SISA Joins Global Group of PCI Recognized Labs to Perform Security Evaluations of Payment Acceptance Devices and Solutions

Bangalore, India – March 12, 2026 : The PCI Security Standards Council (PCI SSC) and SISA have announced today that SISA is now a PCI recognized laboratory approved to conduct security evaluations of payment acceptance devices and solutions.

PCI recognized laboratories are recognized by PCI SSC to perform security evaluations of payment acceptance devices using the PCI PTS Standards (Hardware Security Module (HSM) and Point of Interaction (POI)). Some are additionally recognized to perform evaluations using the PCI Mobile Payments on COTS (MPoC) Standard, PCI Software-based PIN-entry on COTS (SPoC) Standard, PCI Contactless Payments on COTS (CPoC) Standard and/or PCI 3DS Software Development Kits (SDK) Standard for payment solutions.

SISA now joins a select group of labs globally that test and validate that payment devices and solutions meet the requirements for protecting cardholder data. With this recognition, SISA becomes India’s first PCI-recognized laboratory authorized to perform full security evaluations under the PCI Mobile Payments on COTS (MPoC) Standard. This recognition enables SISA to support SoftPOS and mobile payment solution providers in achieving formal security validation and listing of their MPoC-enabled payment applications operating on Commercial Off-The-Shelf (COTS) smartphones and tablets. As Tap-to-Phone and mobile-based payment acceptance continue to grow globally, SISA’s MPoC evaluation capabilities will help organizations ensure that mobile payment solutions meet the rigorous security controls required to protect sensitive cardholder data and maintain trust across the payment ecosystem.

In addition to its MPoC evaluation capabilities, SISA is listed by the PCI Security Standards Council across several key PCI programs, including as Qualified Security Assessors to the PCI DSS Standard, PCI Secure Software Standard Assessors, PCI Secure Software Lifecycle Assessors, Qualified PIN Assessors, PCI Forensic Investigators (PFI), PCI 3DS Assessors, and PCI Point-to-Point Encryption (P2PE) Assessors. These recognitions enable SISA to support payment ecosystem stakeholders with services spanning compliance validation, secure software development practices, payment breach investigation, and protection of PIN processing environments.

“I am pleased to welcome SISA to this group of globally recognized labs,” said PCI SSC Head of Product and Technology Deanne Zettler. “The Council is committed to delivering the highest quality in its laboratory programs, and we are confident that SISA will help us continue delivering robust security testing for payment devices and solutions.”

Speaking on the recognition, Founder & CEO, SISA, Dharshan Shanthamurthy, said, “As mobile phones rapidly evolve into merchant acceptance terminals, the definition of trust in payments must evolve with them. With SISA becoming India’s first PCI-recognized laboratory authorized to conduct MPoC security evaluations, we are proud to support the global payments ecosystem in securing the next generation of mobile payment acceptance. Our focus is not just on enabling certification, but on helping solution providers build resilient architectures that embed device integrity, transaction assurance, and security by design into Tap-to-Phone and SoftPOS environments.”

PCI recognized laboratories are listed on the PCI SSC website.

PCI SSC lists a variety of approved devices and payment solutions for use at the point of sale to protect cardholder data.

About the PCI Security Standards Council 

The PCI Security Standards Council (PCI SSC) leads a global, cross-industry effort to increase payment security by providing industry-driven, flexible and effective data security standards and programs that help businesses detect, mitigate and prevent cyberattacks and breaches. Connect with the PCI SSC on LinkedIn. Join the conversation on X (formerly Twitter) @PCISSC. Subscribe to the PCI Perspectives Blog. Listen to the Coffee with the Council podcast. 

About SISA

SISA is a global leader in cybersecurity for the payment ecosystem, operating at the intersection of AI, cybersecurity, and payments. Trusted by leading brands and financial institutions across 40+ countries, SISA secures over 1,000 organizations, helping them anticipate threats, strengthen resilience, and protect critical payment infrastructure. Powered by real-world breach intelligence and deep expertise in payment security, compliance, and forensic investigations, SISA enables organizations to stay ahead of evolving cyber risks. Follow SISA on LinkedIn for the latest insights on cybersecurity, payment security innovation, and emerging technologies. Visit www.sisainfosec.com

 

SISA’s Latest
close slider