Brightsight is now a recognised PCI SPoC evaluation lab

published on July 11, 2018

Delft, 11th of July 2018: As the world’s number one PCI PTS evaluation lab, we are happy to announce that Brightsight has been recognised by PCI SCC as an approved lab to perform Software-Based PIN Entry on COTS (SPoC) evaluations.

The new PCI SPoC standard paves the way for a completely new type of payment solution for versatile commercial off-the-shelf (COTS) devices, such as smartphones and tablets. It enables merchants to accept true EMV-based transactions, both contact and contactless, with the option of PIN entry on the associated smartphone or tablet. This makes it possible to accept high-value payments on cost-effective solutions, which are expected to be attractive to micro and small merchants.

In addition to the merchant’s mobile device, a SPoC solution requires a SRED-approved Secure Card Reader – PIN (SCRP) and a back-end system responsible for the overall solution security. The security of the PIN entry and processing on the COTS device must be secured with a dedicated, sophisticated PIN CVM application, while an inherent monitoring service should ensure that the functionality is only available if the authenticity, integrity and security status of the COTS device are ensured.

Contrary to the PTS POI program, which covers the approval of single components, the PCI SpoC program covers solution approval of all components of the solution. This includes the operational controls of the back office and processes to maintain the security of deployed implementations.

Brightsight has a proven track record of expertise in software-based security, helping our customers with mPOS, Host Card Emulation (HCE) and Trusted Execution Environment (TEE) solutions.

Dirk-Jan Out, CEO at Brightsight, says: “We are very happy to expand our service portfolio to support our customers towards a successful PCI SPoC approval. We will continue to expand our portfolio to maintain our position as the number one security lab in the world.”

 

If you are interested in more information, please feel free to get in touch with:

Rob van Marrewijk, Director Business Development: marrewijk@brightsight.com

For Greater China: Shu Gao, Director Business Development: gao@brightsight.com

News

Brightsight is now a recognised SBMP evaluation lab

published on 2018.11.22

News

My Kettle Hacked What?

published on 2018.11.21

News

Brightsight accredited as PCI 3DS SDK security evaluation lab

published on 2018.10.29

News

Utimaco achieves world’s first eIDAS certification for HSM

published on 2018.10.23

News