MPoC Program · PCI MPoC Certification

PCI MPoC certified in one quarter. Or we keep working until you are.

Tap-to-phone is the fastest-growing acceptance category in payments, and PCI MPoC is the standard that gates it. 192 individual security requirements. Accredited labs. Mandatory annual pen tests. Visa and Mastercard mandates already in effect. Paying.co's MPoC Certification Program is the end-to-end engagement that takes ISVs, acquirers, and OEMs from app to certified-and-shipping. In 90 days. Backed by a written guarantee — if we miss it, we keep working at no additional cost until your solution is on the PCI approved list.

Not sure where MPoC fits next to SPoC and CPoC? Here's what MPoC certification actually is.

90 daysPCI L3 cert guaranteed
192PCI MPoC requirements
3Allowed CMs — ISV / acquirer / OEM
$27.7BSoftPOS market by 2030
Built for three audiences

SoftPOS shippable for the people building it.

Tap-to-phone has three groups of companies trying to ship it — and each one comes into PCI MPoC with a different problem to solve. We've built the program to match.

◆ Audience 01
code

ISVs

Software vendors layering SoftPOS

You already have a vertical SaaS product — field service, restaurant ordering, healthcare scheduling — and you want to add tap-to-phone so customers can take a payment without leaving your app.

SDK integrationAttestationApp store ready
Talk to us
◆ Audience 02
account_balance

Acquirers

Branded SoftPOS for your merchants

You're an acquirer or PayFac who wants to give your merchants a branded tap-to-phone product without building it from scratch. Certification stays under your name.

White-label SoftPOSGateway wiredCert under your name
Talk to us
◆ Audience 03
memory

OEMs

Device makers embedding MPoC

You build Android-based devices — phones, rugged terminals, enterprise hardware — and want MPoC compliance baked in at the firmware/OS layer.

Firmware-level integrationSecure SLCPCI listing
Talk to us
What's in the program

End-to-end. Not piece-by-piece.

MPoC isn't one task. It's an engineering project, a security project, a documentation project, and a lab project running in parallel. The program covers every piece so the only thing you're tracking is the calendar.

◆ 01
fact_check

Gap analysis & scoping

Full technical gap analysis against all 192 PCI MPoC requirements across five domains. Written readiness report on day one, fixed-cost path on day three.

◆ 02
engineering

SDK hardening & integration

Tamper detection, root/jailbreak resilience, code obfuscation, runtime monitoring. If you have an existing app, we adapt it. If not, we build it.

◆ 03
cloud_done

Backend & compliance alignment

MPoC requires PCI DSS backend, PCI PIN processing, and Secure SLC development. We bring you to alignment on all three.

◆ 04
shield

Lab assessment & PCI listing

We bring the accredited security lab, deliver the evidence pack, run the mandatory pen test through Flaw.co, and get you onto the PCI approved list.

closeGoing it alone
  • cancelReading 192 PCI requirements and figuring out what each one means
  • cancelFinding a security lab, getting on their schedule, paying lab fees up front
  • cancelHardening the SDK, wiring attestation, and getting PCI DSS & PIN aligned in parallel
  • cancelFailing the first lab assessment because something didn't pass
  • cancelSlipping 6 to 12 months and watching the market move while you're in evaluation
checkWith the Paying.co MPoC Program
  • check_circleOne scoping call, one written gap analysis, one fixed-cost plan
  • check_circleAccredited labs already lined up, schedule pre-negotiated
  • check_circleSDK hardening, backend, and SLC alignment all delivered as one engagement
  • check_circlePre-assessment runs before the lab review so the official assessment passes first time
  • check_circleCertified in 90 days — or we keep working at no additional cost until you are

This is the program nobody else runs. Because nobody else can.

PCI MPoC is the toughest security spec PCI has ever issued. 192 requirements across five domains, with dependencies on PCI DSS, PCI PIN, and Secure SLC compliance underneath. Most companies trying to ship tap-to-phone either lose 12 months figuring it out themselves, or pay several different consultancies to handle the pieces.

Paying.co is one of the few teams that has the bench depth to deliver MPoC certification as one engagement. We bring the SDK hardening, the secure SLC pedigree, the backend DSS expertise, the pen testing via Flaw.co, and the direct relationships with the accredited labs PCI recognizes. We start every project with a written gap analysis, scope to a fixed cost, and back the entire engagement with a 90-day delivery guarantee.

Tap-to-phone is the fastest-growing acceptance category in payments. SoftPOS is projected to be a $27.7B market by 2030. Visa and Mastercard are mandating MPoC compliance for SoftPOS solutions. The window to be early is open right now.

Talk to our MPoC team
Under the hood

The five MPoC domains. All covered.

