PCI Mobile Payments on COTS (MPoC)
PCI SSC's consolidated standard for accepting PIN and contactless payments on commercial off-the-shelf mobile devices, absorbing the sunsetting SPoC and CPoC standards into one framework.
v1.1 · PCI Security Standards Council — MPoC · published 2024-11-26
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
PCI Mobile Payments on COTS (MPoC) is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- PIN CVM security · Contactless kernel security · Device and OS integrity · Backend monitoring
- Applies to
- payments · mobile point-of-sale · global
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
- Pending change
- MPoC is the designated successor absorbing PCI SPoC and CPoC, which are both in their formal sunset window (2026-05-01 to 2026-10-31).Expected: 2026-10-31 (SPoC/CPoC sunset closes)
03Version ledger
| v1.0 | Superseded | date not published |
| v1.1 | Current edition · supersedes v1.0 | 2024-11-26 |
05Change history
06Related frameworks
Also applies to payments · PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.
Also applies to payments · PCI SSC's standard for accepting PINs on commercial off-the-shelf mobile devices via a software-based PIN-entry application. In its formal sunset window now, with MPoC as the designated successor.
- PCI DSSv4.0.1
Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.
Also applies to payments · PCI SSC's requirements for the secure management, processing, and transmission of personal identification number (PIN) data during payment transactions.