Live Webinar 

PCI MPoC: What It Takes to Pass the Software Security Test

PCI MPoC lets merchants accept card payments and PIN entry on their own phones. But dropping the terminal means that protections once provided by certified hardware now have to be proven in software, on devices an attacker may fully control.

Five MPoC requirements demand a 25-point attack rating, scored independently by your evaluation lab. That’s where many submissions run into trouble.

In this session, Digital.ai walks through how labs score attacks under Appendix B and why protection techniques and key architecture matter more than any feature list.

You’ll learn:

  • Why scalability is the largest single scoring factor and what actually earns those points
  • How wrappers, protection SDKs, and code injection compare when evaluated by a lab
  • How PCI’s July 2026 guidance on AI-assisted attacks changes attack costing
  • Where app hardening and white-box cryptography fit, and which requirements remain yours to build
  • Which decisions to settle with your lab early to keep annual checkpoints cost-effective

Designed for security architects, CISOs, and compliance leads at PSPs, neobanks, acquirers, and ISVs building acceptance on consumer devices.

Register Now

Speakers

Dan Shugrue

Sr. Director of Product Marketing
Digital.ai

Cole Herzog

Sr. Director, Engineering
Digital.ai