MPoC Certification Program →
HomeGuidesWhat is MPoC

What is MPoC certification, really?

The PCI standard behind tap-to-phone payments — what it covers, how it supersedes SPoC and CPoC, who needs it, and what certification involves.

schedule 7 min read · By the Paying.co engineering team
The short version

MPoC — Mobile Payments on COTS — is the PCI standard that lets an ordinary NFC smartphone or tablet accept contactless payments securely, with no dedicated terminal hardware. It consolidates the earlier SPoC and CPoC standards into one modular framework covering both contactless acceptance and PIN entry. If you're launching a SoftPOS or tap-to-phone product, MPoC is the certification acquirers and card brands expect.

Breaking down the acronym

MPoC stands for Mobile Payments on COTS, and COTS stands for Commercial Off-The-Shelf — standard consumer devices like phones and tablets that were never purpose-built to take payments. The standard, published by the PCI Security Standards Council, defines how those everyday devices can accept payments securely enough to satisfy the card brands.

In plain terms: it's the rulebook that makes "tap your card on my phone" a legitimate, approvable way to get paid.

What SoftPOS is, and how it fits

SoftPOS (software point of sale) is the technology; MPoC is the security standard it's certified against. A SoftPOS app uses the phone's built-in NFC radio to read a contactless card or wallet, with no external reader. The appeal is obvious — $0 hardware cost, instant deployment to any compatible device, and a path into acceptance for merchants who'd never buy a traditional terminal. But to run live, that software has to prove it handles cardholder data safely on a device the developer doesn't control. That's what MPoC certifies.

How MPoC supersedes SPoC and CPoC

MPoC didn't appear from nowhere. It unifies two earlier, narrower PCI standards into a single, more flexible one.

StandardCoveredStatus
SPoCSoftware-based PIN entry on COTS, usually with a separate card readerSuperseded by MPoC
CPoCContactless acceptance on COTS, no PINSuperseded by MPoC
MPoCContactless acceptance and PIN entry on one off-the-shelf device, modular architectureCurrent standard

The practical upgrade: under MPoC, a single consumer phone can take a contactless tap and capture a PIN where one is required, under one modular, outcome-based standard — instead of stitching together two older specs with separate hardware assumptions.

Who needs it

code

ISVs & software platforms

Embedding tap-to-phone acceptance into an existing app — ordering, field service, delivery, any flow that should end in a payment.

account_balance

Acquirers & payment facilitators

Bringing a branded SoftPOS product to merchants as a lower-friction alternative to shipping hardware.

devices

OEMs & device makers

Launching tap-to-phone capability across a device line and needing a certified, repeatable acceptance stack.

What certification involves

An MPoC engagement combines secure application development, an attestation and evidence package, and a structured assessment against the standard's modular requirements — covering the software, the monitoring and attestation backend, and the way the solution detects a compromised device. A focused, well-scoped program can target certification in around 90 days. Solutions that bake in the security architecture and evidence from the start certify far faster than ones that treat compliance as a bolt-on at the end.

Frequently asked questions

What is MPoC certification?add
MPoC (Mobile Payments on COTS) is a PCI Security Standards Council standard defining how contactless payments can be accepted securely on off-the-shelf devices like smartphones and tablets. It governs the security requirements for SoftPOS and tap-to-phone solutions that turn an NFC phone into a payment device without dedicated hardware.
What does COTS mean?add
Commercial Off-The-Shelf — standard consumer devices such as phones and tablets that weren't purpose-built as payment terminals but can accept contactless payments through compliant software.
How does MPoC relate to SPoC and CPoC?add
MPoC consolidates both. SPoC covered software-based PIN entry on COTS; CPoC covered contactless acceptance without PIN. MPoC unifies them into one modular standard supporting contactless acceptance and PIN entry on the same device, with more flexible architecture options.
What is SoftPOS?add
Software point of sale — technology that turns an NFC-capable smartphone or tablet into a contactless terminal using software rather than dedicated hardware. Production SoftPOS solutions are generally certified against PCI MPoC.
How long does MPoC certification take?add
It varies by architecture and assessor queue, but a focused, well-scoped program can target around 90 days. Solutions that combine application development, attestation evidence, and assessment from the start certify faster.
Who needs MPoC certification?add
ISVs, acquirers, payment facilitators, and OEMs launching tap-to-phone or SoftPOS products generally need it to accept live contactless payments on consumer devices. It's the standard brands and acquirers look for before approving a software-based acceptance solution.

Launching tap-to-phone? Get it certified.

Our MPoC Certification Program targets PCI MPoC certification in 90 days — or we keep working until you're there.

See the MPoC program arrow_forward