Hide last authors
Uwe Trueggelmann 18.1 1 = Q0) Does CQM only care about production? =
2
3 Within CQM the following principles apply:
4
5 1. All relevant life cycle steps of a CQM certifiable product or component, including development, qualification, and quality monitoring activities, and all production steps, must be conducted by CQM certified entities.
6 1. It must not be possible to bypass CQM Certification by subcontracting parts of the life-cycle, for example only production, to a CQM certified subcontractor.
7 1. Unless the Vendor of a product is purely a reseller (see Q7), the Vendor of the product must carry their own CQM label covering the activities they conduct with respect to the life-cycle of the product or component they are selling to Mastercard issuers or CQM certified customers.
8
SuperUwe Trueggelmann 3.1 9 = Q1) My card is made of another material but newly produced PVC. How does CQM apply? =
SuperUwe Trueggelmann 1.2 10
11 CQM applies independently of the card material.
12 Independent of the card material, your card is expected to comply with all applicable CQM requirements.
13 If your card made from another material is not conform with at least one CQM requirement, then see Q2.
14
SuperUwe Trueggelmann 3.1 15 = Q2) My card is not fully compliant with all applicable CQM requirements =
SuperUwe Trueggelmann 1.4 16
SuperUwe Trueggelmann 4.1 17 If your card is not fully compliant with all applicable CQM requirements, then you need to follow this procedure:
SuperUwe Trueggelmann 1.2 18
SuperUwe Trueggelmann 4.1 19 1. You complete the qualification testing as required by the applicable product worksheet in the cqmAP form to determine your new product's level of conformity with the applicable CQM requirements.
20 1. You create a report containing the results, and you fill in the blue section of the applicable product worksheet of the cqmAP form, indicating the requirements your product is compliant with, and those where it is not.
21 1. You contact Mastercard's CSI team to report that you have a new product that is not fully conform with the applicable CQM requirements, and that conclusively you need to obtain a CSI letter for this product. Include the cqmAP and your own qualification report.
22 1. The Mastercard CSI team will tell you which information they need to progress your request and help you with the process.
23
SuperUwe Trueggelmann 1.4 24 Once you have obtained the CSI Letter, during a CQM Audit you might need to present it as evidence that you have notified the non-conformity to Mastercard's CSI team and that Mastercard has evaluated the resulting risk.
SuperUwe Trueggelmann 1.2 25
SuperUwe Trueggelmann 3.1 26 = Q3) Is the supplier of my components, as considered within the CQM Scheme, a Component Vendor or a Subcontractor? =
27
SuperUwe Trueggelmann 1.4 28 As considered within CQM:
SuperUwe Trueggelmann 6.1 29
30 * A Vendor has control of the product (including Components) the Vendor supplies, and of the related development, qualification, and manufacturing processes.
31 * A subcontractor is an entity that produces a component primarily according to the instructions received from their customer.
32
Uwe Trueggelmann 19.1 33 ==== Example 1 ====
34
SuperUwe Trueggelmann 6.1 35 An example for a Vendor is Company A who designs an IC, an ICM containing the IC, and an IL that works with the IC, and sells the ICM together with the IL to card manufacturers so they can produce cards.
Uwe Trueggelmann 19.1 36
37 ==== Example 2 ====
38
SuperUwe Trueggelmann 4.1 39 An example for a subcontractor is Company B who embeds wire into a sheet of plastic according to a drawing and material specification received from their customer, for example as a subcontractor to Company A.
40
Uwe Trueggelmann 19.1 41 ==== Example 3 ====
42
43 Card manufacturer M procures an iacICM with ISO/IEC 7816-2 contacts, a BSM with a fingerprint sensor, and an iacIL containing the antenna and to connect the iacICM and the BSM from component supplier S. S is CQM certified for iacICM, BSM, and iacIL. S has developed and qualified the iacICM, BSM, and iacIL. S produces iacICM, BSM, and iacIL themselves, or uses subcontractors.
44
45 M's CQM Audit only needs to address M's ability to produce IAC from these components, including verification that S is CQM certified for these components. M only receives a CQM label for IAC.
46
47 S's CQM Audit must have included iacICM, BSM, iacIL; S must maintain CQM labels for iacICM, BSM, iacIL.
48
49 S is a Component Vendor for iacICM, BSM, iacIL.
50
51 ==== Example 4 ====
52
53 Card manufacturer M procures an iacICM with ISO/IEC 7816-2 contacts, a BSM with a fingerprint sensor, and an iacIL containing the antenna and to connect the iacICM and the BSM from component supplier S.
54
55 In addition one of the below points is true:
56
57 * S is not CQM certified for iacICM, BSM, or iacIL,
58 * M had significant involvement in specifying, developing, or qualifying the iacICM, BSM, or iacIL.
59
60 M's CQM Audit must include IAC and each component where
61
62 * S is not CQM certified for, or
63 * where M had significant involvement in specifying, developing, or qualifying the component,
64
65 and M receives CQM labels for IAC and each of the components included in M's CQM Audit.
66
67 S's CQM Audit must have include the components M is not audited for; S must maintain CQM labels for the components M is not audited for.
