Castles Technology Validated Full SoftPOS Portfolio

The company achieved PCI MPoC security compliance for its integrated software-based payment suite.

Updated on Oct. 6, 2026 in Software

Isometric editorial illustration of a metallic payment chip stacked beside a rectangular software module block in muted tones.
Castles Technology has achieved PCI MPoC validation for its SoftPOS portfolio, establishing a new security standard for mobile payment acceptance. AI Illustration. Upload story photo >

Castles Technology has completed PCI MPoC validation for its complete SoftPOS portfolio, including its end-to-end solution, software, and attestation services. This validation provides a standardized security framework for enabling contactless and PIN payment acceptance on mobile devices.

Why it matters

Achieving PCI Mobile Payments on COTS (MPoC) validation allows businesses to deploy secure, software-based payment acceptance tools on standard tablets and smartphones. This simplifies the hardware infrastructure required for merchant transactions while maintaining rigorous payment security standards.

The validation encompasses three core components: the MPoC software, the Attestation and Monitoring (A&M) service, and the end-to-end solution. The system supports Android devices, enabling both contactless tap-to-pay and PIN entry through the CastlesPay suite.

The players

Castles Technology

A provider of payment hardware and software solutions focused on merchant terminal infrastructure.

The details

The solution relies on an isolated MPoC SDK — a software development kit that provides building blocks for developers — to integrate payment acceptance directly into business applications. The A&M service provides the necessary infrastructure for device attestation, which verifies the integrity of the hardware, along with ongoing security monitoring and risk assessment to protect against potential tampering.

Timeline

  1. October 6, 2026: Validation status announced for the SoftPOS portfolio.

The Tech Race

The validation follows the strict security requirements established by the PCI MPoC security framework for smartphone payment acceptance. This certification aligns the company's product architecture with industry standards to compete in the growing market for software-based point-of-sale systems.

Merchants using Android devices will gain the ability to process payments without dedicated hardware terminals once their applications integrate the updated SDK. The change allows for more flexible storefront setups, though specific roll-out dates for individual business apps remain unannounced.

The takeaway

This validation demonstrates the feasibility of securing mobile-based payments to match traditional hardware standards. Interested parties should monitor subsequent announcements regarding the integration of this SDK into local merchant platforms in the EMEA, Pacific, and LATAM regions.

Further reading

For broader trends in mobile transaction security, explore our Software coverage.

Source note: This article includes information reported by Financial IT.