FAQ
Frequently Asked Questions
Answers to common questions about SoftPOS, PCI MPoC certification, payment security, integration, and the Mypinpad platform.
What Is SoftPOS?
SoftPOS (Software Point of Sale) turns a standard commercial device — such as a smartphone or tablet — into a contactless payment terminal. Instead of dedicated hardware, the payment acceptance runs as software on the device, using its built-in NFC antenna to read contactless cards and mobile wallets. The transaction is secured through PCI MPoC-validated software-based security rather than tamper-resistant hardware.
A SoftPOS SDK is embedded into a payment application on the merchant’s device. When a customer taps their contactless card or mobile wallet, the device’s NFC antenna reads the card data. The SDK manages the EMV transaction flow — selecting the correct payment kernel, handling cryptographic operations, and communicating with the payment backend. PIN entry, when required, uses a secure on-screen interface with randomised key layouts and protected memory. The transaction is authorised through the acquirer’s processing network, just like a traditional terminal.
A traditional POS terminal is a dedicated hardware device with a tamper-resistant security module. SoftPOS achieves equivalent security through software running on a standard commercial device (phone, tablet, or purpose-built hardware). Key differences: SoftPOS eliminates hardware procurement and logistics, deploys in minutes rather than weeks, updates over-the-air, and can run on devices merchants already own. Both must meet PCI security standards — traditional terminals under PCI PTS, SoftPOS under PCI MPoC.
mPOS (mobile Point of Sale) uses a smartphone paired with a small hardware card reader (dongle) that handles the secure payment processing. SoftPOS eliminates the dongle entirely — the payment acceptance runs purely in software on the device itself. SoftPOS offers lower cost (no hardware accessory), simpler logistics (nothing to ship or replace), and a cleaner merchant experience. Both accept contactless payments; SoftPOS also supports PIN entry on the device screen for higher-value transactions.
COTS stands for Commercial Off-The-Shelf — any mass-produced consumer or commercial device not purpose-built for payment acceptance. In the context of PCI MPoC (Mobile Payments on COTS), it refers to smartphones, tablets, and similar devices that can accept payments through certified software rather than specialised hardware.
PIN on Glass (also called PIN on Mobile) allows a cardholder to enter their PIN directly on a device’s touchscreen rather than on a dedicated PIN pad. The PIN entry interface uses security measures including randomised key positions, protected screen regions, and encrypted memory to prevent the PIN from being intercepted. This is validated under PCI MPoC and enables higher-value contactless transactions that exceed the no-PIN limit.
Security
Yes. SoftPOS solutions validated under PCI MPoC meet 192 individual security conditions covering device integrity, software security, cryptographic key management, and ongoing monitoring. Mypinpad is additionally validated as a PCI DSS v4.0.1 Level 1 Service Provider, holds ISO 27001:2022 certification, and carries Visa and Mastercard scheme approvals. The security model uses software-based trusted execution environments, runtime application self-protection, code obfuscation, and continuous attestation to achieve security equivalent to dedicated hardware terminals.
SoftPOS achieves an equivalent level of payment security through different means. Traditional terminals rely on tamper-resistant hardware modules; SoftPOS relies on software-based security controls validated under PCI MPoC. Both standards are maintained by the PCI Security Standards Council and require regular recertification. PCI MPoC was specifically designed to ensure COTS devices can securely accept payments, including PIN entry, without dedicated security hardware.
The PIN entry interface runs in a PCI MPoC-validated trusted execution environment isolated from the rest of the device. Security measures include: randomised key layouts that change with each entry, protected screen regions that prevent screenshot or overlay attacks, encrypted memory that prevents PIN interception, and runtime integrity checks that detect device compromise. The PIN is encrypted at the point of entry and is not stored on the device.
Mypinpad’s attestation and monitoring service continuously checks device integrity before, during, and after transactions. If malware, rooting, debugging tools, or other compromise indicators are detected, the payment application is automatically disabled and the device is flagged. Transactions cannot proceed on a compromised device. This continuous monitoring is a mandatory component of PCI MPoC certification.
Cardholder data (PAN and PIN) is protected through multiple layers: point-to-point encryption from the moment of capture, secure key management validated under PCI PIN, isolated processing environments that prevent data leakage to other applications, and immediate secure transmission to the payment backend. No sensitive cardholder data is stored on the merchant’s device at any point.
