Skip to content
Winslow Compliance Partners
Our position, stated first. Winslow is not a Qualified Security Assessor, so we do not assess, sign Reports on Compliance or certify anybody. We prepare you and also introduce independent QSA firms.

Insight

PCI DSS mobile payments: taking cards on phones and tablets

PCI DSS mobile payments questions grow as more merchants accept cards on phones. So the key is choosing a validated solution and keeping devices under control.

  • Not a QSA, stated first
  • Introductions to independent QSAs
  • Written answers, no call
Pci dss mobile payments: pick a validated solution, manage the devices and validate yearly

How PCI DSS mobile payments work

There are two common setups. Either a small card reader connects to the phone, or the phone accepts contactless cards directly through software.

In both cases, the security comes mostly from the solution provider. Therefore the solution you choose matters more than the phone itself.

Validated solutions for PCI DSS mobile payments

PCI SSC publishes standards for accepting payments on commercial phones and tablets. Also, it lists solutions that have been validated.

SetupWhat to check
Reader attached to a phoneThe reader and solution are validated, for example under P2PE.
Software-based acceptanceThe solution is validated under the relevant PCI SSC mobile standard.
Unlisted appAsk the provider for evidence before using it.

PCI DSS mobile payments check

Tick what is true for every device that takes cards.

Your result appears here as you tick, so you can see what is still open.

What stays yours in PCI DSS mobile payments

The provider protects the payment flow. However, you still manage the devices and staff.

  • Keeping phones updated and locked
  • Removing access when staff leave
  • Following the provider's security instructions
  • Never entering card numbers into other apps

Common mistakes

Staff sometimes type card numbers into notes or messages for later. Therefore training must cover mobile habits too. Also, personal phones used for payments are hard to control, so business devices are safer.

In addition, check which questionnaire applies, because a validated solution can shorten it considerably.

Where Winslow helps

We review your mobile setup and confirm which questionnaire fits. We are not a QSA. Gap analysis generally runs $8,000 to $40,000. Validated solutions are listed in the official list of validated P2PE solutions for P2PE readers.

PCI DSS mobile payments questions

Are PCI DSS mobile payments allowed on personal phones?

Some solutions allow it, but control is harder. Business devices are usually safer.

Does a validated solution make PCI DSS mobile payments compliant?

It covers the payment flow. However, device management and policy stay yours.

Which SAQ fits PCI DSS mobile payments?

It depends on the solution. A validated P2PE reader, for example, may allow SAQ P2PE.

What about tablets at a counter?

The same rules apply, so treat them like any payment device.

Related guides

Review your PCI DSS mobile payments setup

Tell us which devices and apps you use. We reply in writing, usually within one business day.

Ask us anything