🎓 CoursesMarkets & internationalIntermediate⏱ 60 min
🏧
Rolling out in-store payment acceptance internationally. 7 chapters and a final quiz.
The day-to-day work of the team that opens stores in multiple countries, step by step. Build a country's acceptance sheet and settle the architecture before ordering hardware. Write the approval clauses of a terminal tender, including PCI PTS and MPoC. Configure contactless, diagnose a decline at the counter, and choose between a terminal and a phone. Integrate the register without redoing the project in every country, reconcile the batch upload with the incoming transfer, and manage the fleet and its after-sales service.
Build a country's acceptance sheet and derive the payment acceptance architecture from it, before buying any hardware
Write the approval clauses of a terminal tender: PCI PTS POI, EMV Levels 1 to 3, national approval, expiration dates
Configure contactless for the local regime and diagnose a decline at the counter with five checks
Choose between a certified terminal, SoftPOS under MPoC, and QR acceptance, one point of sale at a time
Chapter 1. Qualifying a country and settling the architecture.
A retailer entering a new country rarely orders the right terminal the first time. The problem is the order of decisions, not the technology. Hardware comes last. Before it come three questions whose answers sit with third parties: which instrument actually carries in-person payments, which intermediation layer is mandatory, and which local obligations apply to the terminal. This chapter produces one document, the country acceptance sheet: one page, eight rows, each with its source.
Question
Where to get the answer
What the answer locks in
Which instrument carries in-person payments?
The central bank’s annual payment systems report
The entire architecture. In India, the Reserve Bank of India counts 73.13 crore UPI QR codes, about 731 million acceptance points, while the terminal base shrinks (RBI, Payment Systems Report 2026)
Is there a domestic debit scheme?
Scheme operator, national banking association
The acquiring contract. girocard handled 8.3 billion transactions in Germany in 2025 (Deutsche Kreditwirtschaft / girocard.eu, 2026); ignoring it means turning away some cardholders at the counter
Is an intermediation layer mandatory?
National switch operator or authorization network operator
The choice of provider, not just its price. South Korea: VAN contract. Israel: Shva. Spain: Redsys. Mexico: Prosa or E-Global
Which radio technologies must the reader support?
Local schemes, transit operators, domestic aggregator
The hardware model and lead time. FeliCa in Japan; Octopus in Hong Kong, with more than 190,000 acceptance points (Octopus Cards Limited, 2026)
Which national approval must the terminal carry?
National scheme or switch operator
The critical path of the schedule. EMV Level 2 certification does not replace Ashrait in Israel, CB 6.0 in France (from Cartes Bancaires, the domestic scheme), or FeliCa approval in Japan
Does the terminal have tax obligations?
The country’s tax authority
A date, and therefore the opening schedule. Italy: pairing with the registratore telematico, the online cash register (Law No. 207/2024, Art. 1, paras. 74–77). Greece: the myAADE registry and IRIS (AADE)
Is a license required to operate a terminal fleet?
Central bank or payment system regulator
The legal structure of the rollout. In Nigeria, a PTSP (payment terminal service provider) license is required to deploy and maintain terminals (Central Bank of Nigeria)
Who is the leading local aggregator?
Registry of participants connected to the national rail
Actual coverage and settlement time. In QR-first markets, this partner matters more than the international scheme contract
The eight rows of a country acceptance sheet, to complete before any tender
Four architectures and how to choose between them
🏧
Certified terminal attached to the register
Fixed counter, high volume, need for the contact chip and magstripe fallback. A real hardware cost and a fleet to maintain, but complete checkout flows: voids, partial refunds, tips, split payments.
📱
SoftPOS on staff phones
Mobile sales, line busting, pop-up stores. Contactless only, under PCI MPoC, which shifts the cost from hardware to fleet management and OS versions.
🔳
QR acceptance through a local aggregator
Markets where QR carries in-person payments and an acceptance point costs as much as a sticker. The real work shifts to posting payments back to the register and to reconciliation.
🧩
A deliberately mixed architecture
Terminal at the counter, phone as backup, QR as a complement. This is the most common setup once a retailer operates in more than three countries, and it requires an abstraction layer on the register side, covered in chapter 5.
