PCI Security Standards Council Publishes New Standard for Contactless Payments
Today the PCI Security Standards Council (PCI SSC) published a new data security standard for solutions that enable merchants to accept contactless payments using a commercial off-the-shelf (COTS) mobile device (e.g., smartphone or tablet) with near-field communication (NFC). Using the PCI Contactless Payments on COTS (CPoC™) Standard and supporting validation program, vendors can provide merchants with contactless acceptance solutions that have been developed and lab-tested to protect payment data.
“Providing the payments industry with standards and resources that support secure payment acceptance in new and emerging card and card-rooted payment channels is a key focus for the Council,” said PCI SSC Standards Officer Emma Sutcliffe. “The PCI CPoC Standard is the second standard released by the Council to address mobile contactless acceptance. Specifically, the PCI CPoC Standard provides security and test requirements for solutions that enable contactless payment acceptance on a merchant COTS device using an embedded NFC reader.”
“Contactless, or tap and go, payment adoption is on the rise globally, and merchants want affordable, flexible and safe options for contactless payment acceptance that allow them to best serve their customers. In addition to PCI Software-based PIN Entry on COTS (SPoC) Solutions that enable contactless payment acceptance with a dongle attached to the mobile COTS device, the PCI CPoC Standard and Program now provide merchants the option to use validated solutions that require no additional hardware to accept contactless transactions,” said PCI SSC Senior Vice President Troy Leach.
The PCI CPoC Standard includes security requirements for vendors on how to protect payment data in CPoC Solutions and test requirements for laboratories (labs) to evaluate these solutions through the supporting validation program. Validated CPoC Solutions are listed on the PCI SSC website as a resource for merchants and acquirers. Program details are outlined in the CPoC Program Guide, which is available now on the PCI SSC website.
The primary elements of a CPoC Solution include: a COTS device with an embedded NFC interface to read the payment card or payment device; a validated payment acceptance software application that runs on the merchant COTS device initiating a contactless transaction; and back-end systems that are independent from the COTS device and support monitoring, integrity checks and payment processing. Software-based PIN entry is not permitted in a CPoC Solution.
Through a combination of the security controls built into the merchant application and ongoing monitoring and integrity checks performed by the back-end systems, merchants and consumers can have confidence in the security of the CPoC Solution and the contactless transaction.
“Developed with the input of the global payments industry via the requests for comments (RFC) process, the CPoC Standard is a continuation of the Council’s efforts to provide merchants with secure mobile payment acceptance options they can trust to support their customers and protect the integrity and confidentiality of their payment data,” added Leach.
The PCI CPoC Standard and Program documents are available on the PCI SSC website.
For more information on the new CPoC Standard and Program read PCI Perspectives Blog post Just Published: PCI Contactless Payments on COTS.
About the PCI Security Standards Council
The PCI Security Standards Council (PCI SSC) leads a global, cross-industry effort to increase payment security by providing industry-driven, flexible and effective data security standards and programs that help businesses detect, mitigate and prevent cyberattacks and breaches. Connect with the PCI SSC on LinkedIn. Join the conversation on Twitter @PCISSC. Subscribe to the PCI Perspectives Blog.
