Framework · Last verified
Mobile Payments on COTS (MPoC)
MPoC is PCI SSC's standard for accepting PIN and contactless card data on one COTS device, evaluated by PCI-Recognized Laboratories. PCI SSC states it is for entities developing, deploying, or managing solutions accepting both PIN and contactless data on the same device.
- Class
- Framework
- Owner
- PCI Security Standards Council (PCI SSC)
- Last verified
What it is
PCI SSC's own scope statement: "For entities developing, deploying, or managing solutions which accept both PIN and contactless cardholder data on the same COTS device."
PCI SSC positions MPoC as combining and extending two earlier, separate standards: "PCI Mobile Payments on COTS (MPoC) builds on the existing PCI Software-based PIN Entry on COTS (SPoC) and PCI Contactless Payments on COTS (CPoC) Standards." PCI SSC does not use the word "replaces" or "retires" for this relationship on the page reviewed — the relationship is stated only as "builds on," alongside the separate sunset timeline announced for SPoC and CPoC.
The current version is 1.1, last updated 2024-11-25, per PCI SSC's own document-library data — no later version was found.
Who owns it
The standard is owned and published by the PCI Security Standards Council (PCI SSC).
Who assesses it
PCI SSC states: "Independent PCI-Recognized MPoC Laboratories evaluate MPoC solutions against the requirements of the PCI MPoC Standard." This is a laboratory-evaluation model, not the Qualified Security Assessor (QSA) model used for PCI DSS.
Who asks for it
Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself imposes no mandate on any entity.
PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands. Questions about which entities need to validate compliance to any PCI SSC standard, or whether use of a PCI-listed product is required and for which entities, should be referred to the payment brands." PCI SSC itself names no universal requirement.
Sources
- PCI Security Standards Council — Mobile Payments on COTS (MPoC) page (scheme owner) ↗ — accessed
- PCI SSC — Software-based PIN Entry on COTS (SPoC) page (cross-referenced: MPoC is stated to build on this standard, which is in its sunset period) ↗ — accessed
- PCI SSC — Contactless Payments on COTS (CPoC) page (cross-referenced: MPoC is stated to build on this standard, which is in its sunset period) ↗ — accessed
- PCI SSC official document-library endpoint — confirms v1.1 (last updated 2024-11-25) is the current version ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.