The order of decisions, where each step closes off options for the next
Country management
Builds the acceptance sheet
Eight rows, eight named sources. No row filled in by analogy with another country where the retailer operates
➜
Payments team
Settles the architecture
Terminal, phone, QR, or a mix. The decision follows from the first row of the sheet, not from the supplier's catalog
➜
Payments team
Selects the acquirer and the intermediation layer
Where a VAN, a national switch, or a gateway is mandatory, the list of candidates is already short
➜
Procurement
Launches the hardware tender
The required approvals are now known, country by country. That is chapter 2
➜
IT
Kicks off the register integration project
The register-terminal protocol depends on the market and the acquirer selected. It cannot be chosen before them
➜
Operations
Registers the fleet and sets up after-sales support
Key injection, regulatory pairing where required, buffer stock, replacement contract
⚠️
Reversing the order costs an entire store opening
The recurring mistake is to standardize one terminal model at group level, then roll it out country by country. Three walls then go up at once. The reader does not support the local radio technology. The national approval is missing and takes months to obtain, and the register protocol differs from the one used in the home country. All three obstacles surface together, a few weeks before opening, so the fix is to standardize an architecture at group level, never a product model.
🎯 Quick question
A European retailer is preparing to open 10 stores in South Korea. Which check must come before choosing a terminal?
Chapter 2. Writing the approval clauses of a tender.
A payment terminal is a cryptographic vault that must pass three separate approval gates, granted by three authorities on three timelines. The question you put to suppliers determines the quality of the answers. Asking whether the terminal is certified invites a yes that commits to nothing; the right wording names the standard, the country, and the date. A usable answer fits in a table, not a brochure.
Channel
Who grants it
Who owns it in the project
What it doesn't cover
PCI PTS POI, current version 7.0 (PCI SSC document library, accessed August 2026)
PCI Security Standards Council, through an accredited lab
The manufacturer, before market launch
Nothing about the dialogue with the acquirer or the checkout flows. An expired approval bars new deployments but not the use of the installed fleet
EMV Level 1 and Level 2
EMVCo, through accredited labs
The manufacturer
End-to-end behavior. The application kernel can be compliant yet misconfigured
EMV Level 3
The acquirer, under network rules
The acquirer or integrator, country by country
Nothing transfers from one acquirer to another. Switching acquirers restarts these tests
National approval
The scheme or switch operator (Shva, GIE Cartes Bancaires, NCCC, PayNet, etc.)
The manufacturer, with the local acquirer
No validity outside the country. It is the longest item on the hardware schedule
PCI MPoC, published in 2022, consolidating SPoC and CPoC (PCI SSC)
PCI Security Standards Council
The SoftPOS solution vendor
Commercial availability of the service in the target country, covered in chapter 4
Three approval gates: for each one, who opens it, who pays for it, and when it weighs on the schedule
Six requirements to spell out in writing
One row per model AND per country. A table with a single row per model hides exactly what you are looking for: the missing approval in the third market.
An expiration date for each approval, not a checked box. The date sets the ordering window, and therefore the fleet renewal schedule.
The PCI PTS POI approval number, verifiable on the PCI Security Standards Council's public list. A number can be cross-checked; a logo in a brochure cannot.
The radio technologies supported: ISO/IEC 14443 Type A and Type B, plus FeliCa where the market requires it. Japan and Hong Kong fall on this row.
The register communication protocol, named and versioned. This row determines the integration workload in chapter 5.
The key injection method: at the factory, on site, or remotely. On-site injection across 300 stores is a logistics project, not a formality.
Supplier response grid, one row per model and per country
of card-present transactions were processed as EMV in the fourth quarter of 2025. The foundation is in place; the difficulty lies elsewhere
EMVCo
7.0
current version of the PCI PTS POI standard, which covers the physical and logical security of the hardware
PCI Security Standards Council, document library, accessed August 2026
2022
publication of PCI MPoC, which allows contactless and PIN entry on the same off-the-shelf phone
PCI Security Standards Council
🔑
The question that makes the difference in a supplier meeting
Don't ask whether the terminal is certified. Ask which approvals, in which countries, valid until what date. Three pieces of information, one row per model and per market. A supplier that can answer on the spot knows its product line; a supplier that promises to get back to you has just told you that the approval for the third country does not exist yet. The answer, or the lack of one, is an audit in itself.
