| Card reader and payment interface | Applicable EMVCo specifications and approval requirements | Confirm the reader’s contact and/or contactless capabilities match the ATM configuration, supported card schemes, and deployment market. EMV approval is relevant to the applicable payment device or component, not automatically to every replacement part. | Current approval details for the exact device or module, interface and firmware; successful integration and transaction testing in the intended configuration. |
| PIN pad and secure payment entry | PCI PTS POI requirements, where applicable; PCI DSS 4.0 controls for the payment environment | Check whether the exact PIN-entry device model and configuration meet the acquirer’s or payment program’s requirements. PCI DSS applies to the security of the cardholder-data environment; it is not a general product certification for ATM spare parts. | Device approval or listing information where required, secure key-management and injection procedures, and documented assessment of the ATM’s impact on the organization’s PCI DSS scope. |
| Cash dispenser, safe, and physical security parts | UL 291, if required by the buyer, insurer, acquirer, or local authority; applicable physical-security requirements | Verify the required safe or equipment classification and whether the replacement preserves the tested assembly’s security characteristics. A component alone does not establish that the complete ATM or safe complies with UL 291. | Documentation for the complete rated assembly, installation instructions, and written confirmation that the change does not invalidate a required rating or insurance condition. |
| Power supply, cables, and electrical assemblies | Electrical safety, electromagnetic compatibility (EMC), and product-marking rules applicable in the destination country | Match input voltage, frequency, output ratings, grounding, connector polarity, temperature range, and required approvals. Requirements and accepted conformity routes differ by market. | Rated specifications, applicable test or conformity documents, correct local markings, and inspection of the installed assembly. |
| Modems, wireless modules, and antennas | National radio-equipment and telecommunications regulations | Check permitted frequency bands, transmit power, antenna configuration, carrier compatibility, and any equipment registration or import conditions. Approval in one country may not be accepted in another. | Destination-market approval or registration evidence where required, plus confirmation that the installed configuration matches the approved configuration. |
| Displays, keypads, and accessibility-related parts | Local accessibility, consumer protection, language, and operating requirements | Confirm visibility, usable controls, required audio or tactile features, supported languages, and any locally mandated screen or transaction notices. | Functional checks against the deployment specification and documented accessibility review for the relevant location. |
| Firmware-dependent or security-sensitive replacements | PCI DSS 4.0 security obligations and the organization’s change-control and vulnerability-management processes | Use supported firmware from an authenticated source, verify compatibility, and assess effects on encryption, logging, patching, remote access, and security controls. A replacement part does not by itself make a system PCI DSS compliant. | Change record, integrity and version checks, security testing, rollback plan, and updated asset or configuration records. |
| Cross-border sourcing and installation | Import, customs, environmental, recycling, and product-compliance rules in the destination market | Check customs classification, documentation, restricted substances, packaging obligations, and end-of-life requirements. Confirm the part is approved for the exact ATM revision and local operating conditions. | Technical datasheet, traceable part and revision details, required declarations, shipping documents, and a locally reviewed installation checklist. |