PCI SSC released additional MPoC guidance to support consistent interpretation of MPoC v1.1 requirements across solution providers, laboratories, and the mobile payment ecosystem.
What changed
The guidance supports interpretation of MPoC v1.1; it is not a shortcut around the standard. Responsibilities can span the solution provider, software, device controls, monitoring, laboratories, acquirers, and processors.
Buyer and integrator analysis
For Android POS and softPOS projects, hardware selection, payment application design, attestation, monitoring, and assessment readiness need to be planned as one security scope.
Project checklist
- Define the acceptance model: dedicated POS, softPOS, or a hybrid deployment.
- Identify MPoC components, responsible parties, and required evidence.
- Align device updates, attestation, monitoring, assessment, and rollout timing.
From industry signal to implementation
Use this update as an input to requirements and validation, then confirm the final hardware, software, certification, and deployment scope for your market.
Explore the related Cairan capabilityContent note: This section is based on public updates from industry organizations, with practical interpretation from Cairan Technology for smart-terminal procurement and system integration. Publication dates follow the original sources.