What has been certified
PCI MPoC (Mobile Payments on COTS) is the PCI Security Standards Council standard governing secure payment acceptance on commercial off-the-shelf mobile devices. CYNTE's certification covers the TAP4PAY payment software and, listed as its own security component, the TAP4PAY Isolated SDK.
| Standard | PCI MPoC (Mobile Payments on COTS) v1.1 |
|---|---|
| Validated MPoC Software | Reference #2026-01606.001 |
| Isolated SDK | Reference #2026-01606.002 |
| Supported platforms | Android 10 to 16, on NFC-enabled smartphones, tablets and Android payment devices |
| Evaluation laboratory | Applus Laboratories, a PCI Recognized MPoC Laboratory |
| Development process | PCI Secure Software Lifecycle (SLC) validated processes |
The listing can be checked directly against the source: verify CYNTE TAP4PAY on the PCI SSC Validated MPoC Software list.
Why does this matter?
For acquirers, PSPs and ISVs, MPoC is what makes software-only payment acceptance deployable rather than experimental. Certification is the difference between a demo that taps a card and a solution a scheme and a regulator will accept in production.
Three things change once the software is certified:
- PIN is allowed on the same device. Under the earlier CPoC standard, cardholder verification on the merchant's phone was off the table. MPoC permits PIN entry and richer verification, which is what lets TAP4PAY offer PIN on Glass and Manual PAN entry inside one certified solution.
- The compliance burden shifts. Deploying certified MPoC software means partners inherit an evaluated security architecture instead of building and defending their own.
- No hardware to certify, ship or replace. Merchants use NFC Android devices they already carry. There are no dongles, card readers or terminal logistics in the rollout.
Certified as an Isolated SDK
The second listing reference matters as much as the first. An Isolated MPoC SDK is evaluated as a self-contained security component, independent of whatever application embeds it.
In practice, a partner integrates the TAP4PAY SDK into their own Android app without pulling that app into the core MPoC software evaluation. The security boundary sits at the SDK, not at the app around it, which shortens time to market and cuts certification cost for the integrator. Partners can ship the ready-made app, a white-label build, or their own application built on the SDK.
Built under PCI SLC, not certified once
A product certification describes one release. PCI Secure Software Lifecycle (SLC) is the PCI Software Security Framework standard that assesses how a vendor designs, develops, tests and maintains payment software in the first place.
CYNTE develops TAP4PAY under SLC validated processes, so security review is part of the engineering lifecycle rather than a gate at the end of it, and updates can reach merchants without a full reassessment each time.
The whole stack is ours
Most SoftPOS vendors license their EMV kernel or their cryptography from someone else. CYNTE engineers the chain in-house: the certified contactless EMV Level 2 kernel, the white-box cryptography protecting keys and PIN blocks at the moment of capture, and the app shielding layers that harden the SDK against rooted or instrumented devices.
Through that kernel, merchants accept Mastercard, Visa, American Express, UnionPay, Discover, JCB, PURE, CPace, RuPay, Interac (Canada) and eftpos (Australia), with additional schemes enabled per market. Because certification, support and roadmap sit with one vendor, there is no third party in the path when a scheme mandate or a PCI revision lands.
See it on your own device
Request a demo of a live tap, PIN on Glass and manual entry, or talk to us about SDK licensing, a partnership or the EMV L2 kernel. Our team typically responds within one business day.
