Close Menu
  • Home
  • Life style
    • Celebrities
    • Exercise & Training
    • Healthline
  • Exploration
    • Beauty tips
    • Business
    • Travel guides
    • Fashion
    • Technology
  • Web tutorials
    • Hosting & Servers
    • Blogger guides
    • WordPress guides
  • English
    • Tiếng Việt
    • Hmoob
    • English
Facebook YouTube X (Twitter) Instagram
Trending
  • PCI SPoC 2026: Prepare Your Phone-Based PIN Payments Before Sunset
  • Entering Schengen with EES: Who Must Provide Biometric Data?
  • Let’s Encrypt SSL on Vultr: Enable HTTPS and Auto-Renewal
  • Install WordPress on a Vultr VPS with Secure HTTPS
  • How to Connect a Domain to a Vultr VPS: A–Z Guide
  • How to Register and Set Up a Vultr VPS: A–Z Guide
  • Docker Minimus Migration: Move to Docker Hardened Images
  • Blogger Permissions for Collaborators: Keep Control
Facebook YouTube X (Twitter) Instagram
SaibABCSaibABC
Chú thích cho quảng cáo
  • Home
  • Life style
    1. Celebrities
    2. Exercise & Training
    3. Healthline
    4. View All

    Unprecedented: Argentina to Honour Messi in the 10th Minute

    05/09/2026

    Messi vs. Ronaldo at 1,000 Goals: Who Will Reach the Milestone?

    30/08/2026

    Comparing Lionel Messi and Cristiano Ronaldo: Their Complete Careers

    30/08/2026

    Celebrities Move to Video Podcasts: The New Era of Talk Shows

    30/08/2026

    Five-Minute Office Exercises: A Snack-Sized Movement Schedule

    30/08/2026

    Best Exercises to Strengthen Your Core: From Beginner to Advanced

    30/08/2026

    Wearable Workouts: Use Data to Exercise Safely

    01/09/2026

    Diagnosing and Treating Severe Pneumonia: A Practical Guide

    30/08/2026

    Preventing Dengue at Home: A Safety Checklist

    30/08/2026

    Using Wearables for Health Monitoring: Safe Use and Limits

    30/08/2026

    Unprecedented: Argentina to Honour Messi in the 10th Minute

    05/09/2026

    Wearable Workouts: Use Data to Exercise Safely

    01/09/2026

    Messi vs. Ronaldo at 1,000 Goals: Who Will Reach the Milestone?

    30/08/2026

    Diagnosing and Treating Severe Pneumonia: A Practical Guide

    30/08/2026
  • Exploration
    1. Beauty tips
    2. Business
    3. Travel guides
    4. Fashion
    5. Technology
    Featured

    PCI SPoC 2026: Prepare Your Phone-Based PIN Payments Before Sunset

    By Nuj Coom11/09/2026
    Recent

    PCI SPoC 2026: Prepare Your Phone-Based PIN Payments Before Sunset

    11/09/2026

    Entering Schengen with EES: Who Must Provide Biometric Data?

    10/09/2026

    Free Windows 11 Product Keys: Facts and Legal Activation

    02/09/2026
  • Web tutorials
    1. Hosting & Servers
    2. Blogger guides
    3. WordPress guides
    4. View All

    Let’s Encrypt SSL on Vultr: Enable HTTPS and Auto-Renewal

    09/09/2026

    Install WordPress on a Vultr VPS with Secure HTTPS

    08/09/2026

    How to Connect a Domain to a Vultr VPS: A–Z Guide

    08/09/2026

    How to Register and Set Up a Vultr VPS: A–Z Guide

    07/09/2026

    Blogger Permissions for Collaborators: Keep Control

    07/09/2026

    Add a Blogger Report Abuse Button to Custom Themes

    07/09/2026

    Optimizing Blogger Images for Google Images: File Names to Landing Pages

    07/09/2026

    Blogger Image Lazy Loading for SEO: Crawlable Pages

    05/09/2026

    Install WordPress on a Vultr VPS with Secure HTTPS

    08/09/2026

    WordPress 7.1 AVIF & HEIC: Reduce Server Load

    02/09/2026

    WordPress 7.1 Responsive Breakpoints: How to Test Them

    02/09/2026

    Protecting WordPress Against AI Bots and Unknown Crawlers

    30/08/2026

    Let’s Encrypt SSL on Vultr: Enable HTTPS and Auto-Renewal

    09/09/2026

    Install WordPress on a Vultr VPS with Secure HTTPS

    08/09/2026

    How to Connect a Domain to a Vultr VPS: A–Z Guide

    08/09/2026

    How to Register and Set Up a Vultr VPS: A–Z Guide

    07/09/2026
  • English
    • Tiếng Việt
    • Hmoob
    • English
SaibABCSaibABC
Home»Exploration»Business»PCI SPoC 2026: Prepare Your Phone-Based PIN Payments Before Sunset
Business 7 Mins ReadNo Comments