PCI Security Standards Council
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Science, Data, and Facts Should Unite Decision-Making, Says PMI CEO in Speech at Concordia Summit24.9.2020 22:20:00 EEST | Press release
André Calantzopoulos, CEO of Philip Morris International (PMI) (NYSE: PM), today delivered high-level remarks at the 2020 Concordia Annual Summit. Calantzopoulos discussed the impact that uncertainty, polarization, hyperpartisanship, and ideology are having on international efforts to overcome pressing global issues. He called for science to be protected from politicization and highlighted the importance of developing open dialogues based on factual scientific objectivity. Calantzopoulos shared PMI’s belief that with the right regulatory encouragement and support from civil society, cigarette sales can end within 10 to 15 years in many countries. The Concordia Annual Summit, which coincides with the United Nations General Assembly (UNGA) meeting, convenes the world’s most prominent business, government, and nonprofit leaders to foster dialogue and enable effective partnerships for positive social impact. Excerpts of the remarks by André Calantzopoulos follow: “Reflecting on the state o
Swiss Medical Group Holding Acquires CoreMedica Europe24.9.2020 18:54:00 EEST | Press release
Swiss Medical Group (SMG) Holding Luxembourg S.A., leading the development of STARKS Age-Management in Europe and Asia, announced today the acquisition of CoreMedica Europe, to expand in Europe and the rest of the world. CoreMedica Europe recently made the headlines in Switzerland for combining a COVID-19 Screening Test and Immunity profile with its existing home self-collection kit that allows customers to collect a few drops of blood and send them by mail to CoreMedica Europe’s accredited laboratory in Geneva to screen the anti-SARS-COV-2 IgG antibody and assess any previous infection to SARS-COV-2, the virus responsible for COVID disease, and analyze a set of 5 key biomarkers known to support the immune system (vitamin D, zinc, magnesium, copper, selenium) so as to receive personalized actionable recommendations to help patients build up their natural defenses against the effects of a next potential viral infection. “In this epidemic and containment context the essential objective
Esri and AfroChampions Launch Partnership to Promote GIS in Africa24.9.2020 16:52:00 EEST | Press release
Esri, the global leader in location intelligence, today announced a joint initiative with AfroChampions, a Pan-African nonprofit that aims to promote policies that foster private-public collaboration for Africa's economic transformation. The goal of the initiative is to engage leaders in business, governments, the African Union, and other regional economic communities through dialogue and potential partnership building in applying geospatial technology and solutions. This new partnership with AfroChampions seeks to contribute to sustainable economic development in Africa and promote the benefits of a shared geospatial infrastructure throughout the continent. As a majority of Africans still live in rural areas, geographic information system (GIS) technology can create new opportunities for growth, especially in critical fields such as health and telemedicine, land management, agriculture, and mobility. The powerful mapping and data analytics that GIS provides forms a foundation for some
DXC Technology Announces Leadership Appointments to Support the “new DXC"24.9.2020 16:20:00 EEST | Press release
DXC Technology (NYSE:DXC) today presented its latest leadership appointments further strengthening the DXC leadership team, the majority being new to DXC within the last year. This team is bringing the “new DXC,” which is focused on its customers and its people, to the market as it executes the company’s transformation journey. DXC Customer Portfolio Leadership Over the past year, CEO Mike Salvino has recruited new IT services industry leaders who bring formidable experience delivering for customers, inspiring people, and running and growing businesses. DXC announces the following appointments and changes to the team that will run DXC’s business and lead execution of the DXC transformation journey: Americas will be led by Jim Brady and David Swift . Jim joined DXC in June 2020 from Accumen, where he was the COO and previously worked at Accenture and Honeywell. David Swift joined DXC in November 2019 from Accolade where he was Chief Service Officer and previously worked at Aon Hewitt an
Statement on One-Year Anniversary of Women’s Entrepreneurship Accelerator24.9.2020 16:07:00 EEST | Press release
Please find the statement below from Women’s Entrepreneurship Accelerator leadership regarding the one-year anniversary of the ground-breaking initiative. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20200924005283/en/ Anita Bhatia, Deputy Executive Director, UN Women One year ago, we committed to educating and empowering ten million women entrepreneurs over the next ten years through the Women’s Entrepreneurship Accelerator (WEA). We began to lay the groundwork for a systemic transformation to break down the barriers keeping women from achieving financial independence and contributing to a better future for themselves and their communities. Today, in our unprecedented reality, women find themselves at history’s crossroads. They are disproportionately harmed by the economic devastation wrought by COVID-19 while simultaneously holding the keys to recovery. Women make up 39% of global employment but have accounted for 54% of o
Airship Acquires Conversational Commerce Pioneer ReplyBuy to Accelerate Expansion Into Mobile Commerce24.9.2020 16:00:00 EEST | Press release
Customer engagement company Airship today announced that it has acquired ReplyBuy, a company that pioneered fully integrated solutions for payments over SMS. This move extends Airship’s platform beyond customer engagement to directly enable commerce, as well as power one-to-one customer conversations via two-way SMS. In addition, Airship plans to extend ReplyBuy’s technology to provide turnkey commerce and payments solutions across more marketing channels, messaging platforms and industry verticals. The acquisition will provide companies of all sizes a single platform to create, manage and optimize cross-channel customer interactions and drive greater revenue more quickly. Airship’s real-time mobile data, predictive AI and unified approach to customer journeys ensures relevant messaging at the optimal time on customers’ preferred channels across app and web notifications, SMS, email, mobile wallet and more. Subsequent digital actions customers take, now including purchases and conversa
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.Visit our pressroom