PCI Compliance POS Hardware: What Merchants and ISVs Need to Know

Published by

on

sunmi-t3-pro-specialty-food-retail-checkout

PCI compliance POS hardware is not a marketing line. It is a certification chain that starts at the payment terminal, runs through the payment kernel, and ends at the acquirer contract. For merchants and independent software vendors, buying uncertified POS hardware, or losing the certification through gray-market sourcing, is one of the fastest ways to inherit a compliance problem that shows up during audit or after a chargeback.

This guide covers what PCI compliance actually requires from a POS terminal, which certifications matter, and which SUNMI POS hardware ships PCI-certified in North America. Rosper is the authorized SUNMI distributor and preserves the certification chain from ship to fleet activation.

Key Takeaways

  • PCI compliance for POS hardware turns on three certifications, PCI PTS for the device, EMVCo Level 1 and 2 for the payment kernel, and PCI DSS for the merchant environment.
  • PCI PTS 6.x is the current active version and the target for any new POS hardware in 2026.
  • Gray-market POS hardware voids the certification chain and the SUNMI warranty in one move.
  • SUNMI CPad Pay, D3 Pro guest display, Flex 3, V3 PLUS Scanner, and P3H ship with the current PCI PTS and EMVCo certifications for North America.
  • Semi-integrated payment isolates the ISV app from card data and reduces PCI DSS scope significantly.

What PCI Compliance POS Hardware Actually Covers

PCI compliance is not one certification. It is a stack. At the top sits the merchant obligation to protect cardholder data under PCI DSS, published by the PCI Security Standards Council. Below that sits the certification of the payment terminal itself, PCI PTS, which validates the physical device against tamper resistance and secure key management. Below the terminal certification sits the payment kernel certification, EMVCo Level 1 and Level 2, which validates the software that processes the card.

All three layers have to align. A merchant on PCI DSS cannot use a POS terminal that fails PCI PTS. A payment terminal that is PCI PTS-certified but lacks an EMVCo-certified kernel cannot process a chip transaction. And a certified terminal that has been sourced through gray-market channels can silently fall off the certification list, because the acquirer validates against the current PTS device listing rather than the printed sticker on the box.

For an ISV, this stack has a further implication. If the ISV app handles card data directly, the ISV inherits a much larger PCI DSS scope than an ISV that runs a semi-integrated payment flow where the card data stays inside the certified kernel. Semi-integrated payment is the standard North American ISV design pattern.

PCI PTS 6.x and Why the Version Matters

PCI PTS versions move forward. PCI PTS 6.x is the current active target for any new POS terminal purchase in 2026. Older versions can remain in-market on legacy hardware for a defined support window, but new deployments should qualify on 6.x to avoid a forced hardware refresh mid-lifecycle. The PCI SSC document library lists the active version and the sunset schedule for prior versions.

Two SUNMI devices carry PCI PTS 6.x certification in the North American lineup, the CPad Pay 11 and the P3H. Both are payment-first devices. CPad Pay 11 is the certified tablet path for ISV checkout and assisted retail, and the P3H is the certified handheld path for mobile payment collection.

Buying a certified device inside the authorized distribution channel preserves the version on the current PTS listing. Buying outside the channel introduces risk that the acquirer flags the device as unlisted, which typically halts card acceptance on the fleet until a listed device is deployed. The compliance path is not recoverable after the fact without hardware replacement.

EMVCo Level 1 and Level 2 Kernel Certification

EMVCo Level 1 covers the electrical and physical characteristics of the payment interface. On a contactless deployment, Level 1 covers the antenna and RF stack, and the certification path is called PCD Level 1. On a contact deployment, Level 1 covers the chip interface. The EMVCo specification library defines the exact scope.

EMVCo Level 2 covers the payment kernel that runs on top of the certified hardware. It is the software half of the certification. Every card network runs on a certified kernel, and the acquirer typically provides the kernel that a certified device runs. On SUNMI hardware, the semi-integrated SUNMI Unified Payment SDK bridges the ISV app to the certified kernel without expanding PCI scope.

Merchants and ISVs should confirm three items on any device SKU. First, PCI PTS 6.x on the device. Second, EMVCo PCD Level 1 on the contactless antenna, or Level 1 on the chip interface. Third, an acquirer-approved kernel that will run on the device. Missing any one item invalidates the payment path.

SUNMI POS Hardware with Current PCI Certification

The current SUNMI North American lineup includes five payment-certified device families. Every model runs SUNMI OS 4.0 on Android and is available through Rosper as the authorized distributor.

