest of your setup

EMV acceptance is table stakes on any current terminal, and it doesn't change what you pay in interchange. What it does is close off the fraud liability that an outdated terminal quietly leaves open. If you're not sure whether your current hardware is fully EMV-certified, or you're overdue for a terminal refresh anyway, see terminal options for what's current, and check your setup against the basics in PCI compliance for small business.

Fair questions

What does EMV actually stand for?

Europay, Mastercard and Visa, the three payment networks that jointly developed the chip standard in the 1990s. The name stuck even though Europay no longer exists as its own company.

How is a chip different from a magnetic stripe?

A magnetic stripe stores fixed card data that's identical every time it's read, which is exactly what makes it easy to skim and clone. A chip generates a new, one-time cryptographic code for every single transaction, so even if that code were intercepted, it can't be reused. That's the core security improvement.

What is the EMV liability shift?

In October 2015, the card networks shifted fraud liability for in-person counterfeit card transactions onto whichever party had the less-secure technology. If a merchant's terminal could accept a chip and the merchant still swiped the stripe instead, and that transaction turns out to be fraudulent, the merchant can be held liable for the chargeback instead of the card-issuing bank. If the terminal has no chip reader at all, the same liability can fall on the merchant regardless of what the customer did.

Does EMV apply to tap-to-pay (contactless) too?

Yes. Contactless payments, including tap-to-pay cards and phone wallets like Apple Pay and Google Pay, use the same EMV chip technology and generate the same one-time transaction codes, just over a short-range wireless connection instead of a physical chip read. Both are treated as EMV-compliant.

Do I need a new terminal to accept chip cards?

If your terminal is more than a few years old or was never EMV-certified, yes. Most terminals sold today accept chip, tap, and swipe in one device, so there's no ongoing tradeoff once it's in place. See terminal options for what's currently deployed.

What should a Washington merchant actually do about this?

Make sure your terminal is EMV-certified and that staff are actually inserting or tapping the card rather than defaulting to a swipe, since that's the behavior the liability shift is built to change. PCI compliance and EMV acceptance both fall under the same basic idea: use the more secure method your terminal already supports. We confirm both are set up correctly as part of every install.

Want this done for you, free?

Send one statement. Plain-English answer in 24 hours.