Home Home / Insights / Blog

What Is SoftPOS? (Tap to Pay on Android Explained)

2026-08-28    Author : ZCS

Key Takeaways

  • ● SoftPOS turns an NFC-enabled Android phone into a card-present terminal by running PCI MPoC-certified software instead of dedicated payment hardware.
  • ● PCI MPoC, finalized by the PCI Security Standards Council in 2022, replaced the earlier CPoC and SPoC frameworks and added on-screen PIN entry.
  • ●  The global SoftPOS market reached roughly $534 million in 2026 and is projected to hit $1.24 billion by 2030, according to Grand View Research.
  • ● Android devices accounted for 58.4% of SoftPOS platform revenue in 2025, ahead of iOS, per the same industry analysis.
  • ● Tap to Pay on Android requires a Google Play Protect-certified device, an unmodified bootloader, and Android 9.0 or higher to process transactions.

A merchant who wants to take a card payment no longer needs a separate reader bolted to a tablet or a countertop terminal wired to a router. Street vendors, pop-up retailers, and delivery couriers increasingly rely on mobile POS setups built for street vending where a phone itself becomes the checkout device, and SoftPOS is the software layer that makes that possible.
The technology sits on top of a certification framework most shoppers never see but every acquirer enforces before a phone is allowed to process a live transaction.
SoftPOS uses PCI MPoC-certified software to convert commercial NFC-enabled smartphones into card-present payment terminals for merchants without dedicated hardware budgets. Contactless acceptance today splits between software-only Tap to Pay apps, represented by Visa's Tap to Pay on Android, and dedicated Android POS terminals with built-in secure elements, exemplified by traditional payment terminal manufacturers.
The category lines between these two paths are drawn by certification and supply model, not marketing, and the rest of this guide breaks down exactly where those lines sit.

 

Tap to Pay on Android POS


1. What Is SoftPOS?

SoftPOS is software that turns a standard NFC-enabled smartphone or tablet into a contactless payment terminal without requiring a card reader or any additional hardware. A customer taps their contactless card, phone, or wearable on the merchant's device, and the app processes the transaction through the same rails a physical terminal would use. The term itself is an industry umbrella: American Express's own SoftPOS FAQ documentation groups the technology under Contactless Payments on COTS (CPoC), Mobile Payments on COTS (MPoC), and the branded terms Tap to Pay and Tap to Phone that individual card networks use in consumer-facing marketing.
Confusion around terminology is common because vendors, processors, and card networks each use a different label for what is functionally the same certification path. A payment app validated under PCI MPoC can legally be called SoftPOS, Tap to Phone, Tap on Phone, or Tap to Pay, depending on which company is describing it.


1.1 SoftPOS vs mPOS vs Traditional POS Terminals

The three terms get used interchangeably online, but they describe different hardware relationships.
 

Category Hardware Required Certification Path Typical User
SoftPOS None — runs on a standard NFC smartphone PCI MPoC (formerly CPoC/SPoC) Micro-merchants, pop-ups, couriers
mPOS (mobile POS) A phone or tablet plus a small attached card reader PCI PTS on the reader, PCI DSS on the app Small retailers, market stalls
Traditional POS terminal A dedicated, certified payment device PCI PTS 5.x, EMV L1/L2 High-volume retail, restaurants


SoftPOS is technically a subset of mPOS, distinguished by the absence of any physical reader attachment. Every SoftPOS deployment is mobile POS, but not every mobile POS deployment is SoftPOS.


2. How Does Tap to Pay on Android Actually Work?

Tap to Pay on Android relies on the phone's built-in NFC antenna to read the same encrypted data a countertop terminal would capture. When a customer taps their card or wallet, the phone's NFC controller establishes a short-range connection, pulls the tokenized card data, and passes it to the payment app rather than to the operating system's general NFC stack. The app then routes the transaction through the merchant's payment processor exactly as a hardware terminal would, returning an approval or decline within seconds.
Security in this model depends on isolating the payment app from the rest of the phone's software environment. A compromised or rooted device breaks that isolation, which is why certification bodies test far more than whether the NFC hardware technically works.


2.1 The Role of PCI MPoC Certification

PCI MPoC governs which SoftPOS applications are allowed to touch live card data. Visa's own developer documentation on PCI MPoC compliance states that its Tap to Pay on Android solution is built to comply with the PCI Security Standards Council's Mobile Payments on COTS standard, using a transparent processing overlay so the merchant's normal checkout screen stays visually intact during a transaction. The certification process evaluates the app's software integrity, its attestation reporting to a monitoring service, and — for solutions that support PIN entry — the security of the on-screen keypad.
MPoC absorbed two earlier, narrower standards. CPoC covered contactless-only transactions with no PIN support, while SPoC ("PIN on Glass") added secure PIN capture but stopped short of a unified framework. The 2022 PCI SSC release folded both into MPoC, which now certifies software applications, SDKs, or complete solutions against roughly 192 individual security requirements covering everything from key management to remote device monitoring.