PCI SPoC 2026: Prepare Your Phone-Based PIN Payments Before Sunset

Nuj CoomBy Nuj Coom
Facebook Twitter Pinterest LinkedIn Tumblr Email
Chú thích cho quảng cáo

Contents

  1. Understand the Sunset Timeline and the Status of the Solution in Use
  2. Check the Listing, Configuration and PCI DSS Responsibilities
    1. Compare the Deployed Solution with the Listing
    2. Determine PCI DSS Responsibilities
  3. Plan and Validate the Migration Before Making Changes
  4. Reference source

The short answer: October 31, 2026 is not the date on which all PCI SPoC solutions will stop operating. According to the PCI Security Standards Council Bulletin: Announcement of Sunset Periods for the PCI SPoC and PCI CPoC Standards, PCI SSC’s sunset period runs from May 1, 2026, through October 31, 2026. After that date, PCI SSC will no longer accept new SPoC submissions; accepted listings will continue according to their individual lifecycles, expiration dates and maintenance requirements.

Therefore, merchants using PIN entry on mobile devices should not shut down their systems simply because they have heard the term “sunset.” They need to determine when the specific listing remains valid, whether the deployed configuration matches that listing, which party is responsible for PCI DSS obligations, and what will replace the solution if necessary.

Understand the Sunset Timeline and the Status of the Solution in Use

SPoC stands for Software-based PIN Entry on COTS, meaning a solution for entering PINs on commercial off-the-shelf (COTS) devices such as smartphones or tablets. According to PCI SSC’s description in Software-based PIN Entry on COTS (SPoC), a complete SPoC solution typically involves a PIN-entry application, a secure card reader (SCRP), a COTS device, and server-side monitoring and remote authentication systems.

The important distinction is that the sunset of the submission program and the expiration of a specific listing are not the same thing. Existing listings do not automatically expire on October 31, 2026; businesses must still comply with the expiration date, reassessment schedule and maintenance requirements applicable to each listing.

A merchant may fall into one of three situations:

Chú thích cho quảng cáo
  1. Using an active SPoC listing: there is no basis for concluding that the solution must be replaced immediately. However, record the expiration date, maintenance requirements and the provider’s support plan.
  2. Testing or selecting a solution that is not listed: do not assume that combining an application, reader and server system creates a valid SPoC solution. PCI SSC emphasizes that only complete, approved and listed SPoC solutions fall within the program, as stated in New FAQs on Software-based PIN Entry on COTS.
  3. Planning a new deployment or requiring long-term support: ask the provider about PCI MPoC, which PCI SSC describes as having been developed from SPoC and CPoC, or consider dedicated payment hardware.

The sunset itself does not demonstrate that PIN entry on mobile devices has become unsafe. It means that the SPoC program will no longer accept new submissions after the announced period, while businesses must manage the lifecycle of the specific solution they use.

Check the Listing, Configuration and PCI DSS Responsibilities

Check the Listing, Configuration and PCI DSS Responsibilities

Compare the Deployed Solution with the Listing

Ask the provider to supply, in writing, the exact solution name, listing identifier or reference, SPoC version, reassessment date, expiration date and support status. Do not check only the application’s commercial name. Compare the full configuration in operation at the merchant, including:

  • the payment application and operating-system versions;
  • the COTS smartphone or tablet model;
  • the secure card reader (SCRP) model;
  • the monitoring and authentication server system and relevant versions;
  • any usage limitations or conditions stated in the listing.

You can create an inventory with columns for the provider’s legal entity, listing name and identifier, application version, SCRP model, expiration or reassessment date, support status, MPoC roadmap or replacement option, and incident contact. Then compare the information with PCI SSC documentation and the service agreement. If the provider only gives a general response that the “solution is PCI-compliant” but cannot identify the relevant listing and matching configuration, treat that as an unverified item.

Determine PCI DSS Responsibilities

SPoC is a solution-assessment program; it does not replace the merchant’s PCI DSS obligations in full. PCI DSS applies to entities that store, process or transmit payment account data; a low transaction volume does not automatically exempt a business from its data-protection obligations. The required validation method may be specified by the acquiring bank, payment organization or acquirer. See also Do small merchants with limited transaction volumes need comply with PCI DSS?.

