PCI MPoC penetration testing.

Identify security weaknesses in your mobile payment software and its backend interfaces. Get guidance on fixes and testing evidence to support your formal laboratory evaluation.

For teams developing or integrating mobile payment acceptance software.

PCI Mobile Payments on COTS (MPoC) addresses payment acceptance on commercial off-the-shelf devices, such as smartphones. Our service focuses on two parts of that security evaluation context:

  • MPoC Software (1A-1.3): vulnerability assessment and penetration testing of the mobile software within the agreed scope.
  • Integration interfaces (4A-3.1): penetration testing of the interfaces between the mobile software and its backend environments.

We agree the software, interfaces and test conditions before testing begins.

Our testing provides evidence for your evaluation by a PCI-recognized MPoC laboratory.

Tell us about your payment app or SDK. We help define what to test and guide your team through the preparation.

You get clear findings, practical guidance on fixes and testing evidence to share with your evaluation laboratory.

Explore the technology behind our testing
Who performs the formal evaluation?

A PCI-recognized MPoC laboratory evaluates the solution against the applicable requirements.

What if we need a general mobile security assessment?

If your objective is to understand vulnerabilities in an Android or iOS application rather than support an MPoC evaluation, explore our mobile application penetration testing. We can discuss which assessment fits your objective.

A necessary cookie remembers your choice for up to 180 days. Privacy policy.