🎯 Quick question
A supplier offers a terminal with PCI PTS POI approval and EMV Level 2 certification. Can the retailer deploy it in Israel?
Chapter 3. Configuring contactless and diagnosing declines.
The contactless radio layer is the same everywhere: ISO/IEC 14443 for the physical layer and one EMV contactless kernel per accepted network. What varies from country to country is the amount above which cardholder verification becomes mandatory, and the authority that sets it. That source determines how quickly the limit changes, since a scheme limit moves within months. A regulatory limit takes years. The payments team of a multi-country retailer therefore keeps a table and dates every row.
Market
Per-transaction limit
Cumulative counter
Who sets it
Source
European Economic Area
50 €
€150 cumulative or 5 consecutive transactions
EU regulation
PSD2 regulatory technical standards, Article 11
United Kingdom
100 £
£300 cumulative
Financial Conduct Authority
FCA, policy statement PS21/2, March 3, 2021
India
5 000 ₹
Not applicable, under the Additional Factor of Authentication waiver
Reserve Bank of India
RBI, circular DPSS.CO.PD No.752/02.14.003/2020-21 of December 4, 2020, effective January 1, 2021
Canada
Up to C$250 on Interac Debit
Set by the issuer
The domestic scheme, not the regulator
Interac Corp., June 2020 increase
Cardholder verification regimes for contactless card payments (four markets, four authorities)
Three terminal parameters turn this regime into behavior at the register. The kernel list that is enabled determines which cards are read, network by network. The CVM list ranks the accepted verification methods and the amounts at which they switch. The floor limit sets the amount above which online authorization becomes mandatory. These three settings come with the acquirer's configuration, and they are checked when the first store goes live, never after the hundredth.
A customer complains about a decline at the counter: five checks, in this order
Store manager
Notes the reason code displayed and the exact time
Without a reason code, diagnosis turns into an investigation. The terminal log keeps the code
➜
Payments support
Checks whether the card was declined or a PIN was requested
A PIN request is not a decline. The cumulative counter lives in the card and resets at the first PIN entry
➜
Payments support
Compares the terminal's configuration with that of stores that work fine
Enabled kernels, CVM list, floor limit. A single store out of line on one metric almost always points to a configuration gap
➜
Payments support
Checks which scheme was actually used on a co-badged card
The domestic scheme's limit and the international network's limit often differ on the same card. The cardholder sees only a decline
➜
Payments team
Escalates to the acquirer with the evidence gathered
Reason code, terminal ID, timestamp, amount, card brand. Without these five items, the acquirer cannot trace anything
🔑
Mobile payments are not subject to card contactless limits
A wallet unlocked with biometrics carries a CDCVM, because the cardholder was verified on the device before the cryptogram was generated. The transaction is therefore not unverified, and card contactless limits do not apply to it. The impact at the counter is immediate. Phones handle the high-ticket purchases where physical cards hit the limit, and a manager who sees the average ticket drop off around the local limit is watching the wrong metric. The issue is the verification method, not the contactless limit.
Write the checkout instructions in the local language, with the local limit and its exact wording. A sales associate who explains a PIN request correctly prevents a customer incident.
Prohibit manual entry of the card number when the reader fails. It is a fallback flow that carries costly liability, and some local standards refuse it.
Track the magstripe fallback rate, terminal by terminal. A sustained rise on one terminal signals a worn chip reader before it fails.
Check offline capability where the business requires it. BankAxept works offline in Norway and serves as the designated arrangement for cash distribution in stores (Norges Bank, December 2025).
Check domestic routing where it is mandated. In Malaysia, MyDebit requires priority domestic routing of debit transactions (PayNet).
🎯 Quick question
In the EEA, a customer makes four €12 contactless payments in a row and is then asked for a PIN on the fifth. What happened?
Chapter 4. Choosing between terminal, SoftPOS, and QR.
