Last Updated on July 26, 2026 by Craig Allen Keefner
Common Use Self‑Service (CUSS) and Common Use Passenger Processing Systems (CUPPS) were created to let multiple airlines share the same kiosks, counters, and passenger processing infrastructure instead of each carrier deploying its own proprietary footprint. kma+1
-
These standards were driven by IATA’s Common Use efforts to simplify deployment, reduce integration cost, and make airline applications portable across airports and platforms. iata+1
-
In practice, CUSS/CUPPS did deliver shared check‑in kiosks and workstations, but they also introduced real‑world complexity around security management, certification, branding control, and ongoing updates as new devices and workflows entered the airport.kma+1
-
The KMA article notes that modern passenger journeys are now mobile‑first and increasingly biometric, which puts pressure on legacy common‑use kiosks that were designed around boarding passes, passport scans, and local peripherals rather than identity platforms and cloud services.kma+1
-
Emerging approaches like Common Use Web Services (CUWS) and cloud‑based platforms aim to keep the “common use” benefits while simplifying architecture and lowering the cost of supporting smaller regional airports and dynamic airline operations. aeroexpo+1
-
For kiosk and self‑service vendors, the takeaway is that CUSS/CUPPS are no longer just airline IT acronyms—they sit at the intersection of airport operations, passenger experience, biometrics, payments, and security, and any serious travel or transportation kiosk strategy now has to account for how these standards are evolving.
Why CUSS/CUPPS Matter To Kiosk Vendors
-
They define the “rules of engagement” for airport kiosks: how airline apps talk to shared devices, peripherals, and back‑end systems, and which capabilities are available at the common‑use layer versus the airline layer.iata+1
-
If you build hardware, peripherals, or middleware for travel, CUSS/CUPPS decide whether your devices can participate in shared check‑in, rebooking, bag‑tag, or disruption‑management workflows—or whether you’re stuck in one‑off integrations.kioskindustry+1
-
CUSS 2.0 and newer CUPPS platforms are moving toward modern web technologies (HTML5, OpenAPI, JSON, TLS > 1.2, OAuth2, WebSockets), which directly affects how kiosk software is architected, tested, and certified.iata+1
-
For vendors, that shift means shorter release cycles, easier remote management, and better alignment with mainstream web and cloud stacks rather than bespoke, airport‑only tooling.iata+1
-
As airports push for more flexible, space‑efficient operations, common‑use kiosks and CUPPS become the default way to scale passenger processing without building new terminals—so kiosk and signage providers who play well with these standards will see more RFPs and partnerships.amadeus+2
Biggest Obstacles – And Why Upgrades Are Needed
-
Legacy CUSS/CUPPS deployments are often tightly coupled to old Windows builds, aging device drivers, and proprietary middleware, making it expensive and risky to add new peripherals (biometrics, payment, printers, cameras).kma+1
-
Security baselines have moved: older stacks were not built for continuous authentication, strong encryption everywhere, or modern compliance regimes (PCI DSS, GDPR, HIPAA‑style privacy expectations for biometrics and PII).iata+2
-
Operational complexity is high: airports must coordinate airlines, common‑use platform providers, ground handlers and regulators, so any upgrade is a multi‑stakeholder project that has to be justified against disruption risk and capital budgets.onlinepubs.trb+2
-
Passenger behaviour has shifted to mobile‑first and self‑service everywhere, which exposes the limitations of kiosks that can’t easily integrate with mobile IDs, digital wallets, off‑airport check‑in, or cloud‑based identity and reservation services.amadeus+2
-
In short, the combination of aging infrastructure, changing security expectations, and new passenger journeys makes “doing nothing” more expensive over time than planning a controlled migration to CUSS 2.0 / modern CUPPS.iata+1
Is This About Zero Trust And Certificates?
-
Zero Trust in this context means you no longer assume that anything on the airport network is safe just because it’s “inside”; every kiosk, application, user, and API call is authenticated, authorized, and continuously validated.crowdstrike+1
-
Modern CUSS/CUPPS guidance emphasizes using current security technologies (TLS > 1.2, mutual authentication, standards‑aligned encryption) and complying with data‑protection and payment regulations, which directly implies stronger certificate management and identity controls at the kiosk and platform level.iata+1
-
As airports adopt Zero Trust‑style architectures for critical systems and passenger data, common‑use kiosks have to fit into that model: secure transport, hardened endpoints, auditable access to back‑end services, and strict least‑privilege access for each airline app.cyber+2
-
For kiosk vendors, that means designing hardware and software that can handle certificate rotation, secure boot, encrypted storage, and robust identity/auth flows, instead of assuming a flat, trusted LAN where “everything can see everything.”iata+1
-
Upgrading CUSS/CUPPS is therefore not just an IT clean‑up exercise; it’s a prerequisite for bringing kiosks into a Zero Trust, cloud‑integrated, mobile‑aware airport environment where security, compliance, and passenger experience are all moving targets.