Card payments on your phone: how tap to pay really works

Your phone becomes a card machine the moment a payment app is allowed to use its NFC aerial. This page follows a sale from the tap to the money landing, sets out what the security standard actually checks, which handsets qualify and where the whole thing falls over. What each provider charges is on the costs page.

Editorial: SoftPOS24 Payment ResearchUpdated: 15.08.2026Data set: 121 providers, 14 criteria
Definition

SoftPOS — sold in the UK as Tap to Pay on iPhone or tap to pay on Android — is an app that turns the NFC aerial already in your phone into a contactless card reader. The customer holds a card, phone or watch against the back of your handset and the answer comes back in seconds. There is no card machine to buy, rent or charge up. In return you take contactless only, you live off your own battery and signal, and your handset has to be on the supported list.

What happens when the customer taps

You key the amount into the app and the phone switches on its NFC aerial — the same aerial you already use for Apple Pay or Google Pay, only working the other way round. The customer holds their card, phone or watch a couple of centimetres from the back of your handset.

The card does not hand over its number in plain text. It returns a package containing a dynamic cryptogram, worked out on the spot and valid for that one sale. Copy the package and it is worthless. If the customer pays with Apple Pay or Google Pay the real card number never appears at all: their phone sends a token, a stand-in number tied to that device.

Your app packs up what it received and sends it to your payment provider, which takes the authorisation to Visa or Mastercard and on to the customer's bank. Approved or declined usually comes back in two or three seconds.

Above the contactless limit, or when the customer's bank asks for it at random, a PIN pad appears on your screen. That keypad runs in a walled-off part of the phone: the rest of the app cannot see the layout or the digits. It is the part of the system the security standard scrutinises hardest.

So the division of labour is: your phone is the reader and the screen, the security sits in the card and on the provider's servers, and the card number is never stored on your handset.

Where this differs from the card machine you know

The obvious difference is that there is no box. Nothing to buy or rent, no separate charger, no till roll to reorder, no engineer visit. You download the app, get through the checks and start selling — often the same day.

The difference that only shows up later is how the card is read. A card machine takes three things: contactless, chip and PIN with the card inserted, and on older models the magnetic stripe. A phone takes contactless only. A customer whose card has no contactless symbol simply cannot pay you. That is rare in the UK now, but it still happens with some older business cards, a few prepaid and benefit cards and cards issued abroad.

Then come the awkward ones. The battery is the same battery you use for everything else. The receipt is digital unless you buy a printer. And it is your personal phone that gets handed towards strangers twenty times a day.

There is also the supported-handset question, which a dedicated card machine does not have: the box is approved at the factory, your phone has to earn its place on a list.

The table below puts the two side by side. Which providers offer which model in the UK is set out in the full comparison.

Security: what PCI MPoC actually certifies

PCI MPoC stands for Mobile Payments on COTS — payments on a commercial off-the-shelf phone. It is the security standard of the PCI Security Standards Council, the same body behind PCI DSS, and it is the standard that governs this kind of solution. Version 1.1 was published on 26 November 2024.

MPoC pulled together two things that used to be assessed separately: CPoC, which covered contactless reading, and SPoC, which covered typing a PIN on the screen. You will still see both acronyms in older provider material.

The standard does not just look at the app. It assesses the app, the back-end servers that watch every handset in real time, and the processes of the company that keeps all of it running. If a phone is rooted or jailbroken, has developer mode switched on, or starts behaving oddly, the system is expected to stop taking payments on its own. Validation is done by an accredited laboratory and approved solutions are listed publicly on the PCI SSC website.

Two honest caveats. First, the name on the listing is usually the technology supplier, not the brand you signed up with — your app can be covered without its own name appearing. Second, disclosure is patchy: of the 33 providers with a UK offer in our database, 10 publish a certification of this kind. Silence is not proof of anything either way, so ask in writing.

Which phones can actually do it

iPhone. The feature is called Tap to Pay on iPhone and Apple launched it in the UK on 13 July 2023, with Revolut and Tyl by NatWest first out of the gate. It needs an iPhone XS or later running the latest iOS. It accepts contactless Visa, Mastercard and American Express cards, Apple Pay and other wallets. Apple now lists roughly eighteen payment platforms for the UK, among them Adyen, Dojo, Global Payments, Mollie, myPOS, PayPal, Rapyd, Revolut, Square, Stripe, SumUp, Teya, Trust Payments, Tyl by NatWest and Viva.com. The constraint is rarely the handset — it is whether your provider has switched the feature on.

Android. You need NFC with HCE (Host Card Emulation) and a minimum OS version that differs from provider to provider; we have seen Android 8.0 demanded by one app and Android 10 by another. Rooted devices and phones with developer options enabled are normally refused outright.

On top of that sits the supported-device list. Many providers only enable the feature on models they have tested, because the position of the NFC aerial varies wildly between manufacturers. Grey imports, regional variants and obscure brands often miss out despite having NFC.

Before you sign anything — and certainly before you buy a phone for this — install the app, register and try a £1.00 sale. The app tells you straight away whether the handset qualifies. A phone with no NFC aerial will never work, and no update will change that.

What it costs, and what the price list leaves out

The pricing itself is taken apart on the costs page — transaction rates, monthly fees, payout timing, contract length and the charges nobody advertises. We are not going to repeat it here. What belongs on this page are the costs that appear on no price list at all, because nobody invoices you for them.

The first is the phone. It stops being a phone and becomes trading equipment: it gets dropped, rained on, nicked, or its screen goes on the busiest Saturday of the year. If it dies, your takings die with it — unlike a broken card machine, where the phone is still in your pocket to ring someone.

