Four rules cover a retail ATM: EMV chip cards, the TR-31 key-block standard for the PIN pad, the ADA accessibility standards, and the Reg E fee notice. A new machine from Genmega or Hyosung already meets all four. Only one of them can actually stop a machine from processing, and even that one arrived years late and without a single shutdown day.
If you have heard that ATM compliance is a minefield, you have mostly heard it from people selling upgrades. This guide explains what each rule actually requires, what really happens if a machine falls short, and how to check a specific machine yourself. None of it is legal advice. It is the practical picture from operating machines.
Is my ATM legally required to be EMV compliant?
No. EMV is not a law and not a network mandate. It is a liability shift. Since October 2016 for Mastercard and October 2017 for Visa, if a chip card is used at an ATM that can only read the magnetic stripe and the transaction turns out to be counterfeit fraud, the ATM owner pays the chargeback instead of the card’s bank. A non-EMV machine still processes normally.
The card networks chose this approach on purpose. Rather than a deadline with shutdowns, they gave operators a risk-based choice: upgrade and hand fraud liability back to the issuer, or don’t and carry it yourself.
What that risk looks like depends on the site. Counterfeit-card fraud clusters at unattended, high-traffic, easy-to-reach machines. An ATM inside a salon, where staff are on the floor all day and regulars make up the customer base, sees little of it. Plenty of older mag-stripe machines are still processing at locations like that.
The honest caveat is that the exposure only runs one direction, and one fraud ring working a machine can erase months of surcharges. That is why the practical answer is to buy EMV on anything new — it is standard on every current retail machine anyway — and to weigh the risk on an existing mag-stripe machine by its location rather than by a sales pitch.
What is TR-31, and will it shut my ATM down?
TR-31 is a standard for how the encryption keys in your PIN pad are packaged when they are loaded. The PCI PIN security rules required ATMs to use it from January 1, 2025. It is the one requirement that can stop a machine, because a processor can decline to key a PIN pad that does not support it — but it is enforced processor by processor, on no single cutoff date.
The deadline itself has moved more than once. When the PCI Security Standards Council introduced key blocks in 2014, it phased them in, and the phase covering ATMs was originally due June 1, 2023. In August 2020, citing the COVID-19 pandemic among other factors, it pushed that phase back to January 1, 2025, and the network-connection phase before it from June 2021 to January 2023.
When January 2025 arrived, machines did not go dark across the country. Processors have been working non-compliant machines off their networks on their own schedules, and many allowed them to keep transacting while owners upgraded. That window is narrower now than it was on the deadline, and it will not stay open forever. The practical move is to ask your processor where your specific machine stands, instead of assuming either extreme.
For most machines built in the last decade, the fix is small. On a Genmega with an EPP-B3 or EPP-B5 PIN pad, it is a software update. On older pads it is a keypad replacement. Hyosung’s path runs through the EPP 8000R or EPP X1 PIN pad at current firmware. The machines that genuinely aged out are the old platforms — the basic Hantle 1700 and older 4000-series machines, the Hyosung NH and MB series — which most operators had already retired.