[ KPCS · Handbook v1.0 · 2026-09-06 ]
KPCS candidate handbook
KeyLab Certified Payment Cryptography Specialist (KPCS) is a certification issued by KeyLab. This handbook is the contract between KeyLab and a candidate: what the exam is, how it is scored, what the certificate means, and what happens in the cases nobody likes to think about. It applies to cohort 1, which opens on 5 December 2026.
Back to the course.
1. What KPCS certifies
KPCS attests that the holder can perform, on a working bench, the six competencies of the syllabus: PIN and PIN blocks; Key management and key blocks; payShield host commands; EMV cryptograms; DUKPT end to end; KMIP for payments.
It is a certification of skill, not of attendance. Watching the lessons is not a requirement to sit the exam and does not by itself earn anything.
KPCS is issued by KeyLab alone. It is not a PCI SSC, EMVCo, Visa, Mastercard or Thales credential, is not mapped to any of their programmes, and claims no accreditation from any body. What it attests is what this handbook says and nothing more.
2. Who may sit the exam
Anyone holding a KPCS seat or an exam-only purchase, from the day the cohort opens (5 December 2026) until their 12 months of access end.
There is no formal prerequisite. The syllabus assumes familiarity with a PIN block and with the vocabulary of card payments; the exam does not re-teach it.
The exam is taken under the KeyLab account that made the purchase. The name on that account at the time of passing is the name on the certificate.
3. Exam format
Two parts, taken in one sitting of 120 minutes in the KeyLab bench, in a browser.
- Part A: 60 questions, multiple choice and short answer, drawn from a bank per domain according to the blueprint weights. Each candidate receives a different draw.
- Part B: 6 bench tasks, one per domain, each a thing the candidate produces on the simulator — a key block, a translated PIN block, a cryptogram, a working key, a KMIP message, a diagnosis of a trace. Inputs are generated per candidate; the bench grades the result deterministically, the way it checks the course exercises.
Pass rule: at least 70% on Part A and at least 4 of the 6 tasks correct in Part B. Both conditions, in the same sitting.
Results for Part A and Part B are shown at the end of the sitting. The certificate is issued within 24 hours, once the sitting has been reviewed for integrity (section 6).
4. Blueprint
Domains, weights and the number of Part A questions each contributes. Every domain also contributes one Part B task. The objectives of each domain are the lessons of the corresponding module.
- PIN and PIN blocks: 15% · 9 questions · task: Build and translate a PIN block
- Key management and key blocks: 20% · 12 questions · task: Wrap a key into a TR-31 block
- payShield host commands: 20% · 12 questions · task: Read a payShield trace
- EMV cryptograms: 20% · 12 questions · task: Verify an ARQC and issue the ARPC
- DUKPT end to end: 15% · 9 questions · task: Derive a DUKPT working key
- KMIP for payments: 10% · 6 questions · task: Compose and read a KMIP exchange
Weights are fixed for a cohort and published before it opens. A change to the blueprint applies to the next cohort, never to a sitting already scheduled.
| Domain | Weight | Questions | Bench task |
|---|---|---|---|
| 01 · PIN and PIN blocks | 15% | 9 | Build and translate a PIN block. Given a PAN, a PIN and two zone keys, produce the ISO 9564 format 0 block under the first key and its translation under the second. Graded byte for byte. |
| 02 · Key management and key blocks | 20% | 12 | Wrap a key into a TR-31 block. Given a clear key, a KBPK and a stated usage, produce a version B or D key block that unwraps to the key with the right header. Graded by unwrapping it. |
| 03 · payShield host commands | 20% | 12 | Read a payShield trace. Given a captured host command and its response, name the command, the key scheme, the outcome and the reason for the error code. Graded against the trace. |
| 04 · EMV cryptograms | 20% | 12 | Verify an ARQC and issue the ARPC. Given an issuer master key, card data and a transaction, derive the session key, verify the ARQC and produce the method 1 or 2 ARPC. Graded against the cryptogram. |
| 05 · DUKPT end to end | 15% | 9 | Derive a DUKPT working key. Given a BDK and a KSN, produce the PIN or MAC working key (3DES or AES as stated) and decrypt the given block with it. Graded against the derivation. |
| 06 · KMIP for payments | 10% | 6 | Compose and read a KMIP exchange. Given an operation and its parameters, produce the TTLV request; given a TTLV response, state its outcome and the identifiers it returned. Graded byte for byte. |
5. Retakes, rescheduling and time
A seat or an exam-only purchase includes one sitting and 1 retake, both within the 12 months of access. A retake receives a new draw of questions and new task inputs.
Further retakes are bought at the exam-only price and follow the same rules.
There is no scheduling: the exam is available on demand from the day the cohort opens. A sitting that is started counts as taken, unless the bench itself fails during it, in which case it is voided and does not count.
A candidate who needs extra time for a documented reason writes to KeyLab before starting; extra time is granted as a fixed multiplier for the sitting and noted on the record, not on the certificate.
6. Integrity
The exam is not proctored by a person. It is protected by design: per-candidate draws, per-candidate task inputs, a bank that rotates, and a record of the sitting (timing, the tasks issued, the results submitted) kept with the certificate.
A candidate may use their own notes, the KeyLab tools and the public specifications. A candidate may not be assisted by another person during the sitting, and may not share questions or task inputs afterwards.
Sharing exam content, sitting on behalf of another person, or tampering with the bench voids the sitting and any certificate from it. The decision is written, with the evidence, and can be appealed (section 9).
7. The certificate and its verification
A passing candidate receives a PDF certificate with their name, the cohort, the date and a number of the form KPCS-2026-NNNNN, plus a badge image for professional profiles.
The number resolves at keylab.cloud/verify to the holder's name, the cohort, the dates of issue and expiry, and the status (valid, expired or withdrawn). Verification is public and needs no account. A holder may ask for their name to be shown as initials.
A certificate is valid for 3 years from issue. It is renewed by passing the current exam again, at the exam-only price, within the year before expiry. An expired certificate stays verifiable, marked as expired.
8. If KeyLab stops
KeyLab is maintained by one person and says so. Two promises cover the case where it stops operating before your access or your certificate ends:
- Access: the unused months of the 12-month access are refunded pro rata, automatically, to the original payment method.
- Verification: the registry of issued certificates (number, name as displayed, cohort, dates) is published as a signed static file at keylab.cloud/verify/registry.json, with its Ed25519 public key beside it, so a saved copy of the registry stays checkable without KeyLab's servers.
Before the cohort opens, the promise is simpler: if the course does not open on 5 December 2026, every purchase is refunded in full, automatically.
9. Appeals and contact
A candidate may appeal a result, a voided sitting or a refused accommodation by email within 14 days of the decision. KeyLab answers in writing within 14 days with the record of the sitting.
Questions about this handbook, and requests under it, go to the contact page on keylab.cloud. Nothing in this handbook limits rights a candidate has under the law of their country.
At a glance
- Course: 6 modules, 30 recorded lessons, an exercise on the bench after each.
- Exam: 60 questions + 6 bench tasks, 120 minutes, 70% and 4/6 tasks to pass, 1 retake included.
- Validity: 3 years, renewable by exam. Verification public at keylab.cloud/verify.
- Cohort 1 opens 5 December 2026; full refund on request until then, automatic if it does not open.