Establish which MPoC product type applies to what you've built — Solution, Software, or Service — and where your architecture sits against the security and test requirements. We map the boundary of the evaluation before you commit budget to it, so the scope you pay for is the scope you actually need.
MPoC is objective-based rather than prescriptive, which puts the burden on your documentation to argue that your design meets the objective. We review architecture, key management, attestation, and monitoring design against the requirements early, while changes are still a sprint rather than a re-architecture.
Full attack-driven testing of the mobile application, SDK, cryptographic implementation, and backend. This includes white-box cryptography analysis, side-channel and fault injection techniques, reverse engineering, and penetration testing of the attestation and monitoring components. Run as a pre-evaluation, it surfaces findings before they become a formal non-compliance.
The evaluation itself, carried out as a PCI-recognized MPoC lab, through to submission and listing by PCI SSC. We also plan for what comes after: annual checkpoints, revalidation, and the delta evaluations triggered when you change your solution.
Focus on advancing your product while Keysight guides you through PCI MPoC preparation and evaluation.
Keysight offers an online, interactive workshop on the PCI MPoC requirements. It covers what's in scope, how the requirements map to your architecture, and the pitfalls that most often send a first submission back. Our specialists take questions on your specific use case.
PCI Mobile Payments on COTS (MPoC) is a PCI Security Standards Council standard for payment acceptance solutions that run on commercial off-the-shelf devices such as smartphones and tablets. It is modular and objective-based, meaning it sets security objectives that a solution must meet rather than dictating the specific components used to meet them.
SPoC covered PIN entry on a COTS device and required an external card reader. CPoC covered contactless acceptance without PIN. MPoC combines both, allowing PIN and contactless cardholder data entry on the same device, and adds support for offline transactions, online PIN, manual card entry including capture via the device camera, remote kernels, external magnetic stripe and secure card readers, and enterprise devices not sold to the public.
Yes. PCI SSC has announced a formal sunset period for both the SPoC and CPoC standards running from 1 May to 31 October 2026. Vendors with solutions validated under either program should be planning their MPoC path now. Talk to your acquirer and the payment brands about what your specific deployment requires and by when.
Version 1.1 was published on 26 November 2024. Notable changes include removal of the Secure Software and kernel functional validation requirements, and an allowance for one MPoC SDK to integrate another MPoC SDK. The update broadens the range of solution architectures that can be certified.
PCI SSC lists MPoC products in three categories: MPoC Solutions, MPoC Software, and MPoC Services. Each is evaluated and listed separately. A complete, end-to-end MPoC Solution listing is what allows a live deployment. Component listings such as software or attestation and monitoring services are valid products in their own right, but a vendor holding only a component listing still needs a full solution listing before going live.
Yes. MPoC products must be evaluated and validated by a PCI-recognized MPoC laboratory before PCI SSC will accept and list them. Keysight is a PCI-recognized MPoC lab.
Products already validated under SPoC or CPoC can be submitted for evaluation under the MPoC program. In practice this is a full evaluation rather than a paperwork exercise, because MPoC's scope and structure differ from both predecessors. A scoping engagement is the fastest way to find out how much of your existing evidence carries over.
It depends on scope, product type, and how complete your documentation is when you start. The single largest driver of overrun is documentation that doesn't yet argue the case against the security objectives. Starting the design and documentation review before the formal evaluation is the most effective way to protect the timeline.
MPoC listings carry ongoing obligations, including annual checkpoints and revalidation due dates. Changes to your solution can trigger delta evaluations. Keysight plans for this at the outset so the maintenance cycle is budgeted rather than a surprise.
Yes. MPoC supports the use of external magnetic stripe readers and external contact or contactless secure card readers, with or without PIN entry. The evaluation scope changes depending on how security responsibility is divided between the reader and the COTS device.
Because a COTS device offers no hardware-backed security guarantee, MPoC relies on an attestation and monitoring system to continuously judge whether a given device is in a state safe enough to process a transaction. It's central to the standard's security model, and it's frequently where evaluations run into trouble.
Yes. If you're also pursuing EMVCo, Visa, Mastercard, American Express, or other PCI programs, Keysight can align the work under one roadmap and reuse documentation and test evidence across schemes.
Typically your mobile engineering lead, backend or platform lead, cryptography or security architect, and whoever owns compliance. Documentation ownership matters more than teams expect. Naming that owner on day one is the cheapest thing you can do to protect the schedule.
Our experts regularly share practical insights in our blog. Explore the latest developments in mobile and payments security.
What are you looking for?