Skip to main content

Developers

PCI MPoC certification, stated precisely

Compliance claims in payments are easy to overstate and hard to verify from the outside. This page states exactly what Mypinpad holds, exactly what it covers, and exactly how you can confirm any of it yourself.

What Mypinpad holds

Every component of the platform — SDKs, EMV kernels and backend infrastructure — is developed, maintained and operated entirely in-house.

PCI MPoC v1.1

Listed and validated across all three sub-programmes: Software, Solution, and Attestation & Monitoring Services.

PCI DSS v4.0.1

Validated as a Level 1 Service Provider.

PCI PIN v3.1

Validated for PIN management and processing.

ISO 27001:2022

Certified.

What all three sub-programmes actually means

PCI MPoC — Mobile Payments on COTS — covers software-based PIN entry and contactless acceptance on standard commercial devices. A vendor can be listed against one, two or all three.

Software

The MPoC-listed application component itself.

Solution

The complete solution built on that component, evaluated as a whole.

Attestation & Monitoring Services

The ongoing service that attests to the deployed solution's continued integrity and monitors it in operation.

Depth matters here more than the headline. A vendor listed only under Software has had one part of the picture assessed; the Solution and Attestation & Monitoring sub-programmes examine what happens once that component is deployed and running.

Your obligations do not disappear because ours are in order

What Mypinpad holds covers the Mypinpad platform. It does not automatically cover your integration, and not every standard applies to every integration in the same way.

PCI MPoC, PCI DSS and PCI PIN each define a scope, and where your responsibility sits within that scope depends on how you have built on the platform — which integration route you chose, what your application does with cardholder data, and what your acquirer or scheme relationship requires of you directly. A payment facilitator integrating our SDK into a broader app has a different compliance position from an acquirer white-labelling Wattle across its whole merchant base, even though both sit on the same underlying platform.

We would rather say this plainly than let a page of logos imply the question is settled. Confirm your own position with your QSA, your acquirer or your scheme relationship before you assume Mypinpad's status closes out an obligation of yours.

What you will be asked to do

  • Pass Mypinpad's application review before go-live, and confirm it each year
  • Complete the scheme certifications your acquirer and schemes require, including Level 3 testing
  • Keep credentials off the device and your production app hardened
  • Keep the SDK current under the update policy

Standards that may apply to you

  • PCI DSS
  • PCI MPoC
  • PCI PIN
  • EMV contactless specifications
  • PSD2 and strong customer authentication
  • UK GDPR and data protection law

Not every standard applies to every integration, and local rules can add more. Your compliance team confirms which apply to you.

Check any vendor's claims yourself

Do not take a compliance claim at face value — from Mypinpad or anyone else you are evaluating.

For PCI MPoC, PCI DSS and PCI PIN, the PCI Security Standards Council publishes a list of validated solutions and service providers on its website, searchable by vendor name and standard. Search for the vendor, confirm the standard and sub-programme you need, and check the listing is current rather than expired — validations run on a cycle, and a vendor can be listed today and have let one lapse.

For ISO 27001, ask the vendor for their current certificate and the name of the accredited body that issued it, then verify with that body directly if the claim matters to your decision.

This is not a step we are asking you to take because we are worried what you will find. It is worth taking with any vendor: a claim you can verify yourself is worth more than one you are asked to trust.

Request sandbox access

Reading a registry entry only gets you so far. The sandbox lets you see how the platform behaves against your own integration.

Talk through your own scope

If you are not sure where the line falls for your integration, raise it before you build.