PCI Mobile Payments on COTS (MPoC) is a global security standard for payment acceptance on commercial off-the-shelf devices such as smartphones and tablets, maintained by the PCI Security Standards Council. Its modular, objective-based model lets vendors certify a complete solution or an individual component, whether software, an SDK, or an attestation and monitoring service, and demonstrate resilience against realistic attacks on devices that offer no hardware-backed security guarantees. As a PCI-recognized MPoC evaluation laboratory, Keysight supports you from scoping and readiness assessment through pre-evaluation testing to formal evaluation, delivering the validated results PCI SSC requires to accept and list your MPoC product.

pci ssc logo
PCI MPoC Evaluation and Advisory Services
red icon with a grid

Scoping and Gap Analysis

Establish which MPoC product type applies to what you've built — Solution, Software, or Service — and where your architecture sits against the security and test requirements. We map the boundary of the evaluation before you commit budget to it, so the scope you pay for is the scope you actually need.

red icon with a folder

Design and Documentation Review

MPoC is objective-based rather than prescriptive, which puts the burden on your documentation to argue that your design meets the objective. We review architecture, key management, attestation, and monitoring design against the requirements early, while changes are still a sprint rather than a re-architecture.

red icon with a shield

Security Testing and Pre-Evaluation

Full attack-driven testing of the mobile application, SDK, cryptographic implementation, and backend. This includes white-box cryptography analysis, side-channel and fault injection techniques, reverse engineering, and penetration testing of the attestation and monitoring components. Run as a pre-evaluation, it surfaces findings before they become a formal non-compliance.

red icon with a certificate

Formal Evaluation and Listing

The evaluation itself, carried out as a PCI-recognized MPoC lab, through to submission and listing by PCI SSC. We also plan for what comes after: annual checkpoints, revalidation, and the delta evaluations triggered when you change your solution.

Working with Keysight

Focus on advancing your product while Keysight guides you through PCI MPoC preparation and evaluation.

mobile phone with many app icons

Proven Track Record

  • More than 200 security evaluations of host card emulation (HCE) mobile wallet solutions
  • More than 50 evaluations of tap-to-phone solutions
  • Contributed feedback to PCI SSC that helped shape the MPoC standard
engineer with magnifying glass

Deep Cryptographic and Attack Expertise

  • Pioneered side-channel analysis and fault injection against white-box cryptography
  • Attack expertise that finds the issues a checklist review misses
  • Findings delivered as prioritized, fixable engineering work rather than a list of clauses
three engineers examining graphs

One Partner Across Payment Schemes

  • Accredited across PCI, EMVCo, Mastercard, Visa, and American Express programs
  • Fold MPoC into a single certification roadmap instead of running parallel lab relationships
  • Reuse evidence and documentation across schemes to cut duplicated testing
engineer at a computer

PCI MPoC Workshop

Get Your Team Ready Before the Evaluation Starts

Keysight offers an online, interactive workshop on the PCI MPoC requirements. It covers what's in scope, how the requirements map to your architecture, and the pitfalls that most often send a first submission back. Our specialists take questions on your specific use case.

Frequently Asked Questions

Learn Resources

Featured Blogs

Our experts regularly share practical insights in our blog. Explore the latest developments in mobile and payments security.