Skip to main content
Framework library
Framework module · pci-cpoc-1-0

PCI Contactless Payments on COTS (CPoC)

PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.

v1.0 · PCI Security Standards Council — CPoC

Standing today
Directory entry

00Answer

from the registry record
What is PCI Contactless Payments on COTS (CPoC)?
PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.
Who does PCI Contactless Payments on COTS (CPoC) apply to?
PCI Contactless Payments on COTS (CPoC) applies to payments, mobile point-of-sale, global, per PCI Security Standards Council — CPoC.
What is the current version of PCI Contactless Payments on COTS (CPoC)?
The current edition is v1.0, issued by PCI Security Standards Council — CPoC. Source: https://www.pcisecuritystandards.org/standards/contactless-payments-on-cots-cpoc/.
What does an assessment under PCI Contactless Payments on COTS (CPoC) require?
No control catalog has been ingested for PCI Contactless Payments on COTS (CPoC) yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

PCI Contactless Payments on COTS (CPoC) is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Contactless kernel security · Device and OS integrity · Backend monitoring · Solution management
Applies to
payments · mobile point-of-sale · global
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
PCI SSC announced the formal sunset period for CPoC from 2026-05-01 to 2026-10-31, the same window as SPoC. PCI MPoC v1.1 is the standard's designated successor.Expected: 2026-10-31 (sunset window closes)

03Version ledger

1 edition
v1.0Current editiondate not published

03aCoexisting versions

1 other version in force
  1. PCI MPoC v1.1 (designated successor)

    Applies to: New solutions and any CPoC solution being migrated ahead of the sunset

    Coexistence scheduled to end 2026-10-31

    Source (opens in a new tab)

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to payments · PCI SSC's consolidated standard for accepting PIN and contactless payments on commercial off-the-shelf mobile devices, absorbing the sunsetting SPoC and CPoC standards into one framework.

  2. Also applies to payments · PCI SSC's standard for accepting PINs on commercial off-the-shelf mobile devices via a software-based PIN-entry application. In its formal sunset window now, with MPoC as the designated successor.

  3. Also applies to payments · PCI SSC's standard for validated point-to-point encryption solutions that can reduce a merchant's PCI DSS scope. Part of the payments family beyond bare PCI DSS.

  4. PCI DSSv4.0.1

    Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.

PCI Contactless Payments on COTS (CPoC) | ControlFrame