Table of Contents
If you’re like most point of sale (POS) independent software vendors (ISVs) and value-added resellers (VARs), you’re seeing more interest in software-based point of sale (SoftPOS). This technology allows merchants to accept contactless payments by downloading an app on near-field communication (NFC)-enabled Android devices. Customers tap their contactless cards or mobile wallets on the device screen to pay quickly and conveniently. SoftPOS is a payment terminal-free, cost-effective way for merchants to accept payments, and it allows consumers to make contactless payments in more places, from a taxi or rideshare vehicle to a pop-up shop or food truck.
When one of your customers or a prospect asks you about SoftPOS, though, they’ll inevitably ask whether it’s secure. You can assure them that it keeps payment and customer data safe with these standards, safeguards, and best practices.
PCI Compliance for SoftPOS
The Payment Card Industry Security Standards Council (PCI SSC) published standards specifically for contactless payments on commercial off-the-shelf (COTS) devices. The Mobile Payments on COTS (MPoC) Standard, published in 2022, builds on two previously published standards: Contactless Payments on COTS (CPoC) and Software-based PIN Entry on COTS (SPoC). MPoC addressed a major usability issue: PIN entry on the same device that captures payment account data, but it does so with data protection in mind. When you provide a SoftPOS solution that is PCI certified, you can assure your merchants that it has passed third-party testing to ensure that it protects payment and consumer data privacy and secures data from hacking and data loss.
No SoftPOS Payment Data Is Stored on the Device
Bring-your-own-device SoftPOS solutions can raise the question of whether a hacker who gets access to a device that a merchant uses, for example, for inventory management or communication, can steal payment data. You can assure your customers and prospects that payment data is only captured and used by the SoftPOS application, and it’s encrypted and tokenized and never stored on the device. So, even if a hacker or an unauthorized person can open a phone, there is no payment data from SoftPOS for that actor to find.
SoftPOS Protects Data in Transit
You might get some questions about payment data that the SoftPOS application sends to the payment processor or acquirer. SoftPOS must comply with PCI-compliant network security using end-to-end encryption and secure network channels to protect data. It’s end-to-end data protection, from data capture on the mobile device to the secure processor and then a secure approval or denial to the merchant.
Leading SoftPOS is Human-Error-Proof
SoftPOS that’s designed for use on bring-your-own-devices smartphones and tablets might raise questions about whether user error can make payment data vulnerable. The concern is that a careless employee could put cardholder data (and, subsequently, the merchant’s entire business) at risk. However, SoftPOS providers use layered security, from built-in security features to requiring authentication to open the app, to cover all possible risk scenarios. In addition, if unusual activity is detected, the provider can disable the app on that device in question. Leading providers put multiple safeguards in place to secure the app in use.
How to Capitalize on SoftPOS Interest with the Confidence that It’s Secure
SoftPOS adoption is growing around the world, especially among small and medium-sized businesses. Market.us reports that the global market is set to increase from about $46 billion in 2026 to $128.1 billion in 2035, taking this technology past the tipping point from niche to mainstream.
As merchants learn they can accept contactless payments without investing in new payment devices, they’ll look for providers who can help them meet demand for contactless payments wherever their customers want to pay.
Datacap offers SureTap, a complete and certified contactless payments solution that is fully encrypted and protects merchants by tokenizing payment data. You can provide SureTap as part of the Datacap solutions ecosystem for ease of integration and with Datacap’s high standards for performance and data protection.
Ready to Learn More?
Contact us today to see how SureTap can help you securely meet demands for contactless payment solutions.
FAQs
What happens if a SoftPOS device is lost, stolen, or compromised?
A PCI-certified SoftPOS solution doesn’t store readable cardholder data on the device that a merchant uses to accept contactless payments. However, leading SoftPOS providers will take steps to ensure that a compromised device doesn’t compromise cardholder data security. The provider can disable the app on the device in question and will always run scans to ensure application security. Merchants with remote device management can also lock or wipe the device.
Do ISVs or VARs need PCI certification to offer SoftPOS?
If you partner with a certified SoftPOS provider, the partner takes the responsibility for certification and ongoing compliance. Although VARs and ISVs do not have to get PCI certification to provide a partner’s solution, they must follow all security guidance that the provider advises them to follow.
How do ISVs and VARs handle SoftPOS updates?
Work with your SoftPOS provider to schedule necessary updates for cryptographic protection, security patches, and to comply with changing PCI or EMV requirements. Remote update capabilities enable you to manage updates quickly across all SoftPOS accounts or segments of the customer base with minimal disruption to merchants or your operations.

