Insights

SoftPOS Goes Mainstream: When the Terminal Became an App

A phone that accepts contactless cards used to be a pilot. Now it is a standard product line for acquirers, backed by a dedicated security standard and a growing set of use cases.

JWJonah WhitlockContributing Editor, Commerce · 25 March 2026 · 8 min

2022

Year the PCI Security Standards Council published the Mobile Payments on COTS (MPoC) standard

~4 cm

Nominal operating distance for EMV contactless card reading

0

Additional acceptance devices required beyond an NFC-capable phone

For decades, accepting cards meant owning a terminal: a tamper-resistant device with a secure keypad, a card reader and a certified software stack. Terminals are reliable and secure, but they cost money to buy, ship, replace and repair. For a market trader, a courier or a tradesperson, the economics rarely worked.

SoftPOS, also called tap to phone or tap to pay, removes the terminal. A merchant downloads an app to an ordinary NFC-capable phone and accepts contactless cards and device wallets directly. What began as pilots has become a standard offering for many acquirers.

Why it took so long

The obstacle was never NFC hardware; most modern phones have it. The obstacle was trust. A payment terminal is a controlled environment. A phone is a general-purpose device that also runs games, messaging apps and whatever its owner installs. Card schemes and security bodies needed a framework for accepting card data on hardware nobody in the payments chain controls.

That framework arrived in stages. The PCI Security Standards Council published a contactless-only standard for commercial off-the-shelf devices, followed in 2022 by the Mobile Payments on COTS (MPoC) standard, which covers both contactless acceptance and PIN entry on the device and allows for more modular, software-based architectures. The schemes set their own program requirements alongside.

A second obstacle was access to NFC itself. On some mobile platforms, third-party payment apps did not have access to the phone's NFC capability for card acceptance, which limited SoftPOS to particular devices or to platform-provided services. That access has broadened in several markets, partly under regulatory pressure, although the details vary by platform and region.

How the security model works

Because the device cannot be trusted by default, SoftPOS security is continuous rather than static.

  • Attestation: the app checks the device and its own integrity before and during each transaction, looking for rooting, hooking frameworks, debuggers and modified builds.
  • Back-end monitoring: a server-side service evaluates attestation results across the fleet and can disable an individual device or an entire app version if something looks wrong.
  • Isolation: sensitive operations, particularly PIN handling, are separated from the rest of the app, with PIN entry on glass using techniques such as randomized keypad layouts to resist observation.
  • Limits: acquirers can apply transaction limits and velocity rules suited to the merchant's risk profile.
A terminal is secure because of what it is. A SoftPOS phone is secure because of what is continuously being checked. That difference changes who has to do the work.

Who is using it

The obvious beneficiaries are micro-merchants: sole traders, market vendors and service businesses that previously relied on cash or bank transfers. For them, zero hardware means zero upfront cost and near-instant onboarding.

The less obvious beneficiaries are large enterprises. Retailers equip store associates with tap-to-pay on the devices they already carry for inventory, reducing queues. Delivery firms and field-service companies let drivers and technicians take payment on their company phones. For these organizations, SoftPOS is less about cost and more about eliminating a separate device from a workflow.

The limits

SoftPOS is not a universal replacement for terminals. High-volume counters still benefit from dedicated hardware that is always on, always charged and designed for thousands of taps a day. Chip-and-PIN insert transactions and magnetic stripe are out of scope. And the merchant's own phone may not always be available, charged or connected when a customer is ready to pay.

Contactless limits also matter. In markets where PIN is required above a threshold, SoftPOS solutions without PIN on glass have to decline or fall back for larger purchases. MPoC-based PIN entry addresses this, but support varies by acquirer and region.

What comes next

Three developments are worth watching. First, SoftPOS is converging with the point-of-sale software itself, so the payment is just one screen in an app that also handles orders, inventory and loyalty. Second, the same devices increasingly accept QR-based account-to-account payments alongside cards, particularly in markets with strong instant-payment schemes. Third, acquirers are treating fleet security as an operational discipline, with dedicated teams monitoring attestation data around the clock.

The terminal is not disappearing. But for a growing share of merchants, it has become optional, and that is a significant shift for an industry that has always started with the hardware.

Found this useful? Pass it on.

Companies working on this

Read next

Debit vs. Credit at the Point of Sale: The Economics Behind the Tap

Search PaymentSolutions.fyi

Search companies, categories, insights and the content library