Commercial Off-the-Shelf (COTS)
PCIComplianceHubLast updated
Products sold as stock items, not built or customised for a particular customer, and ready to use as supplied. In PCI DSS the term appears mainly around mobile payments, where a COTS device is an ordinary consumer smartphone or tablet used to accept payments.
Applies to. Software acquisition generally, and specifically merchants accepting payments on consumer phones and tablets through a solution on the Council's SPoC, CPoC or MPoC lists.
Example. A retailer takes contactless payments on staff members' ordinary phones through a listed MPoC solution. The phone is the COTS device; the solution, not the phone, is what the Council validated.
Limits. A COTS device is by definition not under the merchant's hardening control the way a PTS-approved terminal is, which is why the Council's mobile programmes exist at all: they validate the software and back-end monitoring around the device. Buying COTS software does not remove the entity's obligations under 6.3 to track its vulnerabilities and patch it.