In-Person Payments

Tap to Pay, Explained: How Soft POS Turns Any Phone Into a Payment Terminal

The Cashless Ai till on the left taking a table order, and the kitchen display on the right showing the same tickets as they are prepared.

For twenty years, accepting a card in person meant buying a certified piece of hardware. Soft POS collapses that requirement into an app: the NFC antenna already in a merchant's phone becomes the reader, and the security boundary moves from a tamper-proof chip to an attested software stack in the cloud.

What Soft POS actually is

Soft POS — the standards bodies call it CPoC and MPoC, Apple and Google call it Tap to Pay — is a software payment terminal. Instead of routing a contactless card through a certified reader with a tamper-resistant secure element, the merchant's own phone reads the card over NFC and hands the encrypted payload to an attested application.

The distinction matters because it changes who carries the security burden. A hardware terminal proves it has not been tampered with physically. A Soft POS app has to prove the same thing continuously, in software, on a device the acquirer does not control — which is why attestation and back-end monitoring sit at the centre of every certification scheme.

ANATOMY OF A TAP

  1. 01Cardholder tapsEMV payload read over NFC
  2. 02Attested appDevice integrity checked
  3. 03Cashless CortexRisk scored, keys resolved
  4. 04AcquirerAuthorised in ~900ms
Fig. 1 — The four hops in a Soft POS authorisation. Only the first happens on the merchant's device; everything after it is server-side, which is what keeps the phone out of PCI scope.

How a tap becomes a payment

The end-to-end flow looks deceptively similar to a hardware terminal, but three of the five stages have moved off the device entirely.

  1. 01Attestation handshakeBefore the reader ever activates, the SDK asks the OS to prove the device is unrooted, the app binary is unmodified and the OS build is patched. A failed attestation kills the session — not the transaction.
  2. 02Reader activationThe NFC controller is put into card-emulation-read mode. On iOS this is gated behind Apple's Tap to Pay entitlement; on Android it runs through the standard NFC stack under an MPoC-certified wrapper.
  3. 03Encrypted captureTrack and chip data never touch application memory in the clear. The payload is encrypted to a scheme key the app cannot read and shipped straight to the backend.
  4. 04Cloud PIN and riskFor high-value taps, PIN entry is rendered by a remote, certified component rather than the merchant app. Cashless Cortex scores the transaction against merchant history in the same round trip.
  5. 05Authorisation and receiptThe acquirer responds, the app shows the result, and a digital receipt is issued over SMS, email or wallet pass. Median end-to-end time on our UK estate is 0.9 seconds.
The moment you stop shipping hardware, onboarding stops being a logistics problem and starts being a software problem. That is the whole unlock — a merchant can be live in the time it takes to download an app.
Aria ChenHead of Payments, Cashless Ai

The PCI MPoC certification path

MPoC (Mobile Payments on COTS) replaced the older CPoC and SPoC standards in 2022 and is the only route that lets you take both the card read and the PIN on a commercial off-the-shelf device. It is modular: you certify components, not one monolithic product, which is why most merchants inherit certification from their provider rather than pursuing it directly.

Device attestationContinuous proof that the OS, the app binary and the NFC stack have not been tampered with. Re-checked on every session.
Estate monitoringA back end that can spot anomalous behaviour across the fleet and revoke a single device in seconds, not days.
Key isolationCard data is encrypted to keys the merchant app can never access. The phone is a pipe, never a vault.

Terminal vs. Soft POS: the numbers

Averages across 1,400 UK merchants onboarded to Cashless Ai between January 2025 and June 2026. Your acquirer pricing will differ; the shape of the curve rarely does.

CRITERIAHARDWARE TERMINALCASHLESS AI SOFT POS
Upfront cost per till£220 – £400 per unit, plus spares£0 — the phone is already paid for
Time to first payment5 – 12 days including shippingUnder 30 minutes, fully self-serve
Certification modelPCI PTS POI, re-certified per devicePCI MPoC, inherited from the provider
PIN entryPhysical keypad on the terminalCVM on glass with remote cloud PIN
Peak throughputHighest — dedicated lane hardwareStrong, but battery and OS updates bite
Best fitFixed high-volume checkout lanesPop-ups, field sales, delivery, queue-busting

Take a real tap on your own phone today

Sandbox merchant, live £1 contactless payment, no card reader in the box.

Book a Demo

TAGGED

  • Tap to Pay
  • Soft POS
  • PCI MPoC
  • NFC
  • Merchant Ops

WRITTEN BY

Aria Chen

Head of Payments, Cashless Ai

Aria leads acquiring and in-person payments at Cashless Ai. She spent eight years shipping terminal firmware before deciding the terminal was the problem.

Upgrade Your Business Operating System Today

Replace multi-vendor clutter with one intelligent ecosystem. Get up and running in under 24 hours.