All transactions take basically the same time to verify. The trick is more in the motivations of any potential attackers.
The heart of the Bitcoin system is the block confirmation system. Once a transaction has been accepted into a block and that block becomes part of the official blockchain, it becomes essentially impossible to perform any kind of scam or attack on that transaction, such as spending those coins somewhere else. Only one spend of a particular quantity of bitcoins can be in the blockchain at once, so any attempt to spend them again will be rejected.
The trouble is that this is relatively slow. Getting one confirmation on a transaction takes probably like 5 minutes on average, and could vary depending essentially on the luck of the mining network at that moment. Using 6 confirmation is the official recommendation, and this may be expected to take about 1hr.
It isn't necessary to use the official recommendation, though. It's always hard to attack the system, and the 6 confirmation point is where it becomes essentially impossible for even major governments to attack the system, but such strong security is not necessary on all transactions. So the question becomes, how hard do we need to make it for a particular transaction?
To guess at that, we have to look at attacks. I mentioned earlier completing the physical transaction after the initial arrival of a Bitcoin transaction through the P2P Bitcoin network, before any blocks confirming it come in. To do a double-spend in that scenario, you would put 2 transactions spending the same coins on the network, and arrange for one to hit the vendor's system, while the other went out to the rest of the network and would be included in the next block. That's tough to arrange though - who knows what nodes the vendor is connected to, and it's impossible to know which miner will produce the next block. To have a solid chance at pulling this attack off, you would have to run a very powerful miner yourself, solve a block with a transaction spending some of your coins before another miner solved a block, then hold back that block, and perform your transaction at the target vendor between when you solved that block that you are holding and when another miner does.
That's a window of a could of minutes, maybe, and it could take days or weeks or longer for your miner to solve a block that puts you in the position to do this. The timing is very tough to pull off at a physical store, then. And to do all of this, you have to be running your own independent miner, which is powerful enough to have a reasonable chance at solving a block in the next couple of weeks. But just running that miner as a normal miner means you're likely to get the mined block reward, currently 25 bitcoins, currently worth $12,500, just for solving that block. Why pull the funny business with transactions for, say, a $10 sandwich when you just made over 1000 times that money by doing nothing?
So because of this, completing physical transactions after only a receipt of the Bitcoin transaction is a risk, but given the high difficulty and low reward to the attacker, and low loss amount to the business, it seems like a very acceptable risk to make the purchase process more convenient to the normal customers.