EPI External Security Evaluator: usd Receives Accreditation from the European Payments Initiative

24. March 2025

usd AG has been accredited as a Security Evaluator by the European Payments Initiative (EPI). We are now authorized to carry out security evaluations for the certification of participating companies.

About EPI and Wero

EPI is an association of 16 issuers and acquirers with a common goal: the introduction of a standardized digital payment service for all European companies and citizens.

Since July 2024, customers of participating banks in Germany have been able to send and receive money in real time using the “Wero” wallet app. From 2025, payments will also be possible online via Wero and in retail stores from 2026. “Wero will strengthen European sovereignty in payment transactions,” Joachim Schmalzl, member of the Management Board of the German Savings Banks Association (DSGV) and Chairman of the Supervisory Board of EPI, told dpa

Participation requires regular security certifications

EPI requires regular security certifications from banks and financial service providers who wish to enable their customers to pay or accept payments via Wero. Depending on their role in the payment process, banks or financial service providers, issuers or acquirers receive such certification either through a self-certification or a security assessment carried out on site by an accredited auditor (EPI Security Evaluator).

usd as your EPI Security Evaluator

As an EPI-accredited External Security Evaluator, we carry out audits for you. We are of course also available to advise you at any time - both in preparation for the security assessment and during your self-assessment.

“As a long-standing auditor and consultant for information security in the payment industry and financial sector, accreditation as an EPI Security Evaluator is a logical step for us. We look forward to putting our experience and expertise to good use in supporting our customers with this new development in the payment industry.”


Torsten Schlotmann, Head of PCI & Payment Security

Also interesting:

Security Advisories on PRTG Network Monitor

Security Advisories on PRTG Network Monitor

The pentest professionals at usd HeroLab examined the PRTG Network Monitor web application as part of web application pentests and identified several vulnerabilities. Two vulnerabilities relate to cross-site scripting (XSS), which allows attackers to inject JavaScript...

PCI Secure Software Standard v2.0: What You Should Know

PCI Secure Software Standard v2.0: What You Should Know

On 15 January 2026, the PCI Security Standards Council (PCI SSC) released version 2.0 of the PCI Secure Software Standard. This is the first comprehensive revision since the introduction of the standard. Insight into the Key Changes The new version streamlines the...

Part-IS and ISO 27001: How to Leverage Synergies for Your Compliance

Part-IS and ISO 27001: How to Leverage Synergies for Your Compliance

On 22 February 2026, the EU Regulation Part-IS for aviation organizations will come into force. They must manage information security risks in a way that best protects civil aviation safety. Many already rely on an ISMS according to ISO 27001 – but is that enough for...

Categories

Categories