Why — Certification
PCI MPoC validation — why all three sub-programmes matter
Many vendors claim MPoC certification. Fewer hold all three sub-programmes. Mypinpad is listed and validated against MPoC v1.1 across the complete stack, which lets us run app integration reviews in-house — no third-party lab in your critical path.
What PCI MPoC is — in buyer terms
PCI MPoC (Mobile Payments on COTS) is the PCI Security Standards Council standard for accepting card payments — including PIN entry — on commercial devices such as smartphones and tablets. It defines 192 individual security conditions covering software integrity, cryptographic key management, device attestation, and continuous monitoring.
For acquirers and PSPs, MPoC certification is the gating requirement for new SoftPOS listings. Existing CPoC and SPoC listings remain valid until their expiry dates, but new submissions close on 31 October 2026. With MPoC, any commercially available device can become a certified payment terminal — no hardware procurement, no logistics chain, no terminal refresh cycle.
Three sub-programmes — why all three matter
The three sub-programmes cover different things — the SDK, the solution it sits in, and the monitoring that keeps a deployment in scope. Check any vendor's listing on the PCI SSC registry.
Component 1
Solution
The overall SoftPOS solution — encompassing the SDK, payment flows, kernel integration, and user interface. Assessed against 192 PCI MPoC security requirements.
Without it: Without Solution certification, the SoftPOS product itself is not approved for commercial deployment.
Component 2
Software
The software components that make up the solution — assessed against PCI's software security standard. Covers code security, vulnerability management, and secure development lifecycle.
Without it: Software certification confirms the individual components are secure by design, not just as an assembled product.
Component 3
Attestation & Monitoring
The continuous service that verifies device integrity before and during every transaction. Detects compromise, rooting, debugging tools, and malware in real time.
Without it: The hardest sub-programme to achieve. Without it, the SoftPOS stack cannot monitor for device compromise in production.
Primary differentiator
Validated across all three sub-programmes
PCI MPoC has three sub-programmes — Software, Solution, and Attestation & Monitoring Services. They cover different things: the SDK itself, the complete solution it sits in, and the ongoing monitoring that keeps a deployment within scope.
Mypinpad is listed and validated against PCI MPoC v1.1 across all three. That matters to your assessment because a vendor validated for one sub-programme and a vendor validated for three can both describe themselves as MPoC validated — and the difference lands in your compliance scope, not theirs.
Our listings are on the PCI SSC registry under Mypinpad Ltd. Search the PCI SSC MPoC listings for Mypinpad Ltd (opens in a new tab)
Full certification portfolio
Each certification is what it certifies, why it matters, and what changes for the customer.
Lead credential
PCI MPoC v1.1 — all three sub-programmes
Listed and validated against Software, Solution, and Attestation & Monitoring Services. Checkable on the PCI SSC registry.
PCI PIN v3.1
Validated for the secure management and processing of PINs across our platform. PIN entry on the device itself is covered by PCI MPoC.
PCI DSS v4.0.1 Level 1
Validated as a Level 1 Service Provider — covering Mypinpad's full operational environment.
ISO 27001:2022
Information security management system certification — operational discipline independently verified.
PCI SSC Board of Advisors
Member 2025–2027 — contributing to the payment security standards that govern the industry.
Certification scope and currency vary by listing. Contact us for current certification documentation for your deployment.
Regulatory readiness
The certifications above sit within a broader compliance landscape. Key milestones relevant to acquirers and PSPs.
PCI PTS v5 — April 2027 hard stop
No new PCI PTS v5 terminals may be deployed after 30 April 2027. Mypinpad SoftPOS is listed and validated against PCI MPoC v1.1 and needs no PTS hardware.
Terminal strategy guidePSD3 / PSR — Council compromise text, April 2026
PSD3 and PSR are agreed in principle; the publication date and transition period are not yet final. Mypinpad's authentication primitives are aligned with the new framework requirements.
UK contactless cap removed — March 2026
The UK contactless transaction limit was removed on 19 March 2026. Higher-value contactless transactions now flow directly, increasing the commercial case for PIN-capable SoftPOS deployments.
Certification questions
Common questions about MPoC, the certification process, and what it means for integration.
What is PCI MPoC?
PCI MPoC (Mobile Payments on COTS) is the PCI Security Standards Council standard for accepting payment card transactions — including PIN entry — on commercial off-the-shelf devices such as smartphones and tablets. It defines 192 individual security requirements covering software integrity, cryptographic key management, device attestation, and continuous monitoring. MPoC replaces the earlier SPoC and CPoC standards and is now the primary certification path for SoftPOS solutions.
Why do all three sub-programmes matter?
PCI MPoC has three distinct sub-programmes: Solution (the overall SoftPOS product), Software (the software components), and Attestation & Monitoring (the ongoing device integrity service). Some vendors hold only one or two. Holding all three means the entire stack — from the SDK to the continuous monitoring service — has been independently assessed. For acquirers, this removes the need to assess sub-programme gaps and reduces integration risk.
What is PCI MPoC v1.1?
MPoC — Mobile Payments on COTS — is the PCI Security Standards Council standard governing payment acceptance on everyday commercial devices rather than dedicated hardware. It has three sub-programmes: Software, Solution, and Attestation & Monitoring Services. Mypinpad is listed and validated against PCI MPoC v1.1 across all three.
How do I verify what a vendor is actually validated for?
Check the PCI Security Standards Council's public registry of validated MPoC products. It is searchable, it is free, and it is the only authoritative source. Look at three things: which sub-programmes the vendor holds, which version of the standard they are validated against, and the stated scope of that validation. A vendor holding one sub-programme and a vendor holding all three can both accurately say they are 'MPoC validated' — the registry shows you the difference.
What are PCI DSS v4.0.1 Level 1, PCI PIN v3.1 and ISO 27001:2022?
Mypinpad is validated as a PCI DSS v4.0.1 Level 1 Service Provider, covering its systems, processes and infrastructure. It is validated against PCI PIN v3.1 for PIN management and processing; PIN entry on the device is covered by PCI MPoC. ISO 27001:2022 is the international standard for information security management systems, held across the full organisation. Together these cover Mypinpad's operational security posture, not only its product.
Talk to us about certification and integration
We can walk through our certification documentation, integration timeline, and what MPoC v1.1 means for your specific deployment.