MPoC SoftPOS Strategy: SaaS vs. Hybrid vs. In-House
In this article you will find information about the ways of having and going live with the MPoC Softpos product.
MPoC SoftPOS Strategy: SaaS vs. Hybrid vs. In-House

In this article you will find information about the ways of having and going live with the MPoC Softpos product.
For a company to have an MPoC product, there are multiple certifications required to be accomplished. Because of the complexity and the cost of certifications, and the long certification and development timeline, some companies prefer to buy it in a SaaS model from the companies which are providing end-to-end payment service compliant with MPoC Softpos. But obviously the biggest disadvantage of this approach is the fees paid for each transaction and the dependency and limitations to the third party when you have your own custom requirements.
Alternative to the SaaS model, for the companies that prefer to develop it in-house: L2 Kernel certification is the starting point of the Softpos roadmap. It is basically the engine between the card and terminal, covering all EMV functions defined in the card scheme books and EMVCo Contact and Contactless books. It is a very specific domain and requires specialized resources and tools. A company should consider the following steps to develop its own L2 Kernels, which eventually are going to be used in their MPoC Solution:
- L2 Kernel development
- L2 Kernel Test Tools
- Type approval in the Lab
After L2 Kernel certifications are completed, the second step is to complete MPoC Security Evaluation with the labs accredited by PCI.
In the MPoC Security Evaluation, there are 5 major domains with different sets of requirements. A company aiming to have MPoC Softpos should comply with all these domains to get listed in the PCI as an MPoC Software/Solution provider.
- Domain 1: Core cryptography and security
- Domain 2: MPoC SDK Integration
- Domain 3: Attestation & Monitoring
- Domain 4: MPoC Software Management
- Domain 5: MPoC Solution (Merchant Management)
Because of the different domains and complication levels, in the MPoC administrative documents PCI provides some flexibility to the vendors who are getting MPoC Security Evaluation.
Certification Paths
- Single Certification Path (Monolithic Certification): Covers all domains in one certification.
- 2-phased certification Path (MPoC Software + MPoC Solution): MPoC Software mainly covers the most complicated Domain 1, and MPoC Solution mainly covers Domain 2, which is more related with the MPoC SDK Integration.

