SoftPOS SDK
An SDK that turns a standard smartphone into a contactless payment terminal. It accepts EMV contactless payments through the NFC interface of an Android device, without dedicated POS hardware.
What is supplied
A software SDK that turns a standard smartphone into a contactless payment terminal. It is intended for embedding in terminals and SoftPOS, and is supplied as an implementation that has passed certification.
Specifications and certifications
How CPoC and MPoC differ
PCI has two SoftPOS standards, and their scope differs.
| Standard | Scope |
|---|---|
| PCI CPoC | Contactless card reading only; PIN entry is out of scope. PCI SSC has set 2026-05-01 to 10-31 as the transition period, and MPoC is now the current standard. |
| PCI MPoC | Contactless reading plus PIN entry on the smartphone screen, that is a software PIN pad |
Handling PINs in SoftPOS requires attestation, monitoring, key management, tamper detection and root detection, which in turn assumes a backend service alongside the SDK.
What SoftPOS is made of
| Element | Detail |
|---|---|
| Contactless kernel | Contactless Level 1 and Level 2 running on the phone's NFC interface |
| Software PIN pad | For MPoC. PIN entry on screen |
| Attestation | Continuous confirmation that the device is genuine and unmodified |
| Monitoring | Monitoring for fraud, tampering and abnormal behaviour |
| Key management | Distribution, rotation and revocation of cryptographic keys |
Verification when deploying this product
Because SoftPOS is a smartphone plus software rather than a dedicated terminal, it is verified differently. RF characteristics vary from handset to handset, so measurement at Level 1 on real devices matters.
| Aspect | Verification we recommend |
|---|---|
| RF characteristics and antenna | ProxiLAB Quest for waveform analysis and characterisation |
| Protocol behaviour | ProxiSPY Quest for non-intrusive monitoring |
| Phase drift immunity | Testing in combination with devices that use active load modulation |
| Level 3 and acceptance testing | ICCSimTMat and similar, for scheme integration testing |
Choosing the right Alcinéo stack
Alcinéo does not make test equipment. It supplies software that is embedded in the device under test. The scope of certification differs by product, so the schemes covered and the extent of any valid approval are confirmed individually. Completeness increases along the path from component kernel, to SDK, to operations, to an industry-specific stack.
| Product | If you are considering |
|---|---|
| Level 2 contactless kernel | You want to embed an EMV kernel in your own terminal or SoftPOS, as a component |
| MPoC Software SDK | You want to implement software-based payment aligned with PCI MPoC |
| ★ SoftPOS SDK (this page) | You want to turn a standard smartphone into a contactless payment terminal |
| A&M Backend Services | You want attestation and monitoring for SoftPOS operation, run from a backend |
| SoftPOS for transit | You want a complete stack for gates and transit operators |
To verify this device under test
A terminal with this runtime embedded — the device under test — is tested at Level 1, Level 2 and Level 3 with the testers below. What is verified is not the runtime on its own but the device under test with the runtime embedded.
