Tap-to-phone is the fastest-growing acceptance category in payments, and PCI MPoC is the standard that gates it. 192 individual security requirements. Accredited labs. Mandatory annual pen tests. Visa and Mastercard mandates already in effect. Paying.co's MPoC Certification Program is the end-to-end engagement that takes ISVs, acquirers, and OEMs from app to certified-and-shipping. In 90 days. Backed by a written guarantee — if we miss it, we keep working at no additional cost until your solution is on the PCI approved list.
Not sure where MPoC fits next to SPoC and CPoC? Here's what MPoC certification actually is.
Tap-to-phone has three groups of companies trying to ship it — and each one comes into PCI MPoC with a different problem to solve. We've built the program to match.
You already have a vertical SaaS product — field service, restaurant ordering, healthcare scheduling — and you want to add tap-to-phone so customers can take a payment without leaving your app.
Talk to usYou're an acquirer or PayFac who wants to give your merchants a branded tap-to-phone product without building it from scratch. Certification stays under your name.
Talk to usYou build Android-based devices — phones, rugged terminals, enterprise hardware — and want MPoC compliance baked in at the firmware/OS layer.
Talk to usMPoC isn't one task. It's an engineering project, a security project, a documentation project, and a lab project running in parallel. The program covers every piece so the only thing you're tracking is the calendar.
Full technical gap analysis against all 192 PCI MPoC requirements across five domains. Written readiness report on day one, fixed-cost path on day three.
Tamper detection, root/jailbreak resilience, code obfuscation, runtime monitoring. If you have an existing app, we adapt it. If not, we build it.
MPoC requires PCI DSS backend, PCI PIN processing, and Secure SLC development. We bring you to alignment on all three.
We bring the accredited security lab, deliver the evidence pack, run the mandatory pen test through Flaw.co, and get you onto the PCI approved list.
PCI MPoC is the toughest security spec PCI has ever issued. 192 requirements across five domains, with dependencies on PCI DSS, PCI PIN, and Secure SLC compliance underneath. Most companies trying to ship tap-to-phone either lose 12 months figuring it out themselves, or pay several different consultancies to handle the pieces.
Paying.co is one of the few teams that has the bench depth to deliver MPoC certification as one engagement. We bring the SDK hardening, the secure SLC pedigree, the backend DSS expertise, the pen testing via Flaw.co, and the direct relationships with the accredited labs PCI recognizes. We start every project with a written gap analysis, scope to a fixed cost, and back the entire engagement with a 90-day delivery guarantee.
Tap-to-phone is the fastest-growing acceptance category in payments. SoftPOS is projected to be a $27.7B market by 2030. Visa and Mastercard are mandating MPoC compliance for SoftPOS solutions. The window to be early is open right now.
Talk to our MPoC teamPCI MPoC v1.1 breaks 192 requirements into five security domains. Most teams that fail certification fail because one of the five was treated as an afterthought.
Tamper detection, code obfuscation, anti-debugging, root and jailbreak resilience, runtime integrity checks.
The attestation server validates device posture in real time, wired to the SDK, the backend, and the runtime hooks.
PCI DSS for the payment processing back end. PCI PIN for PIN handling. Existing controls leveraged where they exist.
PCI MPoC requires development against the Secure SLC standard — threat modeling, code review, vulnerability response.
Annual penetration testing of mobile + backend is a hard requirement, run through Flaw.co on the first pass.
Cert programs are notorious for slipping. The MPoC Certification Program comes with six commitments backed by the engagement contract — not a sales deck.
From contract signature to PCI approved list in 90 calendar days, or we keep going at no additional cost.
One scope, one price, no scope creep. Quoted flat on day three, even if the lab needs a second pass.
Full internal pre-assessment before submitting to the accredited lab — failures fixed on our dime first.
The PCI MPoC listing is in your company name, not ours — the cert, artifact and listing are your asset.
We bundle the first year through Flaw.co at no extra cost — mobile app, attestation server, full remediation.
Fixed renewal rate for year-two recertification — same scope, same team, same delivery promise.
Every MPoC engagement follows the same three-phase shape. Status meetings every Friday. Slack channel open the whole time.
Full gap analysis on day one, fixed-cost quote on day three. SDK hardening, attestation server, backend DSS and PIN alignment, SLC documentation by day 30.
Internal pre-assessment against the lab's evidence pack. Mandatory pen test through Flaw.co on mobile + backend, remediated and submitted.
Lab assessment runs against the cleaned evidence pack. By day 90, you're on the PCI approved list — in your name, ready to ship.
Tell us where you are today — existing SoftPOS app, idea phase, or somewhere in between — and which audience you fit (ISV, acquirer, or OEM). We'll come back with a written gap analysis, a fixed-cost scope, and a 90-day delivery plan backed by our guarantee.