bankingwith.

NFC Contactless Payments: Why Close Proximity Is Required

In October 2025, the NFC Forum launched Certification Release 15, codifying a fourfold expansion of the certified operating range for contactless payment connections — from 5 millimeters to 20 millimeters.

Spencer Merrick·Updated: July 24, 2026·10 min read

NFC Contactless Payments: Why Close Proximity Is Required

The move arrives three decades after the underlying standard, ISO/IEC 14443, was first drafted, and it sits at the intersection of two competing pressures: consumer complaints about finicky tap-to-pay alignment, and the regulatory insistence that proximity remain a load-bearing security primitive. The fact that the official range has only now been widened from a fingernail-width gap to roughly the thickness of a stack of nine U.S. quarters illustrates how tightly the contactless payments ecosystem treats physical distance — not as a UX inconvenience, but as a structural defense.

Contactless payment range is a security specification, not a usability suggestion.

The Physics of Inductive Coupling: How NFC Connections Form

NFC transactions are not radio broadcasts. They are tightly coupled inductive events between two loop antennas — one embedded in the payment terminal, the other in the card or smartphone. Both operate at 13.56 MHz, a frequency selected because it occupies a globally unlicensed ISM band and because the corresponding wavelength (~22 meters) is enormous relative to the dimensions of the antennas involved. The practical consequence is that energy transfer between the two coils falls off rapidly with distance, following the inverse-cube law that governs near-field magnetic coupling. At a few centimeters, the magnetic field is strong enough to power a passive credential and sustain bidirectional data exchange. At half a meter, it is functionally zero.

This is not a coincidence or an engineering oversight. Inductive coupling requires the reader's field to physically reach the card and induce a current in the card's antenna. Passive cards carry no battery; they harvest all operational energy from the terminal's electromagnetic field. Once the distance grows beyond the range at which that harvested energy exceeds the threshold required to power the chip and sustain the handshake, the transaction cannot even begin.

The standard's theoretical communication ceiling sits at 10 cm under ISO/IEC 14443. The Forum's original certification window was tighter: 0.5 cm, reflecting both practical antenna design and the deliberate engineering margin that ensures connections are intentional rather than incidental. The shift to 2 cm in Release 15 does not change the physics; it adjusts the certification tolerance within the standard's existing envelope.

Security by Design: Why Short-Range Limits Prevent Skimming

The short operating range is the most fundamental security feature of contactless payments. Every layer above it — tokenization, dynamic authentication, cryptographic handshake — depends on the assumption that an attacker cannot easily intercept or initiate a transaction from a meaningful distance.

Skimming concerns have historically centered on two vectors: passive eavesdropping and active relay attacks. Passive eavesdropping requires the attacker to be within radio range with specialized equipment capable of reading the 13.56 MHz handshake. The rapid field falloff at this frequency bounds the practical eavesdropping radius by the same physics that limits legitimate transactions. Active relay attacks — "ghost and leech" setups that extend range by amplifying and forwarding the signal between a victim's card and a distant terminal — are more sophisticated, but they still require physical proximity at one end of the chain. The attacker must place a relay device within centimeters of the target card.

This is why Release 15's expansion to 2 cm is calibrated rather than dramatic. The cryptographic payloads exchanged during a transaction are tokenized: the card number is replaced with a single-use encrypted token that expires immediately after authorization, and intercepted data cannot be replayed or reused. But the tokenization model depends on the assumption that the initial handshake — the moment at which the card and reader negotiate session keys — occurs over a channel the attacker cannot easily inject themselves into. Extending the range to 20 mm widens the window for relay placement, but it does not push the channel into the longer-range regime where interception becomes trivially automatable.

Tokenization handles the data; proximity handles the access.

Evolution of the Standard: From ISO/IEC 14443 to NFC Release 15

The history of NFC payments is, in effect, the history of a single constraint being renegotiated. ISO/IEC 14443, first published in the mid-1990s, defined the proximity card standard that still underpins nearly every contactless payment in circulation. It specified the 13.56 MHz frequency, the modulation schemes, and the anti-collision protocols that allow a terminal to distinguish between multiple cards presented simultaneously. It also drew a clear line between "proximity" cards (operating up to roughly 10 cm) and "vicinity" cards (operating up to roughly 1 m), placing payments firmly in the proximity category.

Over the following decades, the standard was refined through ISO/IEC 14443-A and 14443-B variants, and the NFC Forum — a separate industry consortium formed in 2004 — developed its own certification regime to ensure interoperability across hardware vendors. The Forum's certification releases, distinct from the ISO standard, specified the tested operating envelopes within which compliant devices were guaranteed to function.

SpecificationDocumentOperating RangeRole
ISO/IEC 14443International standardUp to 10 cm (theoretical)Defines the proximity card protocol
NFC Forum (pre-Release 15)Industry certification0.5 cm (5 mm)Certified operating envelope
NFC Forum Release 15Industry certification (June 2025)2 cm (20 mm)Expanded certified envelope
Certification Release 15Testing program (October 2025)2 cmOfficial compliance testing

The June 2025 Release 15 announcement, followed by the October 2025 launch of Certification Release 15, formalized the wider envelope. The change was driven less by new physics than by accumulated field data: terminal antennas have grown more sensitive, card antenna geometry has improved, and consumer tolerance for misaligned taps has eroded. The fourfold range expansion is an acknowledgment that the 0.5 cm envelope was, in practice, a tighter constraint than the underlying standard required.

