What is tokenization in payments?
Tokenization in payments is the replacement of the card number, the primary account number (PAN), with a substitute value called a token. A stolen token is of little use, because it works only for a set merchant, device or payment type. EMVCo standardizes these payment tokens; PCI DSS sets the security rules. The German term is Tokenisierung.
Payment tokenization in brief
| Term | Payment tokenization, also card tokenization. German: Tokenisierung von Kartendaten. |
|---|---|
| What is replaced | The primary account number (PAN). Card security codes and PINs may not be tokenized (PCI DSS Requirement 3.2). |
| Standard | EMV Payment Tokenisation Specification, Technical Framework v2.4, published July 9, 2026 (EMVCo). |
| Security rules | PCI DSS; PCI DSS Tokenization Guidelines, August 2011 (PCI Security Standards Council). |
| EU law | Strong customer authentication under Article 97 of Directive (EU) 2015/2366 (PSD2). The directive does not mention tokens. |
| Supervisors | BaFin in Germany, FMA in Austria for payment service providers. Switzerland is outside PSD2. |
How does tokenization work in payments?
Payment tokenization works by issuing a token in place of the card number and limiting where the token can be used. EMVCo, which publishes the EMV specifications, describes the EMV payment token as "a unique alternative value" that "is constrained in how it can be used. For example, to a specific merchant, device or payment scenario" (EMVCo).
In a 2022 article EMVCo follows the token on its way: it travels from the point of purchase to the acquirer and across the payment networks to the card issuer, which authorizes the payment. A token service provider issues the tokens, and EMVCo assigns each token service provider a code. A payment account reference (PAR) links transactions made with tokens to the PAN. After a data breach, the issuer can replace the tokens for a specific merchant or device, "often without any interaction with the cardholder", and needs to replace fewer cards (EMVCo, March 31, 2022).
What does a credit card token look like?
A credit card token can have many sizes and formats, with digits only or with letters. The PCI Security Standards Council gives a credit card tokenization example: the PAN 4959 0059 0172 3389 becomes the token 729129118523184663129. Another format keeps the first six and the last four digits of the PAN: 5994 0059 0172 3383 becomes 599400x18523mw4cw3383 (PCI SSC, August 2011).
A single-use token stands for one transaction; a multi-use token stands for one PAN across many transactions. Tokenization of a debit card works the same way, because EMV tokens apply "in any environment which currently uses a PAN".
What is the difference between tokenization and encryption?
The difference between tokenization and encryption is whether the card number can be computed back from the value. For a token, the PCI guidelines require that recovering the PAN "must not be computationally feasible knowing only the token". A token made with reversible encryption "is an encrypted PAN" and may fall under further PCI DSS rules. Whether a value counts as a token or as encrypted data depends on how it was generated.
Detokenization is the reverse process, redeeming a token for its PAN. Tokenization and detokenization should happen only inside a clearly defined tokenization system, the guidelines say. The pairs of tokens and PANs sit in a card data vault, which "often presents the most attractive target for attackers".
How does tokenization help with PCI compliance?
Tokenization reduces the systems that PCI DSS covers, because a merchant that stores tokens holds less card data. It does not end the duty. The PCI Security Standards Council (PCI SSC) explained in 2011 that tokenization solutions "do not eliminate the need to maintain and validate PCI DSS compliance". Tokens that can start a payment on their own, which the guidelines call "high-value tokens", may stay in scope for PCI DSS even though they reveal no PAN.
How does payment tokenization differ from asset tokenization?
A payment token replaces a card number and has no value of its own; an asset token on a blockchain is the asset or claim itself. The International Monetary Fund (IMF) defines tokenization as "the creation of assets or representations of assets on a shared, trusted, and programmable ledger, usually a blockchain" (IMF, December 4, 2025). In banking, the word has both meanings. A bank tokenizes card numbers to protect card payments, and it can tokenize bonds or deposits to trade and settle them on a ledger. See what is tokenization of assets? and what are tokenized deposits?
Payment tokenization in Germany, Austria and Switzerland
PSD2, the EU directive on payment services, does not mention tokens. The rule it sets for card payments is strong customer authentication: Article 97 requires it when a payer starts an electronic payment. For remote payments the authentication must link the payment to a specific amount and payee. Payment service providers must also protect the confidentiality and integrity of personalized security credentials. Germany implements this in section 55 of the Payment Services Supervision Act (ZAG), with BaFin as supervisor (section 4 ZAG). Austria implements it in section 87 of the Zahlungsdienstegesetz 2018, with the FMA as supervisor (section 88).
Switzerland is outside the EU, so PSD2 does not apply there. PCI DSS is an industry standard, not a law; the PCI guidelines tell merchants to ask their acquirer or the payment brands about specific requirements for tokens.
The Eurosystem oversees card payment schemes and electronic wallets under its PISA framework, which the ECB in Frankfurt published on November 22, 2021. It applies from November 15, 2022 and also covers digital payment tokens (ECB, November 22, 2021).
This page gives no legal advice.
Sources
- EMVCo: EMV Payment Tokenisation, with the Technical Framework v2.4 of July 9, 2026, read September 29, 2026
- EMVCo: EMV Payment Tokenisation: What, Why and How, March 31, 2022
- PCI Security Standards Council: Information Supplement: PCI DSS Tokenization Guidelines, August 2011
- International Monetary Fund: Understanding Stablecoins, Departmental Paper 2025/009, December 4, 2025
- European Central Bank: Eurosystem publishes new framework for overseeing electronic payments, November 22, 2021
- European Union: Directive (EU) 2015/2366 on payment services in the internal market, November 25, 2015
- Germany: Zahlungsdiensteaufsichtsgesetz (ZAG), section 55, read September 29, 2026
- Austria: Zahlungsdienstegesetz 2018 (ZaDiG 2018), read September 29, 2026
About Finance Loop: payment tokenization
Finance Loop is the meeting place for people at card issuers, acquirers, payment service providers and merchants who secure card payments. It connects the finance, IT and AI communities in Frankfurt, where the ECB published PISA, its oversight framework for card schemes and electronic wallets, which also covers digital payment tokens.
Finance Loop is an official media partner of Capital & Code 2026 at SPARK Europe in Frankfurt. The program covers payments and commerce, agentic payments and retail payments, with speakers from Mastercard and the Deutsche Bundesbank.