Insight
PCI DSS mobile payments: taking cards on phones and tablets
PCI DSS mobile payments questions grow as more merchants accept cards on phones. So the key is choosing a validated solution and keeping devices under control.
- Not a QSA, stated first
- Introductions to independent QSAs
- Written answers, no call
How PCI DSS mobile payments work
There are two common setups. Either a small card reader connects to the phone, or the phone accepts contactless cards directly through software.
In both cases, the security comes mostly from the solution provider. Therefore the solution you choose matters more than the phone itself.
Validated solutions for PCI DSS mobile payments
PCI SSC publishes standards for accepting payments on commercial phones and tablets. Also, it lists solutions that have been validated.
| Setup | What to check |
|---|---|
| Reader attached to a phone | The reader and solution are validated, for example under P2PE. |
| Software-based acceptance | The solution is validated under the relevant PCI SSC mobile standard. |
| Unlisted app | Ask the provider for evidence before using it. |
PCI DSS mobile payments check
Tick what is true for every device that takes cards.
Your result appears here as you tick, so you can see what is still open.
What stays yours in PCI DSS mobile payments
The provider protects the payment flow. However, you still manage the devices and staff.
- Keeping phones updated and locked
- Removing access when staff leave
- Following the provider's security instructions
- Never entering card numbers into other apps
Common mistakes
Staff sometimes type card numbers into notes or messages for later. Therefore training must cover mobile habits too. Also, personal phones used for payments are hard to control, so business devices are safer.
In addition, check which questionnaire applies, because a validated solution can shorten it considerably.
Where Winslow helps
We review your mobile setup and confirm which questionnaire fits. We are not a QSA. Gap analysis generally runs $8,000 to $40,000. Validated solutions are listed in the official list of validated P2PE solutions for P2PE readers.
PCI DSS mobile payments questions
Are PCI DSS mobile payments allowed on personal phones?
Some solutions allow it, but control is harder. Business devices are usually safer.
Does a validated solution make PCI DSS mobile payments compliant?
It covers the payment flow. However, device management and policy stay yours.
Which SAQ fits PCI DSS mobile payments?
It depends on the solution. A validated P2PE reader, for example, may allow SAQ P2PE.
What about tablets at a counter?
The same rules apply, so treat them like any payment device.
Related guides
Review your PCI DSS mobile payments setup
Tell us which devices and apps you use. We reply in writing, usually within one business day.
Ask us anything