The first path (option) is to develop and have certification in one shot with all domains. This one is called MPoC Monolithic certification. Once it is completed, the company can start its L3 certification and go live.
The second path (option) is buying MPoC Software from a third party (there are vendors already listed on the PCI website, which already went through the MPoC Software Security Evaluation and are approved) and developing MPoC Solution on top of it. This is a cost- and time-saving path, as MPoC Software covers the most complicated MPoC requirements defined under Domain 1. And as MPoC Software also contains certified L2 Kernels already in it, in the MPoC Solutions Certification the company only needs to complete MPoC App development according to Domain 2, and either develop A&M or supply it also from a third party. You get MPoC Software from the vendor and develop your own MPoC App (UI) on top of it. In brief, to shorten the certification cost and timeline, MPoC Software can be supplied from a vendor and MPoC Solutions certification can be done with the lab by just performing the remaining requirements in the MPoC Specification.
After outlining the main MPoC certifications and process steps to launch a SoftPOS product, there are three approaches that most companies use in their SoftPOS development roadmaps.
- SaaS
- Hybrid → This is the path usually managed with MPoC Software + MPoC Solution Security Evaluation path explained above.
- All In-House → This is the path usually managed with MPoC Monolithic Security Evaluation path explained above.
SaaS (3rd-party vendor) You plug into a provider that already operates a certified MPoC platform, so they run the stack and handle updates. You can launch quickly with little upfront spend, but you’ll pay ongoing usage fees and have dependent on Vendor`s roadmap for the new features.
Hybrid (3rd-party MPoC Software + your MPoC Solution) You license a certified MPoC software/SDK (including L2) and build your own solution layer. This splits responsibilities: the vendor keeps software certification current while you certify only your solution, giving you solid control over UX and data with mainly license/maintenance costs.
All in-house (MPoC Monolithic ) You build and certify everything; kernels, MPoC software, and the solution inside your organization. It’s the longest and most expensive route (certification alone can be around couple hundred thousand dollars excluding the development cost), but you gain complete ownership of technology, data, and roadmap, and you’re responsible for every future update and scheme change.
As a CNYTE Tecnologies which all modules are developed in-house CYNTE has best flexibility while providing any suitable options to you, it can be just L2 Kernel module or complete MPoC Solution.
SaaS (3rd-party Vendor)
- Time to market: Fast (few months)
- Up-front cost: Lowest
- Ongoing cost: Highest — per transaction, device fee etc.
- Ownership & control: Low (integrate via APIs)
- Certifications: Low — L2 Kernel and MPoC Security Evaluation Certifications are management by Vendor
- Customization & roadmap: Limited — dependent on vendor’s roadmap
- Vendor dependency: High
- In-house expertise required: Low
- Maintenance & Delta evaluations: Vendor handles everything
- Data ownership & analytics: Limited
- Typical risks: SLA/roadmap misalignment, fee escalations
- Best for: Pilots, fast launches, resource constraints
Hybrid (3rd-party MPoC Software + Your Solution)
- Time to market: Moderate (6 months +)
- Up-front cost: Moderate — savings from L2 Kernel, RASP, PIN, Domain 1 development & certification costs
- Ongoing cost: Moderate — License/maintenance fee for MPoC Software, but no per transaction fees
- Ownership & control: Medium
- Certifications: Medium — vendor manages L2 & MPoC SW; you manage MPoC Solution
- Customization & roadmap: Moderate — some vendor dependency, flexible especially in MPoC App (UI)
- Vendor dependency: Medium
- In-house expertise required: Medium — integration, MPoC solution knowledge
- Maintenance & updates: Shared — you handle MPoC Solution, vendor handles SW/L2
- Data ownership & analytics: High — your backend, your data
- Typical risks: Integration overruns, dependency on SDK release timing
- Best for: Processors wanting control without rebuilding core modules
All in-house (Monolithic)
- Time to market: Long (24 months +)
- Up-front cost: Highest — excluding development costs; certification fees
- Ongoing cost: Moderate — internal team maintenance costs
- Ownership & control: High — full ownership of L2 Kernels, MPoC Software & Solution
- Certifications: High — you manage all certifications
- Customization & roadmap: Maximum — build exactly what you need, when you need it
- Vendor dependency: Low
- In-house expertise required: Highest — EMV/L2, crypto, QA, labs etc.
- Maintenance & updates: You handle all deltas and scheme updates
- Data ownership & analytics: High — your backend, your data
- Typical risks: Long timelines, certification risk, talent hiring/retention
- Best for: Large processors seeking long-term cost control & full ownership

Notes:
- Even if the monolithic approach is selected, given the L2 kernel’s specialized resource needs and tooling/certification costs, it is more sensible to buy L2 kernel libraries from third parties.
- This article does not cover L3 certification; however, as with traditional terminals, SoftPOS solutions also require L3 after all other certifications are completed.
- After L2 kernels are certified, they must be re-certified every 3 years. After MPoC certification is completed, delta certifications are required annually, and full re-certification is required every 3 years.
- To develop MPoC Software or a Solution and become an MPoC vendor, PCI imposes strict requirements beyond the five domains mentioned above: the company must have a strong corporate structure and a mature software development lifecycle, validated by PCI SLC or compliant with MPoC Appendix A.
- In addition to the main methodologies mentioned in this article, there are other methodologies as well, such as acquiring MPoC Software from a third-party vendor and using that vendor’s A&M as a SaaS service.
About us: At CYNTE Technologies, all MPoC modules are developed in-house, so we offer flexible engagement; from a single L2 kernel module to a complete MPoC solution, aligned to your business plan.
메타데이터
- post_id
- 4eec10e47013
- slug
- mpoc-softpos-strategy-saas-vs-hybrid-vs-in-house-4eec10e47013
- url
- https://medium.com/@cynte/mpoc-softpos-strategy-saas-vs-hybrid-vs-in-house-4eec10e47013
- canonical_url
- https://medium.com/@cynte/mpoc-softpos-strategy-saas-vs-hybrid-vs-in-house-4eec10e47013
- author_url
- https://medium.com/@cynte
- status
- ok
- fetched_at
- 2026-08-16 19:24:42