 


3. What Hardware Does Tap to Pay on Android Require?

Not every Android phone qualifies, and the requirements are stricter than most merchants expect going in.
Standard Tap to Pay on Android deployments require Android 9.0 or higher, an active NFC radio, and Google Play Protect certification on the handset. Selecting a device with an unmodified bootloader and current security patches prevents transaction declines and PCI MPoC attestation failures during live checkout.
Certified security matters more here than raw processing power, since the phone itself never displays or stores the customer's actual card number.

 

Requirement Typical Threshold Why It Matters
Android OS version 9.0 or higher (some apps require 11+ or 12+) Older versions lack security APIs MPoC apps depend on
NFC hardware Built-in, functioning antenna Required to read the contactless card or wallet
Google Play Protect Certified, active status Confirms the device passed Google's malware and integrity checks
Bootloader Locked, unmodified Rooted or unlocked devices are excluded from MPoC-certified apps
Connectivity Stable internet connection Required for real-time authorization and attestation reporting


A deeper breakdown of device-level thresholds is covered in Android hardware requirements for Tap to Pay, which walks through OS-version fragmentation across manufacturers in more detail.
Fragmentation is the practical obstacle most write-ups skip over. Android's open licensing model means Samsung, Xiaomi, Motorola, and dozens of smaller manufacturers each ship their own build on top of the base OS, with different security patch schedules and, in some cases, delayed Play Protect certification rollouts. A phone technically running Android 9.0 may still fail an MPoC-listed app's attestation check if its manufacturer has fallen behind on monthly security patches, which is why processors increasingly publish approved-device lists rather than relying on the OS version number alone. Enterprise deployments that manage phones through mobile device management software sometimes qualify for extended support windows even after a given Android version reaches its official end of life, provided every device stays centrally patched and locked.
Device tokenization requirements sit alongside the OS-version question. Google's own developer documentation on supported devices sets the baseline at Android 9.0 or higher, with NFC and host card emulation support required on the phone and NFC-enabled terminals required on the merchant side. Devices that fail security checks, including rooted phones or those running unapproved custom ROMs, are blocked from processing payments regardless of NFC hardware capability.
Battery behavior deserves separate attention because it rarely shows up in a spec sheet the way OS version or NFC hardware does. A phone running a SoftPOS app alongside inventory software, messaging, and navigation drains faster than the same phone used purely as a payment terminal, and cold weather or direct sunlight accelerates that drain further for outdoor vendors. None of that shows up as a certification failure — the transaction still processes correctly — but it does mean a merchant's practical uptime depends on habits like carrying a power bank or rotating between two charged devices during a long shift, something a dedicated terminal with a purpose-built battery does not require.
Merchants running outdoor operations should weigh these thresholds against the realities of field use, where NFC checkout devices for outdoor sellers face different battery, connectivity, and durability pressures than an indoor countertop, particularly when a shift runs a full day away from a wall outlet.


4. Is SoftPOS PCI Compliant and Secure?

SoftPOS security is a certification question, not a hardware question. A phone with excellent NFC hardware still cannot legally process card-present transactions unless the specific application installed on it holds current PCI MPoC listing.
The deployment of SoftPOS in PIN-required transaction environments depends on PCI MPoC's PIN-on-glass certification path. Consumer-mode NFC sharing on an unmanaged phone triggers PCI non-compliance, while an MPoC-listed application with remote attestation complies with acquirer security rules akin to a certified countertop terminal.
Workplace or field deployment hinges on that one distinction more than any marketing claim about a particular app's polish. A merchant downloading an uncertified "tap to pay" app from an unofficial source is not protected by any of the attestation, monitoring, or key-management requirements PCI MPoC mandates, even if the transaction technically completes.
Acquirers and processors, not merchants, typically manage the ongoing attestation and monitoring obligations that keep a SoftPOS deployment compliant. That division of responsibility is one reason large processors have started marketing MPoC-certified SoftPOS as a standard acceptance option rather than an experimental add-on, since the compliance burden sits with them rather than with the individual merchant's IT staff.


5. SoftPOS vs Dedicated POS Hardware: When Each Makes Sense

SoftPOS solves a specific problem — eliminating upfront hardware cost — but it does not eliminate every reason a merchant might want dedicated equipment.
 

Factor SoftPOS Dedicated POS Terminal
Upfront hardware cost None — uses the merchant's existing phone Requires purchasing certified hardware
Battery life for full-day use Limited by phone battery, shared with other apps Dedicated battery built for extended checkout cycles
Receipt printing Requires a separate printer or digital receipt Often integrated (built-in thermal printer)
Durability in outdoor/high-volume settings Consumer-grade phone hardware Rugged, purpose-built enclosures available
Certification scope App-level PCI MPoC Device-level PCI PTS plus app-level standards


Tap to Pay versus a dedicated terminal becomes a live question once transaction volume climbs, since a phone competing for battery and processing power with a merchant's other apps behaves differently than a device built exclusively for checkout. High-volume restaurants and multi-lane retail counters typically outgrow a single phone's practical limits well before they outgrow a certified terminal's.
Merchants who need both an app-based fallback and a purpose-built device often turn to open Android POS hardware that keeps the software layer flexible while adding a dedicated secure element, certified Android hardware like the ZCS Z90 among the options built around that model, alongside other Android-based smart terminals and traditional card-present terminal manufacturers such as PAX and Ingenico. The choice is rarely SoftPOS instead of hardware; it is SoftPOS until a specific volume, durability, or battery threshold is crossed.


