SoftPOS certification, explained
What it takes for a phone to accept card payments: the PCI standard behind it, card scheme approval, attestation and monitoring, and what a merchant needs on day one.

SoftPOS, often called tap to phone, turns an ordinary NFC-enabled phone into a contactless card terminal. No reader, no dock, no cables: the merchant downloads an app, the customer taps a card or a phone, and the payment goes to the acquirer like any other card payment.
The hardware disappears, but the security requirements do not. A traditional terminal is a certified piece of hardware; a phone is not. In SoftPOS, the protection comes from certified software and from a back end that watches every device. This guide explains what is certified, by whom, and what it means for a business launching SoftPOS.
The standard: PCI MPoC
The PCI Security Standards Council publishes the standard for accepting payments on commercial off-the-shelf devices such as phones: PCI MPoC (Mobile Payments on COTS), released in 2022. It covers contactless acceptance and PIN entry on the phone's own screen, and it succeeds the two earlier standards that covered them separately, CPoC for contactless and SPoC for PIN.
Certification looks at the whole solution, not just the app:
The app or SDK that reads the card and protects card data on the phone.
The attestation and monitoring service that checks the phone and the app before and during use.
The back end that receives and processes the protected payment data.
Card scheme approval
The card schemes run their own programmes for phone-based acceptance, such as Visa's Tap to Phone and Mastercard's Tap on Phone, and a solution has to be approved for the brands it accepts. Contactless acceptance also relies on certified EMV contactless kernels, the components that run each scheme's card transaction rules.
Attestation and monitoring
This is the part with no equivalent in a classic terminal. Because the phone is general-purpose, the solution keeps checking that it can be trusted:
Is the device rooted or jailbroken, or running a tampered app?
Is the operating system recent enough, and is a debugger or overlay attached?
Does the app still pass its integrity checks during the transaction?
When a check fails, the service can stop that phone from taking payments. It is continuous, not a one-off test.
Which phones
On Android, SoftPOS runs on phones with NFC and a supported operating system version. On iPhone, contactless acceptance goes through Apple's own Tap to Pay on iPhone, which payment providers integrate under Apple's programme.
PIN on glass
Above the contactless limit, or when the card asks for it, a payment needs a PIN. With MPoC the customer can enter it on the merchant's phone screen, on a protected keypad, so higher-value payments do not need extra hardware either.
What a merchant needs on day one
Onboarding in minutes, including identity and business checks, from the app itself.
An acquiring account behind the app, so payments settle to the merchant.
Digital receipts, refunds and a clear view of today's takings.
Staff accounts with limits, and a back office for the owner.
What it means if you are launching SoftPOS
For a bank, a payment provider or a fintech, the work is less about writing the app and more about assembling certified pieces and the partners behind them: an acquirer, scheme approvals, the attestation service, and the onboarding and back office your merchants will use every day.
Our SoftPOS platform brings the terminal app, merchant onboarding with KYC, and the owner back office together under your brand, on certified acquiring rails. The exact requirements depend on your acquirer and your markets, and we configure the platform to match.