PCI MPoC v1.1 breaks 192 requirements into five security domains. Most teams that fail certification fail because one of the five was treated as an afterthought.

verified_user

Software integrity & protection

Tamper detection, code obfuscation, anti-debugging, root and jailbreak resilience, runtime integrity checks.

monitoring

Attestation & monitoring

The attestation server validates device posture in real time, wired to the SDK, the backend, and the runtime hooks.

cloud

Backend & processing security

PCI DSS for the payment processing back end. PCI PIN for PIN handling. Existing controls leveraged where they exist.

code

Secure software lifecycle

PCI MPoC requires development against the Secure SLC standard — threat modeling, code review, vulnerability response.

bug_report

Vulnerability resilience & pen testing

Annual penetration testing of mobile + backend is a hard requirement, run through Flaw.co on the first pass.

90-day plan · example: ISV launching SoftPOS
// Days 1 to 10 — kickoff & gap analysis
[Paying.co] scope → apps=1 backends=2
[Paying.co] gaps → "5 domains mapped, fixed cost quoted"

// Days 11 to 45 — engineering work
[Paying.co] sdk → "hardened, attestation hooked"
[Paying.co] backend → "DSS aligned, PIN aligned"
[Paying.co] slc → "controls documented"

// Days 46 to 75 — pre-assessment & pen test
[Flaw.co] pentest → mobile + backend
[Paying.co] pre-assess → "internal pass"

// Days 76 to 90 — lab assessment & listing
[Lab] evaluation → passed
[PCI] listed · day 90

// Day 91 — you ship.
The 90-day guarantee

Six promises. Written into the contract.

Cert programs are notorious for slipping. The MPoC Certification Program comes with six commitments backed by the engagement contract — not a sales deck.

Guaranteed
schedule

90 days to PCI listing

From contract signature to PCI approved list in 90 calendar days, or we keep going at no additional cost.

Guaranteed
request_quote

Fixed-cost engagement

One scope, one price, no scope creep. Quoted flat on day three, even if the lab needs a second pass.

Guaranteed
verified

First-pass lab assessment

Full internal pre-assessment before submitting to the accredited lab — failures fixed on our dime first.

Guaranteed
badge

Listing in your name

The PCI MPoC listing is in your company name, not ours — the cert, artifact and listing are your asset.

Guaranteed
bug_report

Year-one pen test included

We bundle the first year through Flaw.co at no extra cost — mobile app, attestation server, full remediation.

Guaranteed
support_agent

Year-two recertification

Fixed renewal rate for year-two recertification — same scope, same team, same delivery promise.

The 90-day timeline

Three phases. One outcome.

Every MPoC engagement follows the same three-phase shape. Status meetings every Friday. Slack channel open the whole time.

fact_check
◆ Days 1 to 30 · Scoping & Build

Gap analysis & engineering

Full gap analysis on day one, fixed-cost quote on day three. SDK hardening, attestation server, backend DSS and PIN alignment, SLC documentation by day 30.

science
◆ Days 31 to 60 · Pre-Assessment & Pen Test

Internal review & Flaw.co pen test

Internal pre-assessment against the lab's evidence pack. Mandatory pen test through Flaw.co on mobile + backend, remediated and submitted.

verified
◆ Days 61 to 90 · Lab & Listing

Lab assessment & PCI approval

Lab assessment runs against the cleaned evidence pack. By day 90, you're on the PCI approved list — in your name, ready to ship.

Common questions

MPoC certification, answered plainly.

What is PCI MPoC, and how is it different from SPoC and CPoC?add
MPoC (Mobile Payments on COTS) is PCI's current standard for accepting contactless card payments directly on a standard commercial phone or tablet, no extra hardware required. It replaces the older SPoC (software PIN entry) and CPoC (contactless-only) standards, which PCI has placed on a sunset path.
How long does MPoC certification actually take?add
Our program is built around a 90-day certification guarantee. If your solution isn't certified and on the PCI approved list within that window, we keep working at no additional cost until it is.
Who actually needs MPoC certification — ISVs, acquirers, or OEMs?add
All three, depending on how the tap-to-phone product is packaged. PCI MPoC recognizes three distinct commercial models: an ISV certifying its own app, an acquirer certifying a solution it distributes, or an OEM certifying at the device level.
What do the 192 PCI MPoC requirements actually cover?add
They span the full security posture of a tap-to-phone solution — attestation and monitoring services, secure card data handling on an unmanaged consumer device, backend security architecture, and a mandatory annual penetration test.
What happens if we don't certify within the guaranteed window?add
We keep working at no additional cost until your solution is on the PCI approved list. The 90-day guarantee is a commitment we hold ourselves to, not a soft target.
Why is tap-to-phone growing so fast right now?add
SoftPOS is projected to reach a $27.7B market by 2030, driven by Visa and Mastercard mandates already in effect and the simple economics of turning a phone someone already owns into a payment terminal.
Start the program

Tap-to-phone is happening. Be the one shipping it.

Tell us where you are today — existing SoftPOS app, idea phase, or somewhere in between — and which audience you fit (ISV, acquirer, or OEM). We'll come back with a written gap analysis, a fixed-cost scope, and a 90-day delivery plan backed by our guarantee.