68
69 S is a Subcontractor for the components M is not audited for.
70
SuperUwe Trueggelmann 4.1 71 = Q4) Do Subcontractors have to have their own CQM Certificate? =
72
73 It depends on what the Subcontractor is providing.
74
75 Currently the suppliers of the following CQM Components are required to have their own CQM Certificate:
76
77 * IC
78 * ICM
SuperUwe Trueggelmann 15.1 79 * --iacICM--
Uwe Trueggelmann 22.1 80 * --BSM--
SuperUwe Trueggelmann 4.1 81 * IL
82 * CB
83 * ICC
SuperUwe Trueggelmann 15.1 84 * --iacIL--
SuperUwe Trueggelmann 4.1 85 * IAC
86
SuperUwe Trueggelmann 6.1 87 Note: this list is a DRAFT, under review, and not authoritative in any way!
SuperUwe Trueggelmann 4.1 88
SuperUwe Trueggelmann 6.1 89 Companies conducting certain sub processes as a subcontractor, for example providing wafer backside processing services to an IC or ICM Vendor, might not be required to maintain their own CQM Certificate. But it might be beneficial for them and for their customers if they would. See Q5) and Q6)
SuperUwe Trueggelmann 4.1 90
91 = Q5) Does a Subcontractor's production have to be CQM audited? =
92
SuperUwe Trueggelmann 17.1 93 Within CQM every production process that is listed in the cqmAP of the related product, the product and process development processes, the qualification process, and the quality monitoring processes must undergo a CQM Audit.
SuperUwe Trueggelmann 4.1 94
95 This is independent of the production activity being conducted in a facility owned by the vendor (for example Company A, the owner and seller of an IC, an ICM, and an IL that works with the IC), or in a facility owned by a subcontractor (for example Company B, providing subcontracted wire embedding services to Company A, with the IL having been developed and qualified by Company A, and Company B producing according to antenna drawing and material specification provided by Company A).
96
97 There is no significant difference in the way the IL production processes are assessed, whether they would be conducted in Company A's IL production, or in Company B's.
98
99 In both cases the facility producing the IL will be listed on Company A's CQM Certificate.
100
Uwe Trueggelmann 22.1 101 See CQM requirements #0606#, #0607#, and #0608# for more information.
102
SuperUwe Trueggelmann 4.1 103 = Q6) Does it matter if a Subcontractor is CQM certified? =
104
105 While subcontracted services that are part of the production processes as outlined on the related product worksheets in the cqmAP, may be permitted to be subcontracted to a facility that is not holding their own CQM Certificate, there is a difference how the subcontracted services will be assessed as part of the Vendor's CQM Audit.
106
107 Assuming that Company B provides as a subcontractor wire embedding services to Vendor A, and Vendor A has developed and qualified the IL, and provides Vendor B with an antenna drawing and material specification:
108
109 1. If the subcontractor Company B maintains their own CQM Certificate covering IL production, then during the audit of Vendor A as an IL Vendor, the effort for the auditing of the subcontracted production at Company B may be reduced to an app. 4h remote audit to verify that Company B applies their CQM certified processes to the wire embedding services subcontracted by Company A.
110 1. If the subcontractor Company B does not maintain their own CQM Certificate covering IL production, then during the audit of Vendor A as an IL Vendor, the subcontracted production at Company B shall be audited as if it were a separate IL manufacturing site of Company A, and hence must undergo a complete CQM Audit, except for the processes conducted by Company A, in our example development and qualification of the IL.
SuperUwe Trueggelmann 7.1 111
Uwe Trueggelmann 22.1 112 Note: The times above are the times to assess the Vendor's Subcontractor so that the Vendor can receive the respective label. These are not the times needed if the Subcontractor wants to acquire their own CQM label.
SuperUwe Trueggelmann 10.1 113
Uwe Trueggelmann 22.1 114 See CQM requirements #0606#, #0607#, and #0608# for more information.
115
Uwe Trueggelmann 21.1 116 == Q7) I am purely a Reseller. Do I have to have to have a CQM label for the products I resell? ==
SuperUwe Trueggelmann 10.1 117
SuperUwe Trueggelmann 12.1 118 If the product you are reselling is completely developed, qualified, produced, and its quality monitored by an entity that has a CQM label for this product, then you do not need to have a CQM label for this product.
119
SuperUwe Trueggelmann 16.1 120 If you have any significant input into, or conduct the design, the qualification, the production, or subsequent testing of the product, you are not purely a reseller and you need to have a CQM label for this product.
SuperUwe Trueggelmann 12.1 121
122 = Q8) I have a CSI letter for my Product. Does CQM still apply? =
123
SuperUwe Trueggelmann 11.1 124 CSI is not a replacement for CQM. CSI is mostly independent from CQM.
SuperUwe Trueggelmann 10.1 125
126 CQM will verify if certain things are covered by a CSI letter:
127
128 * Certain products must be covered by a CSI letter, in addition to be covered by a CQM label.
129 * Non-conformities determined during CQM qualification, that the vendor fails to remedy.
130
131 Both cases require that the vendor obtains a CSI letter, but this does not replace CQM certification, and the need for the vendor to conduct full qualification testing against the applicable CQM requirements.
132
Uwe Trueggelmann 20.1 133 = Q9) When is CSI required? =
134
135 CQM requirements #3100#, #3110#, #3120#, #3130# provide some requirements in which cases CQM requires that a CSI letter is obtained for a product or component.
136
137 Mastercard's CSI team may have defined additional requirements when a CSI letter is required.
138
139 In case of doubt, contact [[CSI Security (csi.security@mastercard.com)>>path:mailto:csi.security@mastercard.com]].
140
SuperUwe Trueggelmann 10.1 141
© 2024 TruCert Assessment Services Inc.
V00-01