6. Who Actually Uses SoftPOS Today?

SoftPOS adoption clusters around merchants for whom a dedicated terminal represents disproportionate upfront cost or operational friction relative to transaction volume.

  • ● Micro-merchants and market vendors who process a handful of transactions per day and cannot justify a $300–$600 dedicated terminal.
  • ● Delivery couriers and field sales reps who need occasional card-present capability without carrying separate hardware.
  • ● Pop-up retail and event vendors operating for days or weeks at a time, where hardware rental costs exceed the value of the engagement.
  • ● Restaurants adding line-busting or tableside payment without deploying a full fleet of dedicated handhelds.
  • ● ISVs and payment platforms building card acceptance into an existing app rather than partnering with a hardware vendor.

That last group is where the hardware platform behind a SoftPOS build becomes a genuine engineering decision rather than a checkout-line convenience, since a payments platform embedding MPoC-certified SDKs still has to account for the device fragmentation Android's open ecosystem creates. A software company building a payment product inherits every OS-version and chipset variation its merchant base happens to own, which is a materially different problem than a retailer simply choosing an app to download.

 

Learn more about tap to pay pos


7. SoftPOS Market Growth in 2026

Adoption numbers back up what processors have been signaling in their own marketing. A handful of years ago, SoftPOS pilots were framed as a stopgap for merchants who could not yet afford proper hardware. That framing has largely disappeared from current acquirer and processor materials, replaced by language that positions certified SoftPOS as a standard acceptance option sitting next to countertop terminals and mobile card readers rather than beneath them. The shift tracks a broader move among banks and payment service providers to use SoftPOS for onboarding micro-merchants at scale while also offering it to larger retailers as a line-busting tool during peak hours.
SoftPOS adoption has moved from pilot programs to standard acquiring infrastructure over the past several years. According to Grand View Research's SoftPOS market analysis, published in 2026, the Android segment led the SoftPOS market with a 58.4% revenue share in 2025, ahead of iOS, driven by Android's larger global smartphone base.
Market sizing figures vary by research firm, but the direction is consistent. One 2026 estimate values the global SoftPOS market at approximately $503.9 million for the year, while a separate Grand View Research analysis projects growth from $534.1 million in 2026 to $1,243.9 million by 2030, at a compound annual growth rate of 23.1%. The spread between estimates reflects differing methodology on which mPOS categories count as "SoftPOS," but every major forecast agrees on double-digit annual growth through the end of the decade.
Processor-side commentary in early 2026 has shifted from framing SoftPOS as an experimental add-on toward treating MPoC-certified SoftPOS as a standard terminal type sitting alongside traditional hardware in the acquiring stack. That shift matters more for merchants than the specific dollar figures, since it signals broader bank and processor support rather than a niche fintech offering with uncertain longevity.

 

Contact us


8. FAQ

Q1. Is SoftPOS the same as a mobile card reader?
No. A mobile card reader is a small piece of hardware — typically a dongle or sled — attached to a phone or tablet. SoftPOS requires no attached hardware at all; the phone's own NFC antenna and a certified app handle the entire transaction.
Q2. What Android version do I need for Tap to Pay?
Google's baseline requirement is Android 9.0 or higher with NFC support, though individual payment apps and processors sometimes set stricter minimums, such as Android 11 or 12, based on their own security review.
Q3. Is SoftPOS secure without a physical PIN pad?
Yes, provided the app is PCI MPoC-certified for PIN-on-glass. The standard requires the on-screen keypad to meet the same tamper-resistance and data-isolation requirements a physical PIN pad would, verified through independent lab testing before certification.
Q4. Can SoftPOS fully replace a dedicated POS terminal?
For low-volume or mobile merchants, often yes. For high-volume retail or restaurant counters, SoftPOS typically supplements rather than replaces dedicated hardware, since battery life, receipt printing, and durability needs exceed what a shared-use smartphone comfortably handles across a full shift.
Q5. Does SoftPOS work without an internet connection?
No. SoftPOS requires a stable internet connection to authorize transactions and to maintain the remote attestation and monitoring reporting PCI MPoC mandates, unlike some dedicated terminals that support limited offline transaction queuing.

Have a Question? Write to Us!
Contact
ADD: Room 402, Dewisen Building, No. 16, Gaoxin Nan Seventh Road, Nanshan District, Shenzhen City, China,518000