Mobile Payments
Mobile payments are financial transactions made using a portable device such as a smartphone, tablet, or wearable instead of cash, a physical card, or a check. They let users pay for goods and services, or send money, digitally through the device. The term covers a range of payment processing services delivered through mobile technology.
Mobile payments refer to payment processing services that enable transactions to be initiated and completed through mobile devices such as smartphones, tablets, and wearables. Implementations vary widely and may include in-person acceptance, online payments, and person-to-person money transfer, often via mobile wallet applications. Because the term describes a delivery channel rather than a single technology or control, the applicable security requirements, cardholder data handling, and PCI DSS scope depend on the specific architecture used (for example, whether the device captures, transmits, or stores account data, and whether tokenization, encryption, or other controls are applied); readers should evaluate each implementation against the current published standards rather than assuming a uniform control set.
Why it matters
Mobile payments have become a mainstream way for consumers to pay for goods and services in person, online, and to send money to one another. Because the term describes a delivery channel rather than a single technology, it spans a wide range of implementations, each with its own security characteristics. This variability matters for security and compliance teams: the risks and controls that apply to a wearable tapping a contactless terminal differ from those of a mobile wallet application transmitting account data over the internet, or a person-to-person transfer app.
For payment security purposes, the critical question is not whether a transaction is labeled a mobile payment, but how the specific architecture handles account data. Whether the mobile device captures, transmits, or stores cardholder data, and whether tokenization, encryption, or other controls are applied, drives the applicable requirements and the PCI DSS scope. Two apps described identically to a consumer may sit in very different positions relative to sensitive authentication data handling and cardholder data protection obligations. Treating mobile payments as a uniform category can lead teams to under- or over-scope their compliance efforts.
Because implementations evolve quickly and vary across regions and platforms, organizations should evaluate each mobile payment deployment on its own terms against the current published standards rather than assuming a fixed control set. The label alone does not establish which data is present, where it flows, or which safeguards are validated.
Who it's relevant to
Inside Mobile Payments
Common questions
Answers to the questions practitioners most commonly ask about Mobile Payments.