FAQ Section
Card Payments

Chip, Contactless and SoftPOS Payments Explained

 

Understand EMV chip-and-PIN, contactless tap-to-pay and SoftPOS technology that turns a smartphone into a card machine, and how each keeps cards secure.

In-person card payments in South Africa have moved through three generations of technology: the magnetic stripe (now largely retired), the EMV chip with a PIN, and contactless tap-to-pay. The newest development is SoftPOS, which turns an ordinary Android smartphone into a card machine with no extra hardware.

All three modern methods are built on the same EMV standard, which means every transaction is protected by a unique cryptogram that cannot be replayed or counterfeited. This page explains how each method works and what merchants should know when choosing how to accept in-person payments.

How Does Chip-and-PIN Work?

An EMV chip card is a small computer. When the card is inserted into a terminal:

  1. The terminal and the chip exchange data and agree on how to verify the cardholder.
  2. The cardholder enters their PIN, which proves they are the genuine cardholder.
  3. The chip generates a one-time cryptogram unique to that transaction.
  4. The transaction is sent online to the issuer for approval.

Because the cryptogram changes every time, data skimmed from a chip transaction cannot be used to create a working counterfeit card. This is the main reason chip cards replaced magnetic stripe cards, which stored static data that was easy to clone.

How Does Contactless (Tap-to-Pay) Work?

Contactless payments use NFC (near-field communication) to exchange the same EMV data over a very short range, typically a few centimetres, instead of through physical contact. The security model is the same as chip: a unique cryptogram per transaction.

Key points about contactless in South Africa:

  • Taps below a bank-set limit usually do not require a PIN; above the limit the terminal prompts for a PIN.
  • Issuers apply their own velocity controls, such as requiring a PIN after several consecutive taps.
  • A card cannot be debited accidentally from a distance; the card must be effectively touching the reader, and a terminal processes only one transaction at a time.

Phones and watches using Apple Pay, Google Pay or Samsung Pay tap in exactly the same way, but replace the card number with a device token and the PIN with biometrics. See What Are Digital Wallets?.

What Is SoftPOS?

SoftPOS (software point of sale, also called tap-on-phone) is technology that lets a standard NFC-enabled Android smartphone accept contactless payments directly, with no card machine, dongle or card reader.

How it works:

  • The merchant installs a certified SoftPOS app on their phone.
  • The customer taps their card, phone or watch on the back of the merchant's phone.
  • Where a PIN is required, the customer enters it securely on the merchant's phone screen.
  • The transaction is processed online like any other contactless payment.

SoftPOS is certified against dedicated security standards that isolate and protect card data and PIN entry within the app, so the merchant's phone never sees usable card details.

Why SoftPOS matters for South African businesses

  • Low barrier to entry – no terminal hardware to buy or rent, which suits sole traders, market vendors, delivery drivers and mobile services.
  • Instant scale – a business can equip an entire fleet of staff with payment acceptance using the phones they already carry.
  • Full card-present security – SoftPOS transactions are genuine EMV contactless transactions, with the same low fraud profile as a traditional terminal.

The practical limitation is that SoftPOS only accepts contactless payments; a card without a working contactless function cannot be inserted or swiped.

SoftPOS Security Standards: COTS, CPoC, SPoC and MPoC

SoftPOS solutions are certified against a family of PCI Security Standards Council standards. The names look similar, so it helps to understand what each one covers.

What does COTS mean?

COTS stands for commercial off-the-shelf — an ordinary consumer device such as an Android smartphone or tablet, bought from any retailer, rather than purpose-built payment hardware. Because a COTS device was never designed as a secure payment terminal, the PCI standards below define how payment software must protect card data and PINs when running on it.

What is SPoC (Software-based PIN Entry on COTS)?

SPoC was the first standard, published in 2018. Under SPoC:

  • Card data is read by a small hardware dongle (a Secure Card Reader for PIN, or SCRP) attached to the phone.
  • Only the PIN is entered in software, on the COTS device's screen.
  • The PIN and card data travel through separate, encrypted channels and are only recombined at the processing host.

SPoC still requires a piece of dedicated hardware, so it is best thought of as a halfway step between a traditional terminal and true tap-on-phone.

What is CPoC (Contactless Payments on COTS)?

CPoC, published in 2019, removed the hardware reader entirely:

  • The phone's built-in NFC interface reads the contactless card or wallet directly.
  • No PIN entry is allowed — transactions are limited to those that do not require cardholder verification, such as taps below the PIN limit.

CPoC made hardware-free acceptance possible, but the no-PIN restriction capped the transaction values a merchant could accept.

What is MPoC (Mobile Payments on COTS)?

MPoC, published in 2022, is the newest and most complete standard, and it is where the industry is heading. It combines and extends the previous two:

  • Contactless acceptance on the phone's NFC interface (like CPoC), and
  • Software-based PIN entry on the same device (like SPoC, but without the hardware reader).

MPoC is modular, so vendors can certify different combinations of features, and it allows higher-value transactions because the customer can enter their PIN when prompted. A modern SoftPOS app accepting a tap and then a PIN on the merchant's phone is typically an MPoC-certified solution.

StandardCard readingPIN entryExtra hardware needed
SPoC (2018)Hardware dongle (SCRP)On the phone screenYes — card reader
CPoC (2019)Phone's NFCNot permittedNo
MPoC (2022)Phone's NFCOn the phone screenNo

What does HSM-backed mean?

An HSM (hardware security module) is a tamper-resistant physical device that generates, stores and uses cryptographic keys without ever exposing them, even to the systems that call it. SoftPOS is described as HSM-backed because the security that a traditional terminal provides in hardware is moved to HSMs in the processing back end:

  • The PIN entered on the merchant's phone is encrypted immediately on the device and can only be decrypted inside an HSM at the processor or acquirer.
  • Payment keys are generated and managed inside HSMs, never stored on the phone in usable form.
  • Back-end attestation and monitoring services continuously check that the SoftPOS app and device have not been tampered with (for example rooted or running a modified app), and can block a compromised device from transacting.

The result is that even though the merchant's phone is an ordinary consumer device, card data and PINs are never available to the phone's operating system, other apps or the merchant — the sensitive cryptography always happens inside certified hardware on the processing side.

Which Option Should a Merchant Choose?

  • Choose a traditional terminal for high-volume fixed tills where inserting a card must remain possible.
  • Choose SoftPOS for mobile, low-volume or many-user scenarios where carrying terminals is impractical.
  • Both routes produce card-present transactions with the favourable risk and liability profile described in Card-Present vs Card-Not-Present.
Copyright © 2026 Kwik Payments