Paying.co's MPoC Certification Program takes ISVs, acquirers, and OEMs from app to certified-and-shipping in 90 days, backed by a written guarantee — if the deadline is missed, Paying.co keeps working at no additional cost until the solution is on the PCI approved list.

📱 What is PCI MPoC certification?

MPoC (Mobile Payments on COTS) is PCI's current standard for accepting contactless card payments directly on a standard commercial phone or tablet, with no extra hardware required. It replaces the older SPoC (software PIN entry on COTS) and CPoC (contactless-only on COTS) standards, both of which PCI has placed on a sunset path. Understanding MPoC vs SPoC vs CPoC matters for any ISV, acquirer, or OEM planning a SoftPOS or tap-to-phone rollout — MPoC is the certification that determines whether a solution can actually go live.

SoftPOS is projected to be a $27.7B market by 2030, and Visa and Mastercard are actively mandating MPoC compliance for SoftPOS solutions. The window to be early is open right now.

🎯 Built for three audiences

ISVs — Software vendors layering SoftPOS into an existing vertical SaaS product — field service, restaurant ordering, healthcare scheduling — who want customers to accept a tap-to-phone payment without leaving the app. Covers SDK integration, attestation, and app store readiness.

Acquirers — Acquirers and PayFacs who want to offer a branded, white-label SoftPOS product to merchants without building tap-to-phone from scratch. Certification stays under the acquirer's own name, with the gateway already wired.

OEMs — Device manufacturers building Android-based hardware — phones, rugged terminals, enterprise devices — who need MPoC compliance baked in at the firmware and OS layer, with secure Software Lifecycle Compliance (SLC) and a path to PCI listing.

🔧 What's included — end-to-end, not piece-by-piece

MPoC certification isn't one task. It's an engineering project, a security project, a documentation project, and a lab project running in parallel. The program covers every piece:

Gap analysis & scoping — A full technical gap analysis against all 192 PCI MPoC requirements across five domains, with a written readiness report on day one and a fixed-cost path on day three.

SDK hardening & integration — Tamper detection, root and jailbreak resilience, code obfuscation, and runtime monitoring. Existing apps are adapted; new apps are built from the ground up.

Backend & compliance alignment — MPoC requires PCI DSS alignment for the payment processing backend, PCI PIN compliance for PIN handling, and development against the Secure SLC standard. Paying.co brings all three into alignment.

Lab assessment & PCI listing — Paying.co brings the accredited security lab relationship, delivers the evidence pack, runs the mandatory penetration test through Flaw.co, and gets the solution onto the PCI approved list.

🧩 The five MPoC security domains, fully covered

PCI MPoC v1.1 breaks its 192 requirements into five domains. Most teams that fail certification fail because one of the five was treated as an afterthought.

Software integrity & protection — Tamper detection, code obfuscation, anti-debugging, root and jailbreak resilience, runtime integrity checks.

Attestation & monitoring — A real-time attestation server validating device posture, wired to the SDK, the backend, and runtime hooks.

Backend & processing security — PCI DSS for the payment processing backend and PCI PIN for PIN handling, leveraging existing controls where they already exist.

Secure software lifecycle — Development against the Secure SLC standard: threat modeling, code review, and vulnerability response built into the process, not added afterward.

Vulnerability resilience & penetration testing — Annual penetration testing of mobile app and backend is a hard PCI MPoC requirement, run through Flaw.co on the first pass.

✅ Going it alone vs. the Paying.co MPoC Program

Going it alone typically means: reading and interpreting 192 PCI requirements from scratch, finding and scheduling a security lab while paying fees up front, hardening the SDK and aligning PCI DSS and PIN compliance in parallel with no coordination, failing the first lab assessment because something didn't pass, and slipping six to twelve months while the market moves on.

With the Paying.co MPoC Program: one scoping call and one written gap analysis lead to a fixed-cost plan. Accredited labs are already lined up with schedules pre-negotiated. SDK hardening, backend alignment, and Secure SLC work are delivered as a single coordinated engagement. A full internal pre-assessment runs before the official lab review, so the real assessment passes the first time. Certification lands in 90 days — or Paying.co keeps working at no additional cost until it does.

📅 The 90-day timeline

Days 1–30 · Scoping & Build — Full gap analysis on day one, fixed-cost quote on day three. SDK hardening, attestation server setup, backend DSS and PIN alignment, and SLC documentation completed by day 30.

Days 31–60 · Pre-Assessment & Pen Test — Internal pre-assessment run against the lab's evidence pack. Mandatory penetration test through Flaw.co covering mobile app and backend, remediated and submitted.

Days 61–90 · Lab & Listing — Lab assessment runs against the cleaned evidence pack. By day 90, the solution is on the PCI approved list, listed in the client's own name, ready to ship.

🔒 The 90-day guarantee — six commitments in writing

✓ 90 days to PCI listing — from contract signature to PCI approved list in 90 calendar days, or Paying.co keeps going at no additional cost.
✓ Fixed-cost engagement — one scope, one price, no scope creep, even if the lab needs a second pass.
✓ First-pass lab assessment — a full internal pre-assessment runs before submitting to the accredited lab, with any failures fixed on Paying.co's dime first.
✓ Listing in your name — the PCI MPoC listing belongs to the client's company, not Paying.co; the certification, evidence artifacts, and listing are the client's asset.
✓ Year-one penetration test included — the first year of mandatory pen testing through Flaw.co is bundled at no extra cost, covering the mobile app, attestation server, and full remediation.
✓ Year-two recertification — a fixed renewal rate for year-two recertification, same scope, same team, same delivery promise.

❓ MPoC certification, answered plainly

What is PCI MPoC, and how is it different from SPoC and CPoC? MPoC is PCI's current standard for contactless card acceptance on a standard commercial phone or tablet. It replaces the older SPoC and CPoC standards, both on a sunset path.

How long does MPoC certification actually take? Paying.co's program is built around a 90-day certification guarantee — if the solution isn't certified and listed within that window, Paying.co keeps working at no additional cost until it is.

Who needs MPoC certification — ISVs, acquirers, or OEMs? All three, depending on how the tap-to-phone product is packaged. PCI MPoC recognizes three distinct commercial models: an ISV certifying its own app, an acquirer certifying a distributed solution, or an OEM certifying at the device level.

What do the 192 PCI MPoC requirements actually cover? The full security posture of a tap-to-phone solution — attestation and monitoring services, secure card data handling on an unmanaged consumer device, backend security architecture, and a mandatory annual penetration test.

What happens if certification doesn't happen within the guaranteed window? Paying.co keeps working at no additional cost until the solution is on the PCI approved list. The 90-day guarantee is a binding commitment, not a soft target.

Why Paying.co runs this program

PCI MPoC is the toughest security specification PCI has issued to date — 192 requirements across five domains, with dependencies on PCI DSS, PCI PIN, and Secure SLC compliance underneath. Most companies attempting to ship tap-to-phone independently either lose a year figuring it out, or hire multiple consultancies to handle separate pieces. Paying.co has the bench depth to deliver MPoC certification as one coordinated engagement — SDK hardening, Secure SLC pedigree, backend DSS expertise, penetration testing through Flaw.co, and direct relationships with PCI-accredited labs, all under one team, one contract, and one 90-day guarantee.

🔗 Start the program
🔗 paying.co/mpoc-program
🔗 paying.co

PayingCo #MPoC #SoftPOS #PCICompliance #PCIDSS #TapToPhone #PaymentCertification #FinTech #PaymentSecurity #ContactlessPayments #ISV #Acquirers #PaymentEngineering #MobilePayments #EMV