Even when payment processing is outsourced to a third party and the business does not directly store, process or transmit card data, the PCI DSS scope may be reduced but responsibility does not disappear. The business still needs to verify the provider’s compliance status, have a written agreement defining each party’s responsibilities, and complete the required validation method. See Does PCI DSS apply to merchants who outsource all payment processing operations and never store, process or transmit cardholder data?.

Ask the acquiring bank, acquirer or provider to answer at least the following questions in writing:

  1. Which SAQ or other PCI DSS validation method must the merchant complete?
  2. Which system scope and responsibilities include the mobile PIN-entry solution?
  3. Which requirements are the provider’s responsibility, and which are the merchant’s?
  4. If the listing expires before the migration, what option is available for continuing to accept transactions?

Plan and Validate the Migration Before Making Changes

Follow the sequence below so that work does not begin only after the listing has expired:

  1. Inventory the system: record every smartphone, tablet, SCRP reader, application, version, administrator account and point of sale in use.
  2. Verify the listing: compare the deployed solution with the listing, expiration date, reassessment schedule and maintenance requirements.
  3. Review the contract: look for provisions covering changes to the standard, version support, security incidents, expiry notices, service levels and migration costs.
  4. Confirm responsibilities: obtain confirmation from the acquiring bank or payment acquirer regarding the applicable PCI DSS scope, migration requirements and approved approach.
  5. Choose an approach: Options may include a suitable MPoC solution, a dedicated payment terminal or another method that does not require PIN entry on a COTS device. Do not assemble components yourself and treat the result as a solution approved by the PCI Security Standards Council (PCI SSC).
  6. Test before migration: use an environment or procedure approved by the provider to test chip transactions, contactless transactions where supported, refunds, loss of network connectivity, application updates, device locking and procedures for a lost device.
  7. Keep records: retain the listing, contracts, confirmations from the payment parties, test records, device configurations, responsibility assignments and recovery plan.

Remove the legacy solution only after the new approach has been tested, approved by the relevant parties and backed by a fallback payment method. If the current listing remains valid for a longer period, the business may continue operating under controlled conditions, but it should still set a review milestone before the actual expiry date.

Completion check: the person responsible must be able to answer three questions: until what date does the current solution remain valid; who is responsible for each part of PCI DSS; and, if support ends, which option will the merchant switch to without interrupting payments?

Security note: do not use an employee’s personal phone as a payment device if the business cannot control its configuration, applications, access permissions and ability to erase data remotely. PCI Mobile Payment Acceptance Security Guidelines for Merchants provides guidance on protecting devices and solutions according to the roles of merchants and providers; it does not replace PCI DSS.

If the migration fails, revert to the previous configuration only if its listing and contract are still valid. Record the incident, open a support request with the provider and use the fallback method approved by the acquiring bank or payment acquirer.

Reference source

  • PCI Security Standards Council Bulletin: Announcement of Sunset Periods for the PCI SPoC and PCI CPoC Standards
  • Software-based PIN Entry on COTS (SPoC)
  • New FAQs on Software-based PIN Entry on COTS
  • Does PCI DSS apply to merchants who outsource all payment processing operations and never store, process or transmit cardholder data?
  • Do small merchants with limited transaction volumes need comply with PCI DSS?
  • PCI Mobile Payment Acceptance Security Guidelines for Merchants

Chú thích cho quảng cáo
business compliance mobile payments payment security PCI DSS PCI SPoC POS
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleEntering Schengen with EES: Who Must Provide Biometric Data?
Nuj Coom
  • Website
  • Facebook
  • X (Twitter)
  • Instagram

I'm a doctor, for sure. But I also love writing and sharing knowledge, life experiences, web tricks, and useful lectures. Let's cheer for your passion.

Related Posts

Protect Small Businesses from Impersonation Scams

01/09/2026

AI-Powered Operational Optimization for Small Businesses

30/08/2026

Cross-Border Payments for Small Businesses

30/08/2026
Add A Comment
Leave A Reply Cancel Reply

Latest posts

Free Windows 11 Product Keys: Facts and Legal Activation

Cloud Repatriation for Websites: Should You Move to a VPS?

Evaluating green hosting providers: How to verify claims

IPv6 hosting: Complete website testing checklist

PCI SPoC 2026: Prepare Your Phone-Based PIN Payments Before Sunset

Advertisement
Chú thích cho quảng cáo

SUBSCRIBE TO UPDATES

Get the latest creative news from SaibABC.Com on web tips, design, and business.

Copyright © 2024. Designed by NujCoom.
  • Home
  • Contact
  • Privacy
  • Tiếng Việt
  • Hmoob

Type above and press Enter to search. Press Esc to cancel.