Near Field Communication
Near Field Communication (NFC) is a short-range wireless technology that lets two devices, such as a phone and a payment terminal, communicate when held very close together, typically within a few centimeters. It is commonly used for contactless payments where a customer taps or holds a card or device near a reader. NFC is based on radio-frequency identification (RFID) technology and requires close proximity, which limits communication to devices that are near one another.
NFC is a set of contactless, close-proximity radio communication protocols derived from RFID technology, operating at a base frequency of 13.56 MHz with a typical effective range on the order of a few centimeters (commonly cited around 4 cm). It enables data exchange between two electronic devices, or between a device and a passive NFC tag, over short distances. In payment acceptance, NFC provides the physical and link-layer transport for contactless card-present transactions between a consumer device or card and a reader; the underlying transaction security, cryptographic authentication, and data handling are governed by separate specifications (for example EMV contactless and applicable PCI standards) rather than by NFC itself. NFC as a transport does not by itself define how cardholder data or sensitive authentication data are protected, so applicable data-protection and storage controls must be evaluated against the relevant standards and their current published requirements.
Why it matters
NFC is the transport layer behind the tap-to-pay experience that has become common at physical points of sale, whether a customer presents a contactless card or a phone or wearable. Because it functions only over very short distances, typically on the order of a few centimeters, it requires deliberate proximity between the consumer device and the reader. This close-range constraint is a property of the radio technology itself, not a comprehensive security control, and it should not be confused with the cryptographic and data-protection measures that actually secure a payment.
For security and compliance teams, the key point is that NFC only provides the physical and link-layer means for two devices to communicate. The security of a contactless card-present transaction depends on separate specifications layered on top of NFC, such as EMV contactless for cryptographic authentication and the applicable PCI standards for how cardholder data and sensitive authentication data are handled. Treating NFC as inherently secure because taps happen at close range can lead teams to overlook where the real protections must be evaluated and validated.
Because NFC as a transport does not by itself define how cardholder data or sensitive authentication data are protected, applicable data-protection and storage controls must be assessed against the relevant standards and their current published requirements rather than assumed from the use of contactless acceptance. This matters when scoping an acceptance environment, since the presence of NFC alone tells you little about whether a given implementation reduces or affects PCI DSS scope.
Who it's relevant to
Inside NFC
Common questions
Answers to the questions practitioners most commonly ask about NFC.