# Top tips for securing SoftPOS payments
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-06-14
Category: FINANCE
Category URL: https://financedigest.com/category/finance
Meta Title: Ensuring Security in SoftPOS Solutions
Meta Description: Explore the importance of app security and back-end systems in ensuring the safety and trust of consumers and merchants when using SoftPOS solutions for
URL: https://financedigest.com/top-tips-for-securing-softpos-paymentshtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/soft-payments-1736838283247-compressed.jpg)

_By **Christian Damour,** Pre-sales Manager – Security at Fime_

Digital payments have sky-rocketed in popularity as consumers have sought new, more hygienic ways to pay. SoftPOS payments offer numerous benefits to consumers and merchants alike. Comprised of software solutions that run on Android Commercial Off-The-Shelf (COTS) devices, they can enable [digital payment](https://www.financedigest.com/can-i-please-speak-to-someone-why-building-relationships-is-still-crucial-in-digital-payments.html "“Can I please speak to someone?” Why building relationships is still crucial in digital payments") acceptance in a cost-effective and simple way.

However, SoftPOS solutions must live up to the seamless, consistent and trusted [experience provided by traditional payment](https://www.financedigest.com/curating-a-fully-contactless-customer-experience-for-payments.html "Curating A Fully Contactless Customer Experience for Payments ") terminals. [Security and confidence are part of this and fundamental to the ongoing adoption](https://www.financedigest.com/the-push-and-pull-of-identity-security-adoption-in-the-financial-services-industry.html "The push and pull of identity security adoption in the financial services industry") and success of the technology. This blog explores the [security considerations for SoftPOS solutions](https://www.financedigest.com/securing-financial-institutions-with-the-help-of-pam-solutions.html "Securing financial institutions with the help of PAM solutions").

**Important: app [security & back-end system must](https://www.financedigest.com/fintechs-must-remove-security-and-compliance-friction-to-unlock-new-growth.html "Fintechs Must Remove Security and Compliance Friction to Unlock New Growth") work together**

Some SoftPOS solutions rely on hardware-backed features such as Trusted Execution Environment (TEE) [technologies to add additional security](https://www.financedigest.com/top-5-security-technologies-that-every-finance-institution-workplace-should-consider.html "Top 5 Security Technologies That Every Finance Institution Workplace Should Consider"). However, most [need to be hardware-agnostic to support as many devices as possible](https://www.financedigest.com/do-you-need-financial-guidance-or-financial-advice-or-possibly-both-find-out-here.html "Do You Need Financial Guidance Or Financial Advice – Or Possibly Both? Find Out Here"). In this case, devices could be rooted and infected with malware. So, it is extremely important to [implement as many security](https://www.financedigest.com/how-cloud-is-driving-forward-implementation-of-zero-trust-security.html "How Cloud is Driving Forward Implementation of Zero Trust Security") features as possible within the mobile app itself to protect consumers and merchants. In addition, a back-end system seamlessly [working with the application is required to bring additional security](https://www.financedigest.com/combating-the-security-risk-of-remote-working.html "Combating the security risk of remote working ").

Another reason that [security is so fundamental is that consumers need](https://www.financedigest.com/why-preparation-for-new-swift-cyber-security-standards-needs-to-start-now.html "‘Why preparation for new SWIFT cyber security standards needs to start now’") to feel safe and comfortable with tapping their card and in some cases entering their PIN on a stranger’s smartphone. While [digital payments](https://www.financedigest.com/italys-nexi-signs-digital-payments-deal-with-tims-olivetti.html "Italy’s Nexi signs digital payments deal with TIM’s Olivetti") have recently seen a rise, in part due to the pandemic, not all consumers are on board yet. Having the relevant security certifications offers assurance that the technology is fit for purpose, valuable [payment data is protected and paying will not expose consumers to fraud](https://www.financedigest.com/how-can-you-reduce-the-risk-of-fraud-in-b2b-payments.html "How can you reduce the risk of fraud in B2B payments?").

**Technologies to rely on**

![Christian Damour](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/image002-1736838283309-compressed.jpg)

Christian Damour

One important security element that developers [must ensure](https://www.financedigest.com/finance-firms-must-ensure-they-fix-data-fundamentals.html "Finance firms must ensure they fix data fundamentals") is in place on SoftPOS solutions is attestation and monitoring. This feature is there to thoroughly check the security and [integrity of the solution](https://www.financedigest.com/the-collective-power-of-partnerships-integrating-payment-solutions-to-drive-business-success.html "The collective power of partnerships: integrating payment solutions to drive business success") and constantly monitor that it has not been corrupted. The mobile application sends information about the status and integrity of the application to the attestation and monitoring back-end. The back-end then checks the information, confirms that the integrity of the application has not been corrupted and, if needed, mitigates any detected threat which has not yet been resolved by the [mobile app](https://www.financedigest.com/the-growth-of-mobile-fintech-and-the-impact-for-mobile-app-marketers.html "The growth of mobile fintech and the impact for mobile app marketers").

