Update: 4 July 2026
What are MPoC, sPOC and CPOC? MPoC (Mobile Payments on COTS), sPOC (Software-Based PIN Entry on COTS), and CPOC (Contactless Payments on COTS) are PCI SSC standards for payment software running on commercial off-the-shelf (COTS) devices – smartphones and tablets. Unlike traditional payment terminals, which are dedicated, certified hardware devices, xPOC solutions allow merchants to accept payments on standard iOS or Android devices, transforming them into payment terminals. SoftPOS software providers must obtain PCI SSC certification for their solution before it can be commercially deployed with merchants.
MPoC, sPOC and CPOC – at a glance:
- sPOC (Software-Based PIN Entry on COTS) enables PIN entry on a merchant’s smartphone touchscreen – it carries the highest security requirements of the three standards because it processes sensitive authentication data
- CPOC (Contactless Payments on COTS) is the broadest standard – contactless card, digital wallet, and local payment scheme acceptance on a merchant smartphone without dedicated hardware
- MPoC is the wider framework combining sPOC and CPOC – providers can certify a single, comprehensive SoftPOS solution rather than seeking separate sPOC and CPOC certifications
- MPoC/sPOC/CPOC certification applies to the software provider, not the merchant – the merchant buys a certified solution; the certification obligation sits with the provider
- PCI SSC maintains the Validated MPoC Solutions list, which merchants and acquirers should use to verify SoftPOS solutions before deployment.
- Patronusec as an accredited QSA supports SoftPOS providers in preparing for MPoC/sPOC certification through pre-assessment and technical preparation management
Table of Contents
What are the differences between sPOC, CPOC and MPoC – and which standard is right for your product?
The choice of standard depends on the functionality the provider wants to deliver.
sPOC (Software-Based PIN Entry on COTS) – PCI SSC standard:
sPOC enables the cardholder to enter their PIN directly on the merchant’s smartphone or tablet touchscreen. It is technically the most demanding standard due to specific PIN entry protection requirements – PIN data must be protected even if the device itself is compromised.
For whom: SoftPOS providers whose solution requires customer PIN entry for transactions (debit cards, transactions above the contactless PIN-free limit).
CPOC (Contactless Payments on COTS):
CPOC covers NFC contactless payments without a merchant-side PIN, or with PIN confirmed by the customer’s own device (for example via a digital wallet). The CPOC application does not handle the PIN – the customer confirms the transaction on their own device.
For whom: SoftPOS providers focused on contactless-only payments where the PIN-free limit is sufficient.
MPoC (Mobile Payments on COTS) – the most current, broadest framework:
MPoC is a PCI SSC framework that combines sPOC and CPOC under a single certification programme. It allows providers to certify one MPoC application rather than seeking separate sPOC and CPOC certifications. This is the preferred path for new entrants to the market.
Comparison of standards:
| Standard | PIN entry | NFC contactless | What is certified | Difficulty |
|---|---|---|---|---|
| sPOC | Yes (on COTS screen) | No | Application plus backend | Very high |
| CPOC | No (or via customer wallet) | Yes | Application | High |
| MPoC | Yes (sPOC component) | Yes (CPOC component) | Complete solution | Very high |
Patronusec Insight: SoftPOS providers entering MPoC certification consistently underestimate the complexity of sPOC component security requirements. The requirements for protecting the application’s runtime environment (RASP, anti-debugging, code obfuscation) on a COTS device are significantly more rigorous than standard mobile application security requirements. A pre-assessment before formal certification by a QSSE is essential – it identifies gaps before the provider commits budget to the formal evaluation. As an accredited QSA, we help SoftPOS providers understand these requirements before the certification project begins.
What are the key security requirements for sPOC/CPOC/MPoC solutions?
The security requirements for xPOC solutions are considerably more rigorous than for standard mobile applications – because the application processes payment data on an “untrusted” consumer device.
Key technical requirements:
Runtime Application Self-Protection (RASP):
The application must detect attempts to interfere with its runtime environment – debugging, hooking, emulators. On detection, it must terminate the session and alert the management server.
Code Obfuscation:
Application code must be obfuscated to impede reverse engineering. This is particularly critical for modules handling PIN entry and server communications.
Secure PIN Entry (for sPOC):
The PIN entered by the customer must be protected against interception by other applications, system-level keyloggers, or screen captures. Requirements include a dedicated PIN entry view with protections against screenshots and screen recording.
Integrity Verification:
The application must verify its own integrity at launch – detecting code modifications and unauthorised versions.
Secure Communication:
Communication with the management server and payment processor must use current encryption protocols (TLS 1.2 or higher) with certificate pinning.
Organisational requirements for the provider:
- A documented SDLC (Secure Development Lifecycle) with security controls at every stage
- A vulnerability management programme with a formal disclosure process (Vulnerability Disclosure Policy)
- Procedures for monitoring and managing COTS devices (where the provider manages merchant devices)
- Incident response plans specific to payment application compromise
Developing a SoftPOS application and planning MPoC or sPOC certification?
Patronusec conducts pre-assessments for SoftPOS providers – evaluating technical and organisational readiness before formal certification by a QSSE. We identify gaps before you commit budget to the formal evaluation.
