ICAO, ISO 7810 & EMV Compliance: A Procurement Checklist for Secure Identity Documents

If you are about to issue a tender for national IDs, e-passports, or employee credentials, you already know the scary part: one compliance gap discovered after production can sink an entire program. Cards get rejected at border gates, readers fail to enrol them, or an auditor flags the chip and your rollout stalls for months. This guide walks you through the three standards that decide whether your documents actually pass in the real world — ISO 7810, ICAO Doc 9303, and EMV — and hands you a copy-paste procurement checklist you can drop straight into your RFP.

Why compliance is the make-or-break step in secure ID procurement

Here is the pattern we see over and over: a buyer compares suppliers on price and turnaround, signs, and only later asks whether the cards meet the standards the end system actually requires. By then the tooling is cut and the artwork is approved. Fixing a non-compliant chip or an out-of-spec card body means re-running the whole job.

Compliance is not paperwork you tick at the end — it is the spec that defines what you are buying. Before you talk money, you need to know three things: what physical standard the card body must meet (ISO 7810), whether the document has to be read by government or border systems (ICAO Doc 9303), and whether it also carries payment or secure transaction functions (EMV). Nail these first and every later decision — material, chip, personalization, price — falls into place. Skip them and you are gambling.

ISO 7810 and ISO 7816: the physical and chip foundation

ISO/IEC 7810 is the base standard for the card itself. The format you almost certainly want is ID-1: 85.60 × 53.98 mm, 0.76 mm thick — the exact size of a credit card or driver’s license, so it fits every standard reader, printer, and wallet slot on the planet. The standard also covers how the card behaves physically: bending, torsion, temperature, chemical resistance, and how long the print and card body survive daily handling.

Once you add a contact chip, ISO/IEC 7816 comes into play — it defines the chip’s position, contact pads, and the electrical and command protocol readers use to talk to it. For contactless cards, ISO/IEC 14443 is the equivalent standard for the RFID interface (13.56 MHz). A quick way to think about it: 7810 is the card, 7816 is the contact chip, 14443 is the contactless chip.

What this means for your order: specify the ISO 7810 format explicitly, state the expected card lifespan (a bank card lives ~3 years; a national ID may need 10), and match the chip standard to how the card will be read. A polycarbonate body suits a 10-year government ID; PVC is fine for a 2–3 year access badge.

ICAO Doc 9303: passports and IDs that clear the border

If your document has to be recognised by another government — passports, national eID, visas, travel documents — ICAO Doc 9303 is non-negotiable. It is the specification behind Machine Readable Travel Documents (MRTDs). Two parts matter most to buyers: the Machine Readable Zone (the two or three lines of OCR-B text at the bottom of a passport page) and, for e-documents, the contactless chip that stores the holder’s data and a facial or biometric image.

The chip side brings a security stack you should ask your supplier about by name: Basic Access Control (BAC) or the stronger Supplemental Access Control (SAC/PACE) to stop skimming, Passive Authentication to prove the data has not been altered, and optionally Active Authentication or EAC to protect fingerprints and iris data. If any of these are missing, the document may simply not be accepted at automated border gates.

Practical takeaway: for any cross-border or government-recognised document, put “must comply with ICAO Doc 9303, current edition” in the RFP, and ask the supplier which access-control and authentication mechanisms they implement — not just “yes, it’s ICAO compliant.”

EMV: when your ID card also has to pay

EMV (Europay, Mastercard, Visa) is the standard behind chip-and-PIN and contactless payment cards. You need it whenever the card does more than identify someone — campus cards with a stored-value wallet, transit-plus-payment cards, government benefit or disbursement cards, or corporate cards with a purchasing function.

EMV compliance is stricter than a physical standard because it involves certification: the chip, the card operating system, and the applet must be certified against EMVCo specifications, and card issuance usually happens under a scheme (Visa/Mastercard/UnionPay) with its own approval process. This is not something a general card printer can improvise — it requires certified products and often a certified personalization bureau.

If payment is anywhere on your roadmap, flag it at the RFP stage. Ask whether the supplier offers EMVCo-certified card bodies and chips, whether they can handle scheme certification, and whether the same card can carry both your ID application and the payment applet (dual-application cards are common but need to be planned, not bolted on later).

Your pre-order compliance checklist — and how to verify a supplier

Here is the part you can actually reuse. Before you sign anything, run the document through this checklist. If a supplier cannot answer these clearly and in writing, treat it as a red flag.

  • Card format: Confirmed ISO 7810 ID-1 (or your required format) with stated thickness and durability class?
  • Chip interface: Contact (ISO 7816), contactless (ISO 14443), or dual — and does it match the readers already deployed?
  • Lifespan: Rated service life stated (e.g. 3, 5, or 10 years) and matched to the material (PVC / PETG / polycarbonate)?
  • Cross-border use: If applicable, ICAO Doc 9303 compliance confirmed, with named access-control (BAC/PACE) and authentication mechanisms?
  • Payment function: If applicable, EMVCo certification and scheme approval path confirmed?
  • Security features: Required overt/covert features (holograms, UV, microtext, guilloche) listed and matched to your threat model?
  • Documentation: Test reports, certificates, and sample cards available for your team to verify before mass production?

How do you actually verify a claim? Ask for the certificate numbers and check them against the issuing body. Request pre-production samples and run them through your own readers and enrolment system — not the supplier’s demo. And favour a factory that manufactures in-house over a reseller, so the compliance chain has one accountable owner rather than a hand-off you can’t audit.

Conclusion

Compliance is the cheapest insurance in a secure ID program — as long as you buy it up front. Decide early which standards your document must meet (ISO 7810 for the body, ICAO Doc 9303 for border-ready documents, EMV for payment), write them into your RFP, and make suppliers prove each claim with certificates and samples. Do that and the rest of the project runs on rails.

GENUINE has manufactured secure cards, RFID products, and identity documents since 2005, with in-house control over material, chip, and personalization. If you want a second set of eyes on your spec, we will review your requirements against ISO 7810, ICAO 9303, and EMV and send you free samples to test on your own systems. Request your compliance review and free samples and start your program on solid ground.

Table of Contents

This is the heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Scroll to Top
Request A Qute