Framework · Last verified

Mobile Payments on COTS (MPoC)

MPoC is PCI SSC's standard for accepting PIN and contactless card data on one COTS device, evaluated by PCI-Recognized Laboratories. PCI SSC states it is for entities developing, deploying, or managing solutions accepting both PIN and contactless data on the same device.

Class
Framework
Owner
PCI Security Standards Council (PCI SSC)
Last verified

What it is

PCI SSC's own scope statement: "For entities developing, deploying, or managing solutions which accept both PIN and contactless cardholder data on the same COTS device."

PCI SSC positions MPoC as combining and extending two earlier, separate standards: "PCI Mobile Payments on COTS (MPoC) builds on the existing PCI Software-based PIN Entry on COTS (SPoC) and PCI Contactless Payments on COTS (CPoC) Standards." PCI SSC does not use the word "replaces" or "retires" for this relationship on the page reviewed — the relationship is stated only as "builds on," alongside the separate sunset timeline announced for SPoC and CPoC.

The current version is 1.1, last updated 2024-11-25, per PCI SSC's own document-library data — no later version was found.

Who owns it

The standard is owned and published by the PCI Security Standards Council (PCI SSC).

Who assesses it

PCI SSC states: "Independent PCI-Recognized MPoC Laboratories evaluate MPoC solutions against the requirements of the PCI MPoC Standard." This is a laboratory-evaluation model, not the Qualified Security Assessor (QSA) model used for PCI DSS.

Who asks for it

Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself imposes no mandate on any entity.

PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself names no universal requirement.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Mobile Payments on COTS (MPoC)." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/pci-mpoc

All frameworks & audits →