The second is mobile data. Every sale needs a connection and almost no app authorises offline. At a pitch with one bar of signal that is a takings problem, not a technology problem.

The third is battery, now shared between selling, taking bookings and everything else you do on that handset. A busy market day and a payment app running all afternoon do not go together without a power bank.

The fourth is the cost of moving. If your model drops off the supported list after an update, or a new provider demands a newer OS, you have an unplanned expense that was in nobody's advert.

The British particularity: the contactless limit is no longer fixed

In most markets a contactless limit is a number the card schemes set and everyone forgets about. In the UK it was written into financial regulation, and in 2026 it stopped being.

The old rule sat in Article 11 of the FCA's Technical Standards on Strong Customer Authentication. In PS21/2 the FCA raised the thresholds to £100.00 for a single contactless payment and £300.00 cumulatively before the customer has to authenticate — that is why a card sometimes asks for a PIN on a £4.00 coffee. It is not your app being awkward; the customer's bank has hit the running total.

On 19 March 2026 the FCA instrument FCA 2025/62 removed those fixed figures and replaced them with a risk-based exemption. Banks and card issuers with strong fraud controls may now set their own contactless limits, or none. The FCA was explicit that this is permissive, not compulsory: it is up to each firm whether and when to change anything.

What that means at your counter is unglamorous. You cannot set the limit and neither can your provider — the customer's bank does. Two customers at the same stall can now hit different ceilings, and the ceiling can change without warning. So do not promise a customer that £150.00 will go through contactless, and make sure the on-screen PIN entry works on your handset before you rely on it. On a phone that PIN pad is the only fallback you have: there is no slot to put the card in.

Where the technology runs out of road

Battery. A card machine that runs flat costs you a card machine. A phone that runs flat costs you the till, the calculator, the bookings diary and the phone. Carry a power bank; treat it as equipment, not an accessory.

Contactless only. There is no slot and no stripe. If a card will not tap, the sale does not happen. Keep a fallback — a payment link, a bank transfer, or yes, cash.

Receipts. The receipt is an email, an SMS or a QR code. Customers who want paper — trade customers claiming VAT, anyone doing an expenses claim — will ask, and you will need a plan that is not "write it down". More on what you are actually obliged to give them on our rules page.

Unattended and multi-till use. These apps are built for one person holding one phone. Self-service, a fixed kiosk or three staff on one account is not what they are designed for, and some providers forbid it in their terms.

Signal. Almost nothing authorises offline. Basements, church halls, steel-framed marquees and rural pitches are where this shows up, and it shows up as a queue.

The handset itself. Your personal phone now passes within a few centimetres of every customer, all day. Lock screens, notifications and photos are suddenly a business decision.

Phone versus card machine, point by point

WhatPhone (SoftPOS)Card machineWhat it means for you
HardwareNone — you already own itBought or rented, often on contractNo upfront outlay, but your phone becomes trading equipment
Card entryContactless onlyContactless, chip and PIN, sometimes stripeA non-contactless card cannot pay you at all
PIN entryOn your own screen, in a walled-off keypadOn the machine's own keypadTest it before you rely on it — it is your only fallback
ReceiptEmail, SMS or QR codePrinted roll, plus digital on newer modelsNo paper unless you add a printer
Power and signalYour phone's battery and dataOwn battery, often own SIM or baseOne flat phone stops trading altogether
ContractUsually app-based, no minimum termFrequently 12 to 48 months with exit feesCheck the term and the exit fee before you sign anything

Compare all 33 providers →

Common questions

Do I need a special phone?

For iPhone you need an iPhone XS or later on the latest iOS. For Android you need NFC with HCE, a minimum OS version set by your provider, no root and developer options switched off. Many providers also keep a supported-device list, so a handset with NFC can still be refused. Install the app and try a £1.00 sale before you commit.

Can I take chip and PIN on a phone?

No. There is no slot. The phone reads contactless cards and wallets only. PIN entry does exist, but it happens on your screen after a contactless tap when the amount or the customer's bank demands authentication. If a card will not tap, you need another way to be paid.

Is it as secure as a card machine?

The card number is never stored on your handset, the card returns a one-time cryptogram, and wallet payments send a token rather than a real number. Solutions built to PCI MPoC are also monitored server-side and are expected to shut themselves down on a compromised phone. The weak point is usually the handset's own security, not the payment path.

What is PCI MPoC in one sentence?

It is the PCI Security Standards Council's standard for taking card payments on an ordinary phone, published in version 1.1 on 26 November 2024, replacing the older CPoC and SPoC standards. Approved solutions are listed publicly by the PCI SSC — though the listing usually names the technology supplier rather than the brand you signed up with.

Why did a customer's card ask for a PIN on a small sale?

Because their bank hit a running total, not because of anything you did. UK contactless used to be capped at £100.00 per payment and £300.00 cumulatively before authentication. Since 19 March 2026 issuers may set their own limits, so two customers can hit different ceilings at the same stall.

Is there a monthly fee?

Most UK apps in our database charge nothing monthly and take a percentage per sale instead; a few bundle the app into a paid business account. Fifteen of the 33 providers serving this market publish no price at all. The figures, the worked examples and the break-even point are all on the costs page.

What if my provider ties me into a contract?

App-based providers usually do not, but card machine deals frequently run 12 to 48 months with an early termination fee, and that is the classic UK trap. Read the minimum term, the notice period and the exit fee before signing. If it goes wrong, a business with with turnover under £6,500,000 can usually take a complaint to the Financial Ombudsman Service.