Positive ONE Group corporate siteCorporate site
ENEnglish
Embedded runtime · Alcinéo

SoftPOS SDK

An SDK that turns a standard smartphone into a contactless payment terminal. It accepts EMV contactless payments through the NFC interface of an Android device, without dedicated POS hardware.

Supplied by Alcinéo Supported standards PCI MPoC · EMV Contactless L2 Embedded runtime / SDK
PositionThis is a runtime embedded in a reader or terminal that performs the payment processing. It is not test equipment. It is a product that sits on the device under test, which the test equipment then verifies. Positive ONE supplies it as an implementation built for certification. The SoftPOS SDK has completed PCI MPoC evaluation and is listed by the PCI Security Standards Council as MPoC Software. Type approval of the EMV Level 2 kernel and scheme approval are required separately, for each target hardware and each scheme.

What is supplied

A software SDK that turns a standard smartphone into a contactless payment terminal. It is intended for embedding in terminals and SoftPOS, and is supplied as an implementation that has passed certification.

Specifications and certifications

PCI MPoCEMV Contactless L2

How CPoC and MPoC differ

PCI has two SoftPOS standards, and their scope differs.

How CPoC and MPoC differ
StandardScope
PCI CPoCContactless card reading only; PIN entry is out of scope. PCI SSC has set 2026-05-01 to 10-31 as the transition period, and MPoC is now the current standard.
PCI MPoCContactless reading plus PIN entry on the smartphone screen, that is a software PIN pad

Handling PINs in SoftPOS requires attestation, monitoring, key management, tamper detection and root detection, which in turn assumes a backend service alongside the SDK.

What SoftPOS is made of

What SoftPOS is made of
ElementDetail
Contactless kernelContactless Level 1 and Level 2 running on the phone's NFC interface
Software PIN padFor MPoC. PIN entry on screen
AttestationContinuous confirmation that the device is genuine and unmodified
MonitoringMonitoring for fraud, tampering and abnormal behaviour
Key managementDistribution, rotation and revocation of cryptographic keys

Verification when deploying this product

Because SoftPOS is a smartphone plus software rather than a dedicated terminal, it is verified differently. RF characteristics vary from handset to handset, so measurement at Level 1 on real devices matters.

Verification when deploying this product
AspectVerification we recommend
RF characteristics and antennaProxiLAB Quest for waveform analysis and characterisation
Protocol behaviourProxiSPY Quest for non-intrusive monitoring
Phase drift immunityTesting in combination with devices that use active load modulation
Level 3 and acceptance testingICCSimTMat and similar, for scheme integration testing

Choosing the right Alcinéo stack

Alcinéo does not make test equipment. It supplies software that is embedded in the device under test. The scope of certification differs by product, so the schemes covered and the extent of any valid approval are confirmed individually. Completeness increases along the path from component kernel, to SDK, to operations, to an industry-specific stack.

Choosing the right Alcinéo stack
ProductIf you are considering
Level 2 contactless kernelYou want to embed an EMV kernel in your own terminal or SoftPOS, as a component
MPoC Software SDKYou want to implement software-based payment aligned with PCI MPoC
★ SoftPOS SDK (this page)You want to turn a standard smartphone into a contactless payment terminal
A&M Backend ServicesYou want attestation and monitoring for SoftPOS operation, run from a backend
SoftPOS for transitYou want a complete stack for gates and transit operators

To verify this device under test

A terminal with this runtime embedded — the device under test — is tested at Level 1, Level 2 and Level 3 with the testers below. What is verified is not the runtime on its own but the device under test with the runtime embedded.