Developers
PCI MPoC certification, stated precisely
Compliance claims in payments are easy to overstate and hard to verify from the outside. This page states exactly what Mypinpad holds, exactly what it covers, and exactly how you can confirm any of it yourself.
What Mypinpad holds
Every component of the platform — SDKs, EMV kernels and backend infrastructure — is developed, maintained and operated entirely in-house.
PCI MPoC v1.1
Listed and validated across all three sub-programmes: Software, Solution, and Attestation & Monitoring Services.
PCI DSS v4.0.1
Validated as a Level 1 Service Provider.
PCI PIN v3.1
Validated for PIN management and processing.
ISO 27001:2022
Certified.
What all three sub-programmes actually means
PCI MPoC — Mobile Payments on COTS — covers software-based PIN entry and contactless acceptance on standard commercial devices. A vendor can be listed against one, two or all three.
Software
The MPoC-listed application component itself.
Solution
The complete solution built on that component, evaluated as a whole.
Attestation & Monitoring Services
The ongoing service that attests to the deployed solution's continued integrity and monitors it in operation.
Depth matters here more than the headline. A vendor listed only under Software has had one part of the picture assessed; the Solution and Attestation & Monitoring sub-programmes examine what happens once that component is deployed and running.
Your obligations do not disappear because ours are in order
What Mypinpad holds covers the Mypinpad platform. It does not automatically cover your integration, and not every standard applies to every integration in the same way.
PCI MPoC, PCI DSS and PCI PIN each define a scope, and where your responsibility sits within that scope depends on how you have built on the platform — which integration route you chose, what your application does with cardholder data, and what your acquirer or scheme relationship requires of you directly. A payment facilitator integrating our SDK into a broader app has a different compliance position from an acquirer white-labelling Wattle across its whole merchant base, even though both sit on the same underlying platform.
We would rather say this plainly than let a page of logos imply the question is settled. Confirm your own position with your QSA, your acquirer or your scheme relationship before you assume Mypinpad's status closes out an obligation of yours.
What you will be asked to do
- Pass Mypinpad's application review before go-live, and confirm it each year
- Complete the scheme certifications your acquirer and schemes require, including Level 3 testing
- Keep credentials off the device and your production app hardened
- Keep the SDK current under the update policy
Standards that may apply to you
- PCI DSS
- PCI MPoC
- PCI PIN
- EMV contactless specifications
- PSD2 and strong customer authentication
- UK GDPR and data protection law
Not every standard applies to every integration, and local rules can add more. Your compliance team confirms which apply to you.
Check any vendor's claims yourself
Do not take a compliance claim at face value — from Mypinpad or anyone else you are evaluating.
For PCI MPoC, PCI DSS and PCI PIN, the PCI Security Standards Council publishes a list of validated solutions and service providers on its website, searchable by vendor name and standard. Search for the vendor, confirm the standard and sub-programme you need, and check the listing is current rather than expired — validations run on a cycle, and a vendor can be listed today and have let one lapse.
For ISO 27001, ask the vendor for their current certificate and the name of the accredited body that issued it, then verify with that body directly if the claim matters to your decision.
This is not a step we are asking you to take because we are worried what you will find. It is worth taking with any vendor: a claim you can verify yourself is worth more than one you are asked to trust.
Reading a registry entry only gets you so far. The sandbox lets you see how the platform behaves against your own integration.
Talk through your own scope
If you are not sure where the line falls for your integration, raise it before you build.