Other software-based security mechanisms, which can protect SoftPOS solutions and often need to be implemented on a mobile app, include:

- Anti-Tampering
- Anti-Rooting
- Anti-Instrumentation
- Anti-Emulation
- Anti-Debugging
- Device-Binding
- Obfuscation
- White-box Cryptography

Developers do not need to start from scratch to implement these measures. Most of these security features are available from software protection [technology providers](https://www.financedigest.com/verasity-joins-the-brightcove-marketplace-to-provide-customers-with-proprietary-ad-tech-technology.html "Verasity Joins the Brightcove Marketplace to Provide Customers With Proprietary Ad-Tech Technology"). In particular, it is advised that [solution providers source their White-box Cryptography solution from a commercial](https://www.financedigest.com/the-professionals-at-real-estate-funding-solutions-helping-you-find-success-with-commercial-real-estate-loans.html "The Professionals At Real Estate Funding Solutions Helping You Find Success With Commercial Real Estate Loans") vendor. This is because such a [solution is tricky to develop in an efficient](https://www.financedigest.com/scanwriter-v-verafin-which-solution-can-help-you-unravel-financial-scams-efficiently.html "ScanWriter v. Verafin: Which Solution Can Help You Unravel Financial Scams Efficiently?") way to pass security evaluation. The good news is that a number of vendors already [offer solutions](https://www.financedigest.com/convenience-offered-by-home-automation-solutions-to-offer-opportunities-for-market-players-iot-has-encouraged-the-demand.html "Convenience Offered by Home Automation Solutions to Offer Opportunities for Market Players; IoT has Encouraged the Demand") which have passed the required security evaluation and are ready to be used.

**Two paths to certification success**

Any SoftPOS [security evaluation comprises of three steps:](https://www.financedigest.com/5-steps-to-strengthening-your-online-financial-security.html "5 Steps to Strengthening Your Online Financial Security") documentation and design review, source code review, and penetration testing. But not all solutions can take the exact same approach. When [evaluating the security of your SoftPOS solution](https://www.financedigest.com/asset-management-it-solution-market-asset-management-grow-crucial-for-various-organizations-to-evaluate-entire-business.html "Asset Management IT Solution Market – Asset Management Grow Crucial for Various Organizations to Evaluate Entire Business"), the path you take currently depends on whether the solution supports PIN entry.

- **Solutions with PIN entrymust undergo the [payment schemes’ pilot security](https://www.financedigest.com/allpay-signs-with-eckoh-to-secure-telephone-payments.html "allpay signs with Eckoh to secure telephone payments") programmes. These solutions must meet multiple detailed and stringent requirements to achieve certification. It can be challenging to evaluate these types of solutions, since PIN entry has to be entered on the [touch screen](https://www.financedigest.com/apple-may-add-touch-screens-to-mac-computers-bloomberg-news.html "Apple may add touch screens to Mac computers – Bloomberg News") of a device, which can be complex to secure.**

The [payment schemes’ pilot](https://www.financedigest.com/more-banks-join-european-instant-payments-pilot-from-end-2023.html "More banks join European instant payments pilot from end 2023") security programmes focus on the strength of security. This means that the evaluation looks to find vulnerabilities and performs penetration testing to assess the robustness of solutions against attackers. Throughout this process, the main component which is evaluated is the [mobile payment](https://www.financedigest.com/what-is-the-optimum-mobile-payment-mix.html "What is the optimum mobile payment mix?") acceptance application. The back-end is not assessed, but what is being checked is the communication between the back-end and the front-end.

- **Solutions without PIN entry** must be compliant with the PCI Contactless Payments on COTS (CPoC™) [specification in line with payment](https://www.financedigest.com/payment-community-engagement-in-the-development-of-the-emv-specifications-increases.html "Payment Community Engagement in the Development of the EMV Specifications Increases") scheme requirements. This comprises of a more formal compliance process, which requires an exhaustive [set of documents to be provided as evidence by solution providers and evaluated by a security](https://www.financedigest.com/u-s-russian-officials-set-for-security-talks-on-january-10-u-s-official.html "U.S., Russian officials set for security talks on January 10 – U.S. official") lab. Along with more documentation, the scope of the testing is more expansive. It evaluates the full solution, including both the back-end and front-end systems.

**Taking the** [next step](https://www.financedigest.com/eu-leaders-to-discuss-next-steps-on-energy-ukraine.html "EU leaders to discuss next steps on energy, Ukraine")

It is expected that next [year PCI SSC will issue a new standard called mPoC™ for mobile Payments](https://www.financedigest.com/2019-year-customers-take-control-payments.html "2019: The year customers take control of payments") on COTS, which will evaluate SoftPOS solutions with PIN entry. This new standard will also enable SoftPOS solution components (for example, Software Development Kits (SDK), PIN entry solutions and back-end systems) to be certified separately first and then in combination. This will provide a much more standardised approach to SoftPOS security evaluation and [ensure that the full scope of these solutions is tested](https://www.financedigest.com/ensuring-traders-pass-the-test-of-mifid-ii-and-mar.html "Ensuring traders pass the test of MiFID II and MAR"), rather than just the front-end.

Since solutions supporting PIN entry are most commonplace nowadays, those wanting to bring SoftPOS solutions to market [know that they must undergo the payment](https://www.financedigest.com/the-end-of-payments-as-we-know-it.html "The end of payments as we know it") schemes’ pilot security programmes now, and then perform the new mPoC process in the future. While this is frustrating, with the growing momentum in SoftPOS solutions, they cannot afford to [wait for this standard to come in before launching](https://www.financedigest.com/britain-launches-plan-to-ease-doctor-waiting-lists.html "Britain launches plan to ease doctor waiting lists") their solutions. Switching to this new process will no doubt bring a new set of complexities.

Fortunately, you do not have to go through these processes alone and product [roadmaps can be set](https://www.financedigest.com/britain-sets-out-roadmap-for-self-driving-vehicle-usage-by-2025.html "Britain sets out roadmap for self driving vehicle usage by 2025") to take into account the forthcoming changes. Fime’s experts can provide wide-ranging and global expertise to support the development, delivery and security evaluation of successful SoftPOS solutions. Whether it is delivering training sessions, writing the required evaluation documents or supporting you in developing solutions in line with the relevant security standards, we can help.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

