Opinion
As CPoC and SPoC sunset deadlines loom, why are so many providers still exploiting scheme waivers rather than committing to MPoC?
This month I decided to take a closer look at why so many Mypinpad SoftPOS competitors seem intent on continuing to exploit scheme waivers rather than committing to the PCI Mobile Payments on COTS (MPoC) standard?
Proper MPoC is hard. That is not a reason to keep dodging it
Ask anyone in payments where SoftPOS is heading and you get the same answer: MPoC. The PCI Mobile Payments on COTS standard is the destination the whole industry has agreed on several years ago.
So much so that both the PCI Contactless Payments on COTS (CPoC) and Software-based PIN Entry on COTS (SPoC) standards were put into their formal sunset periods by the PCI Security Standards Council three months ago. The body will stop accepting new submissions on these standards on 31 October 2026.
By retiring CPoC, the Council is phasing out the standalone contactless-only software standard as the industry transitions to the more comprehensive mobile payment framework MPoC. On paper, the whole industry is heading towards the same door. However, closer observation indicates that many are not stepping straight through that door with enthusiasm, but instead are queuing up in front of it.
Look at what is actually happening: solutions built on CPoC and older scheme approvals are being kept alive on scheme waivers. These are bridging arrangements that let providers carry on deploying payment solutions using CPoC and SPoC while continuing to work towards full MPoC.
Waivers buy time
There is nothing improper about waivers. The schemes grant them for good reasons, and serious companies are using them well. However, we should all be more honest about what a waiver is for: it buys additional time to get your tech right and complete high performance compliance with the emerging defacto standard. It begs the question, why are so many major payments providers choosing to buy that time today?
Here is what I think most of us will not say out loud: the reason full MPoC feels like something to defer rather than complete now is a quiet belief that proper MPoC cannot process payments fast enough to meet merchant and consumer expectations.
That concern is reasonable. MPoC does not simply ask you to certify a PIN pad and a contactless kernel. It requires continuous, real-time attestation and monitoring. The software must check itself and its environment, reporting to a back end, both before and during transactions. It must also offer a fallback when the device goes offline mid-transaction. Every one of those checks takes milliseconds. Stack enough of them onto a commodity device and the fear writes itself: a secure transaction so slow the merchant gives up and a queue of disgruntled customers builds up. If that were true, using a waiver would not be a dodge — it would make good business sense.
Median merchant wait time already down to 1.3 seconds
But it is not true and we can now show it is not! On business-grade devices i.e. the mid-tier and above hardware that a real merchant would actually want to deploy, Mypinpad is now measuring a median merchant wait time of 1.3 seconds using MPoC, with 80% at 2.6 seconds or less. Merchant wait time is a measure of frustration where a user is waiting for an app to respond and so excludes user interactions like tapping a card or PIN entry. Before everyone cries foul, lower end devices commonly used by micro-businesses still have respectable merchant wait time median of 2.8 seconds.
Our total transaction speeds from start to completion, including the card/device tap itself and running the complete MPoC-compliant stack, including attestation and monitoring live, now averages under four seconds — making a 'SoftPOS First' strategy a viable proposition in many markets already.
That figure excludes PIN entry, deliberately: PIN time belongs to the human and, as we all know, people's PIN entry speed varies enormously. In addition, an increasing percentage of in-store transactions no longer demand PIN entry, especially now that the UK regulatory £100+ cap (before PIN is required) has been removed. Banks can now choose their own limits or remove them entirely. Strip out the human and the platform holds its speed with full compliance switched on in real conditions. These times were not gathered in a tech lab or demo conditions but in the real retail world.
These numbers matter because they nullify the trade-off that the entire waiver conversation rests on. You do not have to choose between proper MPoC and terminal-grade performance anymore. You can have both!
Furthermore, today's numbers are a floor, not a ceiling. We expect them to keep going down as we refine our MPoC-specific Maple platform; as commodity hardware gets faster with each generation; and as purpose-built, business-grade SoftPOS devices reach the market in greater numbers. The direction of travel is running only one way: the compliance overhead that defined the fear is shrinking rapidly.
Large-scale 'SoftPOS First' deployments coming
A word on scope because this is where SoftPOS has oversold itself before. The early pitch was 'turn any phone into a terminal for any handset, any pocket, no extra hardware required'. That was always more of a slogan than a genuine strategy. The honest and frankly more valuable opportunity is different: multi-branch, even multi-country merchants and the PSPs serving them, can now simultaneously roll out 'SoftPOS First' payment solutions on hundreds, even thousands of devices handpicked for the job. Think of the capability you would get from a dedicated payment terminal, on standard hardware, without the existing terminal's cost base, closed supply chain and refresh cycle.
Hardware to software shift
To be precise, because precision matters here: this does not offer the same security as a PTS-approved terminal at a lower price. It is a different model. The assurance moves from tamper-resistant hardware to software protection plus real-time monitoring — a model the PCI has examined and now accepts as sufficient for the risk. You are not buying cheaper secure hardware. You are buying a security architecture that no longer needs it.
So here is the position I would put to the industry: the waiver was a bridge and bridges are useful but are no longer necessary. Proper MPoC, at a speed merchants will happily live with, on the devices a business actually wants to deploy, is no longer an R&D problem. It is a build problem and it has now been built and is ready to deploy globally.
This fact turns the waiver from a technical necessity into a commercial choice. Some will use the remaining runway of scheme waivers to complete the tech hard work properly. Others will use it to defer that work for another cycle.
However, when the bridges come down — and they will — those that are over-reliant on those bridges will be easy to tell apart from those that have completed the hard yards to make business-grade MPoC ready. Hard is never the same as impossible. It is time we stopped treating it as if it is.
Talk to Us
Ready to explore what Mypinpad can do for you?
Certified. Independent. Deployed across 28 countries. Let's talk about your use case.
Get in Touch