SoftPOS turns an ordinary phone into a contactless acceptance point with no extra hardware. Its security framework is PCI MPoC, published in 2022 by the PCI Security Standards Council, which consolidates SPoC for PIN entry and CPoC for contactless. The best-known implementation is Tap to Pay on iPhone, available in more than 80 countries and territories (Apple, developer.apple.com/tap-to-pay/regions, accessed August 2026). The service requires a certified payment provider as the integration point. Check that country list before making the call, not after.
Older cards without contactless, amounts above the limits
A decline at the counter on a high-ticket sale costs more than the terminal
Market where QR carries in-person payments
Local aggregator, terminal as a complement
The dominant instrument is not the card
Posting payments back to the register, and reconciliation
Decision grid by type of point of sale, and what actually decides it
> 80
countries and territories where Tap to Pay on iPhone is available; India, mainland China, Indonesia, Thailand, and South Korea are not on the list
Apple, developer.apple.com/tap-to-pay/regions, accessed August 2026
165 000
software POS devices in Italy in 2025, out of a total base of 3.6 million terminals, 19% of them smart POS
Osservatorio Innovative Payments, March 12, 2026
44.86M
QRIS acceptance points enrolled in Indonesia at end of June 2026, serving 66 million users
Bank Indonesia, August 6, 2026
Check that the service is available in the country on the vendor's own page, before any cost analysis. The gaps are not delays: these are markets built around something other than card contactless.
Check that the certified provider covers the country. The service and the provider are two separate conditions, and they do not overlap everywhere.
Inventory the staff phone fleet, model by model and OS version by OS version. A mixed Android fleet produces inconsistent contactless behavior.
Measure the share of contactless cards among your actual customers, not the national figure. International customers carry older cards.
Check local obligations for the acceptance point. In Italy, software solutions on phones fall within the same tax pairing scope as terminals.
⚠️
SoftPOS is not a cheaper terminal. It is a different terminal
It reads neither the contact chip nor the magnetic stripe. With international customers, that limitation turns into declines at the counter on the highest-value purchases. The cost does not disappear either. It shifts from hardware to fleet management, OS versions, and support. Where SoftPOS wins, it wins big: micro-merchants, mobile sales, and line busting. The right purchasing analysis compares the total cost per acceptance point per year, not the price of a terminal.
🎯 Quick question
An upscale hotel chain wants to replace all its front-desk terminals with SoftPOS. Which technical objection matters most?
Chapter 5. Wiring the register without redoing the project in every country.
Below the terminal, the authorization message is still ISO 8583 in most markets. Above the terminal, standardization ends. The dialogue between register software and terminal is national, sometimes proprietary, often legacy. That makes it the most expensive layer of a multi-country rollout, and the one specifications forget. The approach taught here is to isolate that layer behind a single contract, then estimate the rest in flows to test.
Component
Reusable?
Why
Payment engine and routing rules
Yes
The retailer's internal logic, independent of the market
Merchant master data and MID/TID hierarchy
Yes
The retailer's own data structure, provided it was designed for multiple countries from day one
Register → payment layer abstraction contract
Yes, if it has been written
That is exactly what this chapter covers
Register ↔ terminal protocol
No
National or proprietary. It changes with the country, sometimes with the acquirer
EMV Level 3 tests
No
Redone for each terminal-acquirer pair, under network rules
Functional test plan
Partially
The framework is reused, and local flows are added: tips, split payments, receipts, partial refunds
Checkout staff training
No
Screens, labels, cardholder verification instructions: everything is local
What carries over from one country to the next, and what has to be redone
nexo: the only attempt at a standard above the terminal
The nexo standards association publishes acceptance protocols based on ISO 20022, three of which directly concern a retailer. The nexo Retailer Protocol standardizes the dialogue between the register and the point of interaction, under the name Sale to POI. The nexo Acquirer Protocol carries messages to the acquirer in the caaa message family. The nexo TMS Protocol governs fleet management, in the catm family (nexo standards, accessed August 2026). Adoption is driven by national standards rather than by the market. In France, the CB 6.0 standard, known as FRV6, builds on these protocols and has been mandatory for new terminals since January 1, 2025 (GIE Cartes Bancaires).
The contract the register must send, identical in every country
The amount travels in the currency's minor unit, with its exponent. A currency with no decimals is written without multiplying by 100.
The batch number comes back in the response. Without it, the reconciliation in chapter 6 cannot be automated.