DeviceCertificationsPayment roleBest for
CPad Pay 11 (P07180008 / P07180026)PCI PTS 6.x, EMVCo PCD L1Semi-integrated SoftPOS, Future X RKI on 026ISV checkout, assisted retail, salon and spa
P3H (P07160012 / P07160025)PCI PTS, NFC plus MSR plus IC certifiedFull three-way payment handheldField service billing, mobile invoice collection
D3 Pro Guest Display (C20000099)Tap on Glass NFC certifiedCustomer-facing tap on Glass acceptanceQSR, fast casual, retail counter
Flex 3 (P11050001 series)EMVCo PCD L1, under-glass NFCSoftPOS on self-service surfaceSelf-service kiosk, unattended checkout
V3 PLUS Scanner (P06120021)EMVCo PCD L1, Apple VASSoftPOS on handheldDelivery, curbside, mobile box office

For ISVs building a semi-integrated payment product the anchor SKU is CPad Pay 11 for the tablet role and P3H for the handheld role. Both preserve the payment kernel outside the ISV app scope and hand back a tokenized status for downstream processing. To confirm which acquirer kernels are pre-loaded on a shipment, request a quote.

Semi-Integrated Payment and PCI DSS Scope

Semi-integrated payment is the fastest way to reduce PCI DSS scope for an ISV product. In this pattern the certified payment kernel on the device handles the card entry, tokenization, and network settlement, and returns only a transaction status to the ISV app. The ISV app never touches card data, which pulls it out of a large section of PCI DSS controls.

The alternative, fully integrated payment, expands scope significantly. The ISV app touches card data, so it inherits controls around encryption at rest, network segmentation, and secure development lifecycle. For a startup ISV that is a heavy cost. For a mature ISV with dedicated security staff it can be justified. Almost every ISV shipping in North America picks semi-integrated for the smaller audit surface.

PCI Compliance POS Hardware Deployment Checklist

  • Confirm PCI PTS 6.x on every payment device in the bundle.
  • Confirm EMVCo PCD Level 1 on contactless devices, and Level 1 contact certification on chip devices.
  • Match the payment kernel to an acquirer-approved list on the device SKU.
  • Pick semi-integrated payment over fully integrated for a smaller ISV PCI DSS scope.
  • Buy only through the authorized SUNMI distributor to preserve certification and the PTS listing.
  • Confirm US and Canada stock and lead time before committing rollout dates.

Source PCI-Certified POS Hardware from Rosper

Rosper is the authorized SUNMI distributor for North America. We stock the SUNMI CPad Pay 11, P3H, D3 Pro guest display, Flex 3, and V3 PLUS Scanner across 8 US warehouses plus a Canadian hub, coordinate the SUNMI warranty and RMA process locally, and support ISVs and reseller partners with SDK integration and acquirer key injection. Most orders arrive in 2 to 7 business days. To scope a PCI-compliant POS fleet, contact us and we will match SUNMI SKUs to your acquirer and merchant environment.

Frequently Asked Questions

What PCI certifications does a POS terminal need?

A POS terminal needs three aligned certifications. PCI PTS 6.x certifies the physical device and its key management. EMVCo Level 1 certifies the payment interface, PCD Level 1 for contactless and Level 1 for chip contact. EMVCo Level 2 certifies the payment kernel software. All three must align at the acquirer, and PCI DSS covers the merchant environment on top.

Is PCI PTS 6.x the current version in 2026?

Yes, PCI PTS 6.x is the current active target for any new POS terminal in 2026. Older PCI PTS versions may still support legacy hardware in-market on defined support windows, but new fleet purchases should qualify on 6.x to avoid a forced mid-lifecycle refresh. The PCI Security Standards Council maintains the active version and sunset schedule.

Which SUNMI POS terminals are PCI-certified for North America?

The current PCI-certified SUNMI lineup includes CPad Pay 11 (P07180008 and P07180026) with PCI PTS 6.x, the P3H handheld (P07160012 series) with a full three-way payment kernel, the D3 Pro guest display (C20000099) with Tap on Glass, the Flex 3 interactive surface with EMVCo PCD L1 under-glass NFC, and the V3 PLUS Scanner (P06120021) with EMVCo PCD L1 handheld NFC.

Does buying gray-market POS hardware void PCI certification?

In practice yes. Gray-market hardware often falls off the PCI PTS active device listing because it lacks the current certified firmware build or the authorized acquirer kernel. Acquirers validate against the PTS listing rather than a printed label, so an unlisted device can halt card acceptance on activation. Gray-market sourcing also voids the SUNMI warranty.

Does semi-integrated payment reduce PCI DSS scope?

Yes. Semi-integrated payment isolates card data on the certified payment kernel. The ISV app receives a tokenized transaction status, not the card data itself, which removes it from a large section of PCI DSS controls including encryption at rest and network segmentation for cardholder data. It is the standard North American ISV design pattern for that reason.

For the certification detail behind PCI compliance POS hardware, see our PCI PTS 6.x on SUNMI payment devices.

Related reading: PCI PTS certified Android payment terminals.