Tap to Pay lets a compatible smartphone or tablet accept contactless card and wallet payments without a separate card reader. The technology can reduce hardware cost and help mobile staff take payments anywhere, but merchants still need an approved provider, device security and proper reconciliation.
The phone becomes the payment-acceptance device
PCI SSC's mobile-payment standards cover solutions that use commercial off-the-shelf smartphones or tablets to accept cardholder data and, in some configurations, PIN. The customer taps a contactless card or wallet directly on the merchant device.
The merchant should use the payment provider's supported app and approved device configuration rather than attempting to build card acceptance from ordinary NFC tools. Payment security depends on the whole certified solution, not just the phone model.
MPoC is the current direction for mobile acceptance standards
PCI Mobile Payments on COTS, or MPoC, combines capabilities previously split across SPoC and CPoC standards. PCI SSC says SPoC and CPoC entered formal sunset periods from 1 May to 31 October 2026 as the mobile-payment standards portfolio evolves.
Existing listed SPoC and CPoC solutions can continue through their normal lifecycle, but merchants choosing new technology should ask providers how their product fits MPoC and current PCI listings. Do not buy only on marketing language such as "PCI ready".
Treat the smartphone as payment infrastructure
Require supported operating-system versions, device lock, updates and controlled app installation. A phone used for accepting cards should not be rooted, jailbroken or handed casually between employees using one shared login.
Use named merchant accounts where the provider supports them and remove lost devices immediately. The payment provider should be able to identify which device and user accepted a transaction, giving finance and security a usable audit trail.
Understand contactless, PIN and transaction behaviour
Mobile acceptance solutions differ in whether they support contactless-only transactions or can also handle PIN entry on the device under the relevant PCI model. The card issuer can still require verification or decline a transaction based on its risk rules.
Test the provider's behaviour for higher-value transactions, offline conditions and digital wallets before relying on the phone at events or field-service jobs. A phone-based terminal is only useful if staff know what happens when a transaction cannot complete normally.
Reconcile phone payments exactly like other merchant settlements
The payment may feel instant to the employee, but the merchant still receives funds according to the provider's settlement timetable. Track gross transaction, refund, chargeback, fee and net payout.
Use location or employee data to reconcile field payments where appropriate. If ten engineers accept payments on ten phones, finance should be able to trace each payment to the job and employee rather than only to one combined provider payout.
Keep a fallback when connectivity or device access fails
Mobile acceptance depends on the device, payment app, provider and network path. Maintain another legitimate payment option such as payment link, invoice bank transfer or a conventional terminal where the business cannot afford to stop taking payments.
Do not respond to a device failure by writing down customer card numbers for later entry. That can expand PCI scope and create security risk. A planned fallback should preserve or improve security rather than bypass it.
For field staff, pair the payment user with a job-management reference. If a plumber accepts £320 on a phone, the transaction should carry the work-order or invoice number so finance can reconcile the settlement without asking which customer was visited. This also makes refunds and disputes easier to investigate.
Define what happens when an employee leaves. Remove the merchant-app account, revoke device access and confirm no saved credentials remain. A personal phone used under a bring-your-own-device policy can still contain a business payment app, so offboarding must cover software access as well as physical terminals.
Compare Tap to Pay fees and reliability with a dedicated terminal. A smartphone solution can reduce hardware cost for occasional sellers, while a busy till may still need faster receipt printing, accessories and dedicated uptime. The best acceptance device depends on sales volume and operating environment, not novelty.
Check battery, connectivity and supported-device status before sending staff to an event or customer site. A software terminal that depends on one employee's low-battery personal phone is not a resilient acceptance setup. Provide charging arrangements and a fallback payment link or bank-transfer process.
Review refund permissions separately from sale permissions. Field staff may need to take payments but not issue large refunds. Role-based controls can reduce fraud while preserving operational speed, particularly where phones are used outside supervised retail premises.
Editorial Verdict
Tap to Pay can turn a supported phone into a practical merchant terminal with very little hardware. The security standard is moving toward PCI MPoC, while SPoC and CPoC entered sunset in 2026.
Choose a listed or appropriately validated provider, manage devices as payment infrastructure and reconcile settlements by employee or job. The convenience is real, but only when the smartphone is controlled as carefully as any other card terminal.
Sources
- PCI SSC, Mobile Payments on COTS (MPoC): https://www.pcisecuritystandards.org/standards/mobile-payments-on-cots-mpoc/
- PCI SSC, Standards catalogue and 2026 sunset notices: https://www.pcisecuritystandards.org/standards/
- PCI SSC, SPoC and CPoC sunset bulletin: https://www.pcisecuritystandards.org/wp-content/uploads/2026/05/PCI_SPoC_and_PCI_CPoC_Sunset_Bulletin.pdf