Book an MPoC/sPOC pre-assessment
How does the MPoC/sPOC certification process work through PCI SSC?
MPoC/sPOC/CPOC certification is conducted by a Qualified Software Security Evaluator (QSSE) accredited by PCI SSC – not by a QSA.
MPoC certification stages:
- Pre-assessment (recommended): Verification of solution readiness before the formal evaluation. May be conducted by a QSA or independent expert. Identifies gaps without the cost of a formal QSSE evaluation.
- PCI SSC portal registration: The provider registers in the MPoC/sPOC/CPOC programme on the PCI SSC portal and pays the registration fee.
- QSSE selection: The provider selects a QSSE from the PCI SSC-approved list. The QSSE conducts the formal evaluation.
- Technical evaluation: The QSSE reviews documentation, conducts technical application testing (dynamic and static analysis), and verifies the server environment and organisational processes.
- Laboratory evaluation (for sPOC): Components handling PIN entry may require evaluation by an accredited security laboratory.
- Report and listing: Following a positive evaluation, the provider is listed on the PCI SSC register for the relevant standard.
Timeline and costs:
MPoC certification for a solution built from scratch is a 9 to 18 month project. QSSE costs depend on the complexity of the solution – typically from several tens of thousands to several hundred thousand euros. Add the cost of technical preparation (secure SDLC, testing, documentation) and any pre-assessment.
Patronusec Insight: The most common gap we find in MPoC pre-assessments is the absence of a documented Vulnerability Disclosure Policy (VDP) and an inadequate SDLC security programme. QSSE evaluators examine not only the application security controls but also the organisational processes that produced and maintain them. A provider with strong RASP implementation but no formal security testing process in their development pipeline will receive findings on the organisational side that are just as blocking as technical gaps. In our pre-assessment engagements, we review both dimensions – technical and organisational – and deliver a prioritised remediation plan before the QSSE clock starts.
Who is responsible for certification – the software provider or the merchant?
MPoC/sPOC/CPOC certification is the responsibility of the software provider, not the merchant.
Division of responsibilities:
SoftPOS provider:
- Obtains and maintains MPoC/sPOC/CPOC certification
- Is responsible for application security and updates
- Must notify PCI SSC of significant changes to the application
- Provides merchants with an AOC or equivalent document confirming certification
Merchant:
- Selects a certified solution from the PCI SSC list
- Is responsible for correct deployment and configuration
- Manages COTS devices in accordance with provider guidelines
- May be eligible for a simplified SAQ path if the provider is certified
Acquirer:
- Verifies that the merchant uses a certified solution
- May require a PCI SSC listing as a condition of the merchant agreement
FAQ – PCI MPoC certification
What is the difference between a SoftPOS solution and a traditional payment terminal?
A traditional terminal is a dedicated, certified hardware device (Ingenico, Verifone, PAX) meeting PCI PTS (Payment Terminal Security) requirements. SoftPOS is an application running on a standard smartphone or tablet (iOS, Android) – a COTS device. SoftPOS is less expensive to deploy and more flexible, but places higher security demands on the software layer.
Does a merchant using SoftPOS still need PCI DSS certification?
Yes – a merchant using SoftPOS remains a PCI DSS merchant and must satisfy the relevant requirements. However, if they use a certified MPoC/sPOC/CPOC solution, their assessment scope is significantly reduced – similar to P2PE. The specific SAQ or certification requirements depend on the extent of data processing at the merchant’s end.
How long is MPoC certification valid?
Certification is valid for 3 years. The provider must notify PCI SSC of significant changes to the solution during the validity period – a new major version may require a fresh evaluation.
How much does MPoC pre-assessment preparation with Patronusec cost?
An MPoC pre-assessment covers documentation review, application code analysis against security requirements, and organisational process assessment. Cost depends on solution complexity and review scope. Patronusec provides a fixed-price quotation after a free initial call.
Can BLIK be considered a CPOC solution?
BLIK is a local instant payment scheme operating through a different model – the customer generates a code on their banking app and the merchant enters it into a terminal. Contactless BLIK via NFC (available in some implementations) is a separate scheme. CPOC specifically refers to NFC contactless card payments on a COTS merchant device.
What are the most common gaps found in MPoC pre-assessments?
Insufficient RASP implementation (the application does not detect debugging or hooking), absence of a documented SDLC with security gates at each phase, incomplete Vulnerability Disclosure Policy, weak code obfuscation, and missing integrity verification at application launch. A pre-assessment typically identifies 5 to 15 areas requiring work before formal QSSE evaluation.
MPoC, sPOC and CPOC certification – free consultation
Patronusec as an accredited QSA supports SoftPOS providers in preparing for PCI SSC certification – from technical pre-assessment through certification project management to QSSE selection support.
In a free 30-minute consultation we will help you:
- Understand the differences between MPoC, sPOC and CPOC and choose the right certification path
- Assess the current technical and organisational readiness of your SoftPOS solution
- Estimate the time and cost of preparing for formal QSSE evaluation
- Plan the pre-assessment scope before the formal evaluation begins
Free consultation | PCI DSS certification | Penetration testing | vCISO | PCI SSF certification