Consumer acceptance has grown rapidly, driven by Apple Tap to Pay and Google Tap to Pay normalising the experience. The tap interaction is identical to tapping on a traditional terminal — the customer sees the familiar contactless symbol and taps their card or phone. Studies show that once consumers complete their first SoftPOS transaction, trust is established. Merchants can further build confidence through branded payment screens (via white-labelling) and visible scheme logos.
Certifications & Compliance
PCI MPoC (Mobile Payments on COTS) is the PCI Security Standards Council’s security standard for accepting contactless payments and PIN entry on commercial off-the-shelf devices. It replaced the earlier CPoC and SPoC standards, unifying them into a single framework with 192 security conditions. MPoC certification has three components: Software (the SDK), Attestation & Monitoring (ongoing security checks), and Solution (the complete merchant-facing product).
Mypinpad is listed and validated against PCI MPoC v1.1 across all three sub-programmes: Software, Solution, and Attestation & Monitoring Services. It is validated as a PCI DSS v4.0.1 Level 1 Service Provider, validated against PCI PIN v3.1 for PIN management and processing, and is a PCI PPO (Principal Participating Organisation) member. Beyond PCI, Mypinpad holds ISO 27001:2022 certification across the full organisation. Every PCI listing is checkable on the PCI SSC public registry.
CPoC (Contactless Payments on COTS) covered contactless-only acceptance without PIN. SPoC (Software-based PIN on COTS) covered PIN entry using a secure card reader. MPoC (Mobile Payments on COTS) replaced both standards, unifying contactless acceptance and PIN entry into a single framework. MPoC is now the active standard. New CPoC and SPoC submissions close on 31 October 2026; after that, new listings are MPoC only. Existing CPoC and SPoC listings remain valid until their expiry dates.
Check the PCI Security Standards Council’s public registry of validated MPoC products. It is searchable and free. Look at which sub-programmes the vendor holds, which version of the standard they are validated against, and the stated scope. A vendor holding one sub-programme and a vendor holding all three can both say they are MPoC validated — the registry shows the difference, and that difference lands in your compliance scope.
PCI PTS v5 reaches its hard stop on 30 April 2027, after which PTS v5 terminals can no longer be shipped or deployed as new. Acquirers must either source PTS v6-compliant terminals (which face supply chain constraints and limited availability) or adopt SoftPOS as a complement or replacement. This deadline is driving strategic re-evaluation of terminal estates across the industry.
Yes. Mypinpad is ISO 27001:2022 certified and compliant with GDPR, PCI DSS v4.0.1, and applicable regional data protection regulations across the 28 countries where we operate. Personal data processing follows data minimisation principles, and cardholder data handling complies with PCI DSS requirements.
Mypinpad handles the ongoing compliance burden as part of the platform. Our Attestation & Monitoring service provides continuous security monitoring, device integrity checking, and compliance evidence gathering. Annual MPoC recertification and penetration testing are managed by Mypinpad. Customers do not need their own MPoC certification: the only MPoC step is an application integration review, which Mypinpad carries out, with no lab review. L3 testing with your acquirer usually still applies, as with any deployment.
Integration & Technical
Mypinpad offers multiple integration paths: SDK integration (native Android or iOS, or a Flutter wrapper on request) for embedding payment acceptance into your existing application; white-label apps (pre-built, branded payment applications ready to deploy); or deeplink integration (launch payment flows from your existing app with minimal code changes). SDK integration takes four to six weeks with direct-to-customer, MPGS or Cybersource routing; host integrations into your own environment take longer, depending on the work.
Both. The Mypinpad SDK handles the on-device payment acceptance — NFC communication, EMV kernel selection, cryptographic operations, and PIN entry. The backend API handles transaction authorisation, reporting, and device management. For the simplest integration, two API calls are required: get the terminal ready, then start a transaction.
SDK integration takes four to six weeks with direct-to-customer, MPGS or Cybersource routing; host integrations into your own environment take longer, depending on the work. Fygaro went from integration start to live in 6 weeks on the SDK. Deeplink integration is usually the quickest, often completed in one to two weeks.
Mypinpad supports Android smartphones and tablets on Android 10 or later, and iPhone through Apple Tap to Pay on iPhone (iOS 18.4 or later, iPhone XS or newer). The platform also runs on purpose-built SoftPOS hardware, enterprise fleet devices, and consumer BYOD devices. A device needs NFC and must pass the platform's security checks, such as hardware-backed key storage and no rooting or jailbreak.
