Five MPoC requirements demand a minimum 25-point attack rating, scored independently by a third-party laboratory. In each one, Digital.ai technology is the control your lab examines.

MPoC lets merchants accept card payments, including PIN entry, on their own phones, with no terminal fleet to buy, certify, or service. The catch: everything a certified terminal does in hardware now has to be proven in software, on a device the standard assumes an attacker fully controls.

AI raises the bar. PCI's July 2026 Technical FAQs require labs to account for AI-assisted reverse engineering when they score an attack. Points earned from attacker effort shrink as tools improve. Points earned by forcing attackers to extract keys device by device don't.

This paper maps Digital.ai App Hardening and White-Box Cryptography to MPoC v1.1: which requirements we address, which we support, and which remain yours to build.

Inside the whitepaper:

  • The five 25-point requirements: the Digital.ai control your lab examines in each, and the two that apply only in certain architectures.
  • How to earn the scalability points: the per-installation key architecture behind the largest single scoring factor, worth nearly half the 25-point threshold.
  • What Digital.ai doesn't do: the A&M, liveness, and iOS gaps teams most often assume are handled for them, plus a 14-item integration checklist.
  • A full responsibility matrix: how all 192 requirements divide. Digital.ai is the primary control for about 17%, supplies supporting evidence for about 11%, and the remaining 72% is yours or another participant's.

Get the Whitepaper Now

Please wait, you may need to disable your adblocker or adjust privacy settings to view content

Want To Keep Exploring Other Resources?