Skip to main content
Framework library
Framework module · pci-mpoc-1-1

PCI Mobile Payments on COTS (MPoC)

PCI SSC's consolidated standard for accepting PIN and contactless payments on commercial off-the-shelf mobile devices, absorbing the sunsetting SPoC and CPoC standards into one framework.

v1.1 · PCI Security Standards Council — MPoC · published 2024-11-26

Standing today
Directory entry

00Answer

from the registry record
What is PCI Mobile Payments on COTS (MPoC)?
PCI SSC's consolidated standard for accepting PIN and contactless payments on commercial off-the-shelf mobile devices, absorbing the sunsetting SPoC and CPoC standards into one framework.
Who does PCI Mobile Payments on COTS (MPoC) apply to?
PCI Mobile Payments on COTS (MPoC) applies to payments, mobile point-of-sale, global, per PCI Security Standards Council — MPoC.
What is the current version of PCI Mobile Payments on COTS (MPoC)?
The current edition is v1.1, issued by PCI Security Standards Council — MPoC and published 2024-11-26. Source: https://www.pcisecuritystandards.org/standards/mobile-payments-on-cots-mpoc/.
What does an assessment under PCI Mobile Payments on COTS (MPoC) require?
No control catalog has been ingested for PCI Mobile Payments on COTS (MPoC) yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

PCI Mobile Payments on COTS (MPoC) is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
PIN CVM security · Contactless kernel security · Device and OS integrity · Backend monitoring
Applies to
payments · mobile point-of-sale · global
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
MPoC is the designated successor absorbing PCI SPoC and CPoC, which are both in their formal sunset window (2026-05-01 to 2026-10-31).Expected: 2026-10-31 (SPoC/CPoC sunset closes)

03Version ledger

2 editions
v1.0Supersededdate not published
v1.1Current edition · supersedes v1.02024-11-26

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to payments · PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.

  2. Also applies to payments · PCI SSC's standard for accepting PINs on commercial off-the-shelf mobile devices via a software-based PIN-entry application. In its formal sunset window now, with MPoC as the designated successor.

  3. PCI DSSv4.0.1

    Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.

  4. Also applies to payments · PCI SSC's requirements for the secure management, processing, and transmission of personal identification number (PIN) data during payment transactions.

PCI Mobile Payments on COTS (MPoC) | ControlFrame