Brightsight is pleased to announce that its Meyreuil laboratory has been recognized by PayCert as an authorized evaluation laboratory for the ECPC Evaluation of CPACE Application according to the eSecCPACE methodology.
This milestone enables Brightsight to perform independent security evaluations for CPACE payment applications under the eSecCPACE certification framework. The recognition follows a successful assessment process, further strengthening Brightsight's position as a trusted provider of payment security evaluation services.
The addition of eSecCPACE further expands Brightsight's portfolio of payment security services, providing customers with access to security evaluation expertise across a broad range of payment and certification schemes.
What is the eSecCPACE Security Framework?
As digital and contactless payments continue to evolve, robust security evaluation frameworks are essential to maintaining trust in payment technologies.
The European Card Payment Cooperation (ECPC) is the organization responsible for defining, maintaining, and evolving the CPACE ecosystem. CPACE (CPA Contactless Extensions) is a payment specification framework covering payment cards, mobile payment applications, and contactless kernels.
To ensure implementations meet strict security objectives, ECPC established the eSecCPACE methodology to evaluate CPACE applications on payment cards and secure devices.
PayCert, acting as the certification body delegated by ECPC, oversees the certification process, authorizes evaluation laboratories, and issues official certificates based on evaluation results.
Benefits of eSecCPACE Security Evaluations with Brightsight
With this authorization, Brightsight can now support vendors, payment solution providers, secure element developers, and card manufacturers seeking eSecCPACE security evaluations of CPACE applications.
Key advantages for customers include:
- Global expertise: access to a globally recognized payment security evaluation organization.
- Specialized testing: advanced penetration testing capabilities, including side-channel analysis and fault injection attacks.
- End-to-end guidance: direct technical support throughout the entire eSecCPACE evaluation process.
Why choose Brightsight?
The Brightsight laboratory in Meyreuil brings together experienced security evaluators, specialized testing facilities, and the broader technical capabilities of the Brightsight group.
This authorization acknowledges the competence of the local team, the maturity of the lab's methodology, testing infrastructure, and its rigorous quality management processes.
"I am proud of the work accomplished by our team to achieve this recognition. Becoming an authorized eSecCPACE evaluation laboratory is an important milestone that demonstrates both our technical expertise in payment security and our ability to support emerging certification schemes with the same level of rigor our customers already expect from Brightsight.
This recognition enables us to support vendors seeking security evaluations under the eSecCPACE framework and further strengthens our portfolio of payment security evaluation services."
Jérémie Delpech
Location Manager, Brightsight France (Meyreuil Laboratory)
Ready to certify your CPACE application?
Looking for an authorized evaluation laboratory to evaluate your CPACE payment solution against the eSecCPACE security requirements? Contact Brightsight’s security experts today to start your eSecCPACE evaluation process.


