CQM Exceptions for Small Volume Products
Introduction
Generally, Mastercard requires that:
- Every Card Holder Device that can be CQM certified, is CQM certified before it is being marketed to Mastercard issuers.
- Every component of a cardholder device that can be CQM certified, is CQM certified before it is being marketed to Mastercard issuers.
To better accommodate small volume products and their components, and to limit the financial impact of the requirement to undergo CQM certification for vendors of products only being produced in small volume, which are typically innovative products, Mastercard has defined special rules for small volume products.
These special rules and their conditions are outlined below.
Definitions
For the purpose of this section the following definitions apply:
Term | Explanation |
anticipated annual production volume | This is the greatest number of the following: Note: "number of products of this type" refers to the total number of products of this type and not only to the number of products of this type dedicated as or for Mastercard branded products. |
CQM certifiable | A product or component is "CQM certifiable" if a set of CQM requirements exists that apply to this product or component. |
CQM certifiable product CQM Product | A "CQM certifiable product", also referred to as a "CQM Product" is a Cardholder Device, that is ready for personalization or has been personalized. CQM products as defined in the CQM Requirements are: ⦁ ICC – integrated circuit card ⦁ IAC – interactive integrated circuit card ⦁ P – personalized ICC or IAC |
CQM certifiable component CQM Component | A "CQM certifiable component", also referred to as a "CQM Component" is a component of a CQM Product that has a corresponding set of requirements defined in the CQM Requirements document. CQM Components as defined in the CQM Requirements document are: ⦁ IC – integrated circuit ⦁ ICM – a module containing an IC for implantation into a ICC ⦁ iacICM – a module containing an IC for implantation into an IAC ⦁ BSM – a module containing a biometric sensor are for implantation into an IAC ⦁ IL – an inlay containing an antenna for producing a CB or a ICC ⦁ iacIL – an inlay for producing an IAC |
Anticipated annual production volume of less than 5000 units
The vendor shall audit their subcontractors of CQM certifiable components for compliance with the CQM requirements.
The Vendor’s operations applicable to this CQM Product are not required to undergo CQM audits. The Vendor may request a CQM Audit of these operations.
The Vendor’s subcontractors and suppliers of CQM certifiable components of such product are not required to undergo CQM audits. The Vendor may request CQM Audits of their subcontractors and suppliers of CQM certifiable components of such product.
The product shall be covered by a CSI letter before the Vendor ships Mastercard branded units.
The vendor does not receive a CQM label for this product, unless the vendor decides to voluntarily comply with the rules for an annual volume between 5000 and 50000 units/a, or with the rules for an annual volume of more than 50000 units/a.
Annual volume of at least 5000 but less than 50000 units/a
The vendor shall audit their subcontractors of CQM certifiable components, and make the audit reports available to their CQM Auditor upon request.
The Vendor’s operations applicable to this product are required to undergo regular CQM audits.
The Vendor’s subcontractors and suppliers of CQM certifiable components of such product are required to undergo CQM remote audits; the remote audit should consist of a 4 hour review call to verify the operations conducted by the supplier or subcontractor to provide CQM certifiable components for this product are conducted in line with the applicable CQM requirements; the auditor may increase the time needed for complex or multiple components. The Vendor may request on-site CQM Audits of their subcontractors and suppliers of CQM certifiable components of such product.
Where CSI is required for the type of product, the product shall be covered by a CSI letter before shipping Mastercard branded units.
The vendor does receive a CQM label for this product.
Annual volume of at least 50000 units/a
The vendor shall audit their subcontractors of CQM certifiable components, and make the audit reports available to their CQM Auditor upon request.
The Vendor’s operations applicable to this product are required to undergo CQM audits.
The Vendor’s subcontractors and suppliers of CQM certifiable components of such product are required to undergo CQM audits.
Where CSI is required for the type of product, the product shall be covered by a CSI letter before shipping Mastercard branded units.
The vendor does receive a CQM label for this product.
When is CSI required?
CQM requirements #3100#, #3110#, #3120#, #3130# provide some requirements in which cases a CSI letter is required to be obtained by CQM.
Mastercard's CSI team may have defined additional requirements when a CSI letter is required.
In case of doubt, contact CSI Security (csi.security@mastercard.com).