← HomeREP27All categories

Payment terminals, POS and kiosk hardware

Electrical and electronic

In short
Article 4 economic operator for the hardware, plus an Article 27 GDPR representative where the vendor processes cardholder or user data

Who has to appoint one

Manufacturers outside the Union placing payment terminals, self-service kiosks or card readers on the EU market. The hardware obligations sit with the manufacturer; the payment service obligations sit with the payment institution, which is a separate regulated entity, and vendors frequently confuse the two.

Thresholds and exemptions

None for the hardware. PSD2 authorisation applies to the payment service provider rather than to the terminal maker, unless the vendor also handles funds or account access.

What must appear on the label

CE marking, manufacturer and EU representative details, model and serial number, radio parameters where wireless, and from December 2027 the CRA support period and vulnerability contact point.

Marketplace fields

Acquirers and payment schemes impose PCI PIN Transaction Security approval as a commercial precondition, which is a scheme requirement rather than EU law but is decisive in practice: an unapproved terminal cannot be deployed regardless of CE marking.

Documentation you must hold

EU declaration of conformity, technical file, radio and safety test reports, cybersecurity documentation under EN 18031 and, from 2026, the CRA vulnerability handling process and SBOM. Where the vendor operates a management cloud, the Article 30 record, the Article 27 designation and the transfer mechanism.

Standards and testing

EN IEC 62368-1 for safety, the applicable radio standards, EN 55032 and EN 55035 for EMC, EN 18031 for the RED cybersecurity requirements, and separately PCI PTS evaluation for the PIN entry device.

Language requirements

Instructions and merchant-facing documentation in the language of each member state of deployment.

When it applies

Hardware documentation before placing on the market. CRA vulnerability reporting from 11 September 2026 and the full regime from 11 December 2027, which for terminals with long deployment lifecycles means the support period must be planned now.

How long records are kept

Ten years for technical documentation, or the CRA support period if longer, which for payment hardware is typically the full deployment life.

What happens if you do not comply

Withdrawal and customs refusal for the hardware. Under the CRA, up to €15 million or 2.5% of turnover. Separately, a vulnerability in deployed terminals is a reputational and contractual event with acquirers that usually exceeds the regulatory cost.

Who enforces it

Market surveillance authorities and radio regulators, CSIRTs for CRA reporting, data protection authorities where personal data is processed, and national competent authorities for the payment service side.

Where the boundary lies

Being CE marked and PCI approved does not make the vendor a payment institution, and conversely holding a PSD2 licence does not exempt the hardware from product conformity. Long deployment cycles make the CRA support period the hardest commitment in this category, because terminals stay in the field for a decade.

Questions we are asked

Is PCI approval a legal requirement in the EU?
No, it is a scheme requirement imposed by the card networks and acquirers. It is commercially decisive but does not replace CE marking or the CRA obligations.
Who reports a vulnerability in deployed terminals?
The manufacturer, under Article 14 CRA from September 2026, within 24 hours of becoming aware that it is being exploited.
Art. 4 economic operator + EU representative · from €290 / year

Who signs for you
EU representative Europe Services, SE — Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic
UK representative REP27 LTD — Unit 82a James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom

Talk to usCheck your category