Payment security

PCI SSC publishes implementation guidance for Mobile Payments on COTS

PCI SSC released additional MPoC guidance to support consistent interpretation of MPoC v1.1 requirements across solution providers, laboratories, and the mobile payment ecosystem.

In brief

PCI SSC released additional MPoC guidance to support consistent interpretation of MPoC v1.1 requirements across solution providers, laboratories, and the mobile payment ecosystem.

What changed

The guidance supports interpretation of MPoC v1.1; it is not a shortcut around the standard. Responsibilities can span the solution provider, software, device controls, monitoring, laboratories, acquirers, and processors.

Buyer and integrator analysis

For Android POS and softPOS projects, hardware selection, payment application design, attestation, monitoring, and assessment readiness need to be planned as one security scope.

Project checklist

  • Define the acceptance model: dedicated POS, softPOS, or a hybrid deployment.
  • Identify MPoC components, responsible parties, and required evidence.
  • Align device updates, attestation, monitoring, assessment, and rollout timing.

From industry signal to implementation

Use this update as an input to requirements and validation, then confirm the final hardware, software, certification, and deployment scope for your market.

Explore the related Cairan capability

Content note: This section is based on public updates from industry organizations, with practical interpretation from Cairan Technology for smart-terminal procurement and system integration. Publication dates follow the original sources.

Ready to discuss your smart terminal integration project?

Tell us your business scenario, existing system, target hardware, and timeline. We will respond with the right next step.

Tell Us Your Scenario