Yes. Mypinpad provides a sandbox environment for development and testing. Contact our developer relations team to request access, along with SDK documentation, sample code, and integration guides.
Mypinpad provides the complete backend infrastructure — transaction processing, key management, device monitoring, and attestation services. Your integration connects to Mypinpad’s APIs. You need an existing acquirer or processor relationship for transaction authorisation and settlement, but Mypinpad handles the payment acceptance technology layer.
Yes. Mypinpad is designed to complement existing terminal deployments, not replace them overnight. Acquirers and PSPs can deploy SoftPOS alongside traditional terminals, enabling a gradual migration or a hybrid strategy where SoftPOS serves use cases (mobile merchants, queue busting, temporary locations) that traditional terminals cannot efficiently address.
Business & Commercial
SoftPOS eliminates hardware procurement, shipping, installation, maintenance, and end-of-life replacement costs. A traditional terminal typically costs $200–$500 per device plus ongoing maintenance, with a 3–5 year replacement cycle driven by PCI PTS expiry. SoftPOS runs on devices merchants already own, with costs based on transaction volume or subscription rather than hardware. The result is a significantly lower total cost of ownership, particularly at scale.
Mypinpad offers flexible pricing models tailored to the customer’s deployment size and business model. Options include per-transaction fees, monthly subscription per active device, or volume-based licensing. Contact our team for pricing details specific to your deployment scale and requirements.
Yes, for a limited period. Attestation & Monitoring Services, the third MPoC sub-programme, permits offline operation: if the connection or our backend is unavailable, merchants keep taking payments for up to 24 hours, then the device reconnects and re-attests. Offline transactions are stored and forwarded for authorisation once the connection returns, subject to the acquirer’s offline processing rules.
Transaction limits are set by card schemes and acquirers, not by SoftPOS technology itself. Contactless transactions below the scheme’s CVM (Cardholder Verification Method) limit proceed with a tap only. Above the CVM limit, PIN entry is required — which Mypinpad fully supports through PCI MPoC-validated PIN on Glass. There is no inherent technology limit on transaction value.
Mypinpad accepts all major contactless payment methods: Visa, Mastercard, American Express, JCB, Discover, Diners Club, UnionPay, eftpos, Interac, RuPay, Elo, BankAxept and Dankort contactless cards and stickers, plus Apple Pay, Google Pay, Samsung Pay, and other NFC-enabled mobile wallets. Thirteen schemes are in production, running on eight EMV contactless kernels developed in-house (our proprietary Walnut kernel suite).
Refunds and voids are processed through the Mypinpad platform in accordance with the acquirer’s rules. A void cancels a transaction before settlement (typically same-day). A refund reverses a settled transaction and can be initiated through the payment application or backend management interface. Both are logged and auditable.
Digital receipts can be delivered via email, SMS, or displayed on-screen for the customer to photograph. The receipt format is configurable through the white-label application or SDK integration. Paper receipt printing is supported through Bluetooth-connected receipt printers where required.
Vendor Lock-in & Independence
Mypinpad is independent by design — not controlled by a card scheme, acquirer, or hardware manufacturer. Your acquirer relationships, merchant relationships, and transaction data remain yours. The platform supports multi-acquirer routing, so you can work with multiple processors without re-integration. If you choose to migrate away, your operational data and merchant relationships are not tied to our platform.
No. Mypinpad is a B2B platform provider. We do not acquire merchants, process transactions as a PSP, or sell payment hardware. Our business model is aligned with our customers’ success — we grow when you grow. This structural independence means your competitive interests are never at odds with ours, unlike scheme-owned, acquirer-captive, or OEM-bundled alternatives.
Yes. Mypinpad supports multi-acquirer and multi-processor configurations. Adding or switching an acquirer is a backend configuration change, not a re-integration of the SDK or payment application. This flexibility protects your ability to negotiate competitive processing rates.
You do. Mypinpad processes transactions on your behalf but does not claim ownership of your transaction data. Data handling is governed by your agreement and complies with PCI DSS and applicable data protection regulations.
Scheme-owned solutions serve the scheme’s interests first. They may restrict multi-scheme acceptance, limit your ability to differentiate, or create dependencies that affect your negotiating position. Mypinpad supports all major schemes equally — thirteen in production — on EMV kernels we develop and certify ourselves, giving you a multi-scheme strategy without vendor bias.