The 2cm Shift: Improving Usability Without Compromising Safety

The headline change — 0.5 cm to 2 cm — warrants scrutiny on its own terms. It is not a security regression. It is a usability concession, accepted because the underlying threat model was reviewed and the wider envelope was determined to leave the cryptographic and proximity defenses intact.

Three mechanisms preserve safety under the expanded range:

  • The cryptographic handshake is unchanged. Devices certified under Release 15 exchange the same session keys, the same tokenized payloads, and the same authentication challenges as devices certified under the previous envelope.
  • The tokenization layer, which substitutes a single-use digital identifier for the actual card number, renders any data intercepted at the expanded range functionally useless.
  • The field falloff at 13.56 MHz remains steep; a 2 cm operating range still places the transaction inside the inductive near-field regime and far short of the distances at which remote skimming becomes operationally viable.

The practical effect of the change is the elimination of a category of failed transactions caused by imperfect alignment. Cards inserted into worn wallets, phones held at oblique angles, and watches worn over cuffs no longer require precise placement. For consumers, the change is nearly invisible. For payment processors, it should reduce a measurable slice of the authorization failure rate attributable to read errors.

The compliance machinery behind the rollout matters as much as the specification itself. PCI PTS and EMVCo certifications govern deployed terminal security; they do not directly define the operating range of the contactless interface, but they require conformance to the underlying ISO and NFC Forum standards. As Release 15 propagates into those standards, terminal vendors must ensure that their implementations remain compliant across both the old and new envelopes during the transition period.

The unknown, as of late 2025, is hardware adoption. Major smartphone manufacturers have not publicly committed to timelines for integrating Release 15-compliant chips, and the percentage of active payment terminals currently supporting the expanded range without hardware upgrades remains undisclosed. Until that gap closes, the 2 cm envelope exists primarily as a forward-looking certification target rather than a deployed reality.

Active vs. Passive Devices: Antenna Dynamics in Modern Payments

Not all NFC credentials behave identically at the edge of the operating range. The distinction between active and passive devices has practical consequences for connection speed, range perception, and power consumption.

Passive cards — standard contactless bank cards and most transit cards — carry no internal power source. They harvest operational energy entirely from the reader's electromagnetic field and backscatter a modulated signal to communicate. Their effective range is bounded by the minimum field strength required to power the chip and sustain the data exchange, which is why they tend to be more sensitive to misalignment and wallet thickness.

Active NFC devices — smartphones, smartwatches, and certain newer payment cards with embedded batteries — generate their own electromagnetic field. Their larger antennas and onboard power allow them to initiate the handshake at slightly greater distances and to complete the connection faster. To a consumer, this manifests as the observation that phone-based taps feel more forgiving than card-based taps. From an infrastructure standpoint, it means the active device is doing half the work of the handshake before the terminal even registers its presence.

ParameterPassive CardActive Device (Smartphone/Watch)
Power sourceHarvested from terminal fieldInternal battery
Antenna sizeSmall, fixedLarger, tunable
Effective rangeNear lower bound of certified envelopeNear upper bound of certified envelope
Connection perceptionRequires precise alignmentMore forgiving of misalignment
Power consumption during transactionNegligible (passive)Modest (active polling)

The Release 15 expansion narrows the practical gap between these two categories. Passive cards still operate at the lower end of the certified envelope, but the envelope itself is wider, meaning the misalignment tolerance for both classes of device has increased proportionally. The asymmetry does not disappear — active devices remain faster and more forgiving — but the worst-case experience for passive credentials is materially improved.

Conclusion: Proximity as Structural Defense

The 20-millimeter operating range codified in NFC Release 15 is the widest envelope the contactless payments ecosystem has ever formally certified. It is also, by a wide margin, the tightest physical constraint of any commonly used payment modality. A consumer can authorize a card-not-present transaction from across a room; the same consumer cannot authorize an NFC payment from across a table.

This asymmetry is not accidental. The proximity requirement is the load-bearing structural element beneath every other security layer in the contactless stack. Tokenization, dynamic authentication, and session key exchange all operate within a channel that is defined, at its outermost edge, by the inductive coupling limit. Release 15 widens that edge from 5 mm to 20 mm, but it does not change the fundamental architecture: the transaction must occur within a distance at which the card and reader can complete a handshake that no third party can easily inject themselves into.

The expansion is welcome because it reduces friction without compromising the underlying defense. It is also a reminder that the range number itself is a negotiated parameter, not a physical constant. The standard bodies, the hardware vendors, and the certification programs will continue to renegotiate it as antenna technology, cryptography, and threat models evolve. The sober assessment is that the next expansion, when it comes, will arrive as quietly as this one — and will be presented as a usability upgrade, while functioning, in practice, as a small concession at the perimeter of the same defense that has protected contactless payments since the standard was first written.

FAQ

Why is the NFC payment range limited to such a short distance?
The short range is a deliberate security feature that ensures transactions are intentional and prevents unauthorized skimming or interception by requiring physical proximity.
Does the new 20 mm range make contactless payments less secure?
No, the expansion is a usability adjustment that does not change the cryptographic handshake or tokenization processes, which continue to protect transaction data.
What is the difference between active and passive NFC devices?
Passive cards harvest energy from the terminal's electromagnetic field, while active devices like smartphones use internal batteries to generate their own field, making them faster and more forgiving of misalignment.
Why do some payment taps feel easier than others?
Active devices like smartphones have larger antennas and their own power sources, allowing them to initiate connections more easily than passive cards, which rely entirely on the terminal's field.
Can an attacker intercept my payment from across a room?
No, the physics of inductive coupling at 13.56 MHz causes the magnetic field to fall off rapidly, making it impossible to initiate or intercept a transaction from a significant distance.