Building SoftPOS in-house requires: developing and certifying EMV contactless kernels (multi-year effort), achieving PCI MPoC certification (192 security conditions, plus scheme certification with each acquirer), building attestation and monitoring infrastructure, and maintaining ongoing compliance. Mypinpad has invested over a decade in this capability. Our customers deploy in weeks, not years, under our existing certifications.
White-Labelling & Customisation
Yes. Every customer-facing element of Mypinpad’s platform is white-labelled to your brand — the payment application, merchant onboarding, transaction screens, and receipts all carry your branding. Merchants and cardholders see your brand, not Mypinpad’s.
Four options: (1) SDK integration — embed payment acceptance into your existing application; (2) White-label app — a pre-built, fully branded payment application ready to deploy; (3) Deeplink integration — launch payment flows from your app with minimal integration; (4) Hybrid — combine SoftPOS with traditional terminals in a unified fleet. Choose based on your technical capacity, time-to-market requirements, and merchant experience preferences.
Full control. The SDK exposes configurable UI elements, and the white-label app supports custom branding, colour schemes, logos, and payment flow sequences. You control the onboarding flow, merchant management, and operational processes through APIs and management tools.
Migration & Deployment
Migration is typically phased: start with new merchant segments (mobile, temporary, event-based) where SoftPOS has a natural advantage, then expand to existing merchants as terminals reach end-of-life or PCI PTS expiry. Mypinpad supports parallel operation — SoftPOS and traditional terminals can coexist in your merchant estate during the transition.
30 April 2027 is the PCI PTS v5 hard stop: the last date for deploying new PTS v5 terminals. After this date, only PTS v6-compliant terminals can be shipped — but supply chain constraints and certification backlogs mean availability is limited. Acquirers should evaluate SoftPOS now as either a complement or alternative to hardware terminals. Contact our team to discuss your terminal strategy.
Minimal. SoftPOS is designed to be intuitive — merchants tap to accept payment, just as customers tap to pay. Mypinpad provides onboarding guides and in-app guidance. Most merchants are operational within minutes of downloading the application. For enterprise deployments, we provide training materials that can be customised to your requirements.
Platform Capabilities Beyond Payments
Yes. The Maple platform spans three pillars: Payments (merchant and consumer device acceptance), Authentication (identity verification, card activation, PIN change, step-up authentication, KYC), and Software & Services (white-label apps, EMV kernel licensing, data APIs, professional services). All run on the same certified platform.
Tap to Activate allows cardholders to activate a new payment card by tapping it on their smartphone through the bank’s mobile app. This replaces the traditional process of calling a phone number, visiting a branch, or using an ATM. The card tap provides cryptographic proof of card possession, offering stronger authentication than traditional methods.
Tap to Verify uses a contactless card tap as an identity verification factor. A cardholder taps their payment card on their device to cryptographically prove card possession. This can be used for KYC verification, step-up authentication for high-risk transactions, or converting a card-not-present online transaction to a card-present transaction (reducing fraud risk and interchange costs).
Yes. Banks and issuers use Mypinpad for card lifecycle management: card activation (Tap to Activate), PIN change, and step-up authentication — all from the bank’s mobile app, without requiring a branch visit, ATM, or call centre. The cryptographic card tap provides stronger authentication than OTPs or passwords, meeting PSD2/SCA requirements.
Scale & Enterprise
Mypinpad handles 10.5 million+ monthly transactions across 1.8 million+ merchants in 28 countries, serving 10 million+ consumers. The platform is designed for enterprise scale with high availability and global deployment capability.
Mypinpad is deployed across 28 countries spanning Europe, North America, Latin America, Asia-Pacific, and Oceania. The platform supports domestic payment schemes (eftpos in Australia, Interac in Canada, RuPay in India, Elo in Brazil, BankAxept in Norway, Dankort in Denmark) alongside global schemes (Visa, Mastercard, Amex). Contact us for availability in your target markets.
Thirteen schemes are in production, meaning a customer can take them to Level 3 certification with their acquirer today: Visa, Mastercard, American Express, JCB, Discover, Diners Club, UnionPay, eftpos, Interac, RuPay, Elo, BankAxept and Dankort. Jaywan and Bancomat are in development, with Cartes Bancaires and Bancontact on the roadmap. Most providers cover the global schemes; domestic coverage is rarer, and it is what lets a merchant accept the cards their customers actually carry. Expected timings are on the capability map at /platform/capabilities.
Eight certified EMV contactless kernels, all developed in-house (our proprietary Walnut kernel suite): Visa, Mastercard, American Express, JCB, Discover, eftpos, Interac and RuPay. UnionPay has completed testing and is awaiting its letter of approval; PURE and Bancomat are in development and CPACE is on the roadmap. Several schemes are accepted through another scheme’s kernel, which is why thirteen schemes run on eight kernels. Mypinpad develops and owns every kernel and maintains every Level 2 approval itself, so the capability is end to end, from card tap to certification, with no third-party dependency in the critical payment path.
Support & Operations
99.99%, contractual on direct-to-customer deployments (DTC-GW and D2A-hard). Other deployment routes carry the service level set out in your agreement, with defined incident response times and escalation procedures.
Mypinpad provides technical support for integration and ongoing operations, developer documentation, and dedicated account management for enterprise customers. Support includes incident management, software updates, and compliance maintenance. Response time commitments are defined in your SLA.
Updates are delivered over-the-air through the SDK or white-label application — no physical device touch required. Security patches, new payment scheme support, and feature updates are rolled out centrally, ensuring all devices in your merchant estate stay current and compliant.
For Banks & Acquirers
Mypinpad manages country-specific compliance requirements as part of the platform. Our PCI MPoC listing, PCI DSS v4.0.1 validation and ISO 27001 certification are internationally recognised, and our scheme coverage includes domestic schemes such as eftpos in Australia, Interac in Canada, RuPay in India, Elo in Brazil, BankAxept in Norway, Dankort in Denmark. Cross-border deployment is a configuration exercise, not a new MPoC certification; local L3 testing with your acquirer usually still applies.
Mypinpad supports per-transaction, per-active-device, and volume-based licensing models. For large acquirers, we also offer white-label SDK licensing where the acquirer operates the platform under their own infrastructure. All commercial terms are negotiated to fit the deployment scale and business model. Contact our team to discuss the right structure for your portfolio.
SDK integration takes four to six weeks with direct-to-customer, MPGS or Cybersource routing; host integrations into your own environment take longer, depending on the work. A deeplink integration can be live in one to two weeks. Mypinpad's certifications are already in place: the only MPoC step is the application integration review, which we carry out.
Mypinpad is not controlled by any card scheme, acquirer, or hardware manufacturer. Our eight EMV kernels are developed and certified in-house — separate certifications for Visa, Mastercard, Amex, and five other schemes, with no preferential routing or scheme dependency. You retain full control over scheme relationships and can route transactions through multiple acquirers without re-integration.
Competitive Differentiation
Four structural advantages: (1) Independence — Mypinpad is independent from card schemes, acquirers and hardware vendors, and never competes with its customers; (2) Operational scale — 10.5M+ monthly transactions across 28 countries, with every component (SDKs, EMV kernels, backend) developed, maintained and operated entirely in-house, ISO 27001:2022 certified; (3) Certification depth — PCI SSC Board of Advisors member, listed and validated against PCI MPoC v1.1 across all three sub-programmes; (4) Platform breadth — payments, authentication and verification on one platform, not a single-purpose tool.
Your SoftPOS provider’s business model determines whether they’re a partner or a competitor. Scheme-owned vendors prioritise the scheme’s interests. Acquirer-owned vendors compete for your merchants. OEM vendors have hardware revenue to protect. Mypinpad’s independence means our commercial interests are structurally aligned with yours — we succeed when you succeed.
Yes. Mypinpad supports Android (Android 10 or later) and iOS through Apple Tap to Pay on iPhone (iOS 18.4 or later). Acquirers and PSPs can offer payment acceptance on the devices their merchants already use, on either platform.
Yes. The platform runs on standard smartphones, tablets, purpose-built SoftPOS hardware, and rugged enterprise devices. This flexibility supports diverse deployment scenarios — from delivery drivers using their own phones to retail chains deploying managed enterprise devices.
Building in-house means multi-year kernel development, MPoC validation against 192 security conditions, and ongoing compliance to maintain — before the first transaction. Scheme-owned solutions restrict multi-scheme flexibility and create dependency. Mypinpad provides independent, multi-scheme capability with ongoing compliance managed as a service.
Still have questions?
Our team is ready to discuss your specific requirements and help you evaluate SoftPOS for your business.