So does the verification method. It explains after the fact why a cardholder entered a PIN, and it defuses complaints.
A per-country adapter translates this contract in a single module, tested in isolation. The rest of the register software knows nothing about the local protocol.
No business rules in the adapter. An adapter that makes decisions ends up duplicated, then divergent, then wrong in one country out of three.
⚠️
The integration budget is counted in flows, not stores
A retailer opening its eighth country reuses its payment engine and merchant master data, but not its register-terminal integration. Overruns always happen in the same place. Functional testing covers local flows, and every market has its own variant of each one: voids, partial refunds, tips, split payments, customer receipts, and fallback mode. Counting stores produces a reassuring, wrong number. The right unit of work is the number of flows to test, multiplied by the number of terminal-acquirer pairs.
🎯 Quick question
Which ISO 20022 message family does the nexo TMS Protocol use, and what is it for?
Chapter 6. Tracking batch upload, settlement, and reconciliation.
An authorization is not a payment. It reserves an amount with the issuer, nothing more. Money flows to the retailer only after the batch of transactions is submitted to the acquirer: the end-of-day batch upload, which runs at a fixed time set by a terminal parameter. A transaction that is authorized but never submitted is never paid. The corresponding check is a single daily query, yet most rollouts do without it.
A terminal's day, from authorization to incoming transfer
Terminal
Obtains online authorization
ISO 8583 message to the acquirer. The response carries an authorization code, not a settlement
➜
Terminal
Closes the period and uploads the batch
At a fixed time set in the terminal. The batch number becomes the key to all downstream reconciliation
➜
Acquirer
Clears with the networks
Sorted by network, card type, and issuing country. This is where the fees are determined
➜
Acquirer
Pays the net amount into the retailer's account
One transfer covering several deposits, net of fees, chargebacks, and open disputes
➜
Store chain
Reconciles the three levels
Register receipt, acquirer deposit report, bank statement line. Three different join keys
Level
What is compared
Join key
Usual gap and corrective action
1. Register ↔ terminal
The sales receipt and the transaction recorded by the terminal
Sale reference + terminal ID (TID)
A tip entered on the terminal, a void never posted back to the register. Replay the terminal log for the day
2. Terminal ↔ acquirer deposit
The uploaded batch and the deposit detail received
TID + batch number + deposit date
Batch never submitted, or submitted twice. Rerun the batch upload before the authorization expires
3. Deposit ↔ bank statement
The gross deposit amount and the transfer actually received
Merchant ID (MID) + settlement date
Fees, holdbacks, chargebacks, currency conversion. Break them down with the fee file, never by hand
The three reconciliations, their keys, and their usual gaps
One merchant ID per country and per legal entity, never shared across two countries. A shared MID makes the third reconciliation impossible to untangle.
A terminal with no batch upload for 24 hours triggers an alert. It is the only check that protects against silently lost revenue.
The settlement currency is written into the acquiring contract. Collecting in local currency and being settled in the head-office currency hands the FX margin to the acquirer.
Dynamic currency conversion offered to the cardholder creates a separate revenue line and a risk of complaints. Manage it actively; do not enable it by default.
Keep deposit files at least as long as the dispute window that applies in the country. A dispute without the deposit record is lost from the start.
ℹ️
Reconciliation is designed before opening, not at the first accounting close
The three levels require three keys that only the initial configuration can guarantee: a sale reference passed all the way to the terminal, a batch number returned in the response, and a merchant ID specific to the country entity. None of the three can be added retroactively to transactions already processed. A retailer that opens its first store without this wiring finds the gap six weeks later, with no way to explain it line by line. Fixing it afterward costs far more than configuring it up front.
🎯 Quick question
A retailer's accountant notices that one store has been taking payments for three days with no transfer arriving. What should be checked first?
Chapter 7. Managing the fleet, after-sales service, and local deadlines.
A terminal fleet is managed like reference data, not like inventory: each unit carries an identifier, a software version, a configuration, a dated approval, and a point of sale. These attributes drift over time, so a retailer that ignores them discovers the gaps through declines, penalties, or service outages. Six indicators are enough to keep the whole fleet under control. Each one must be tied to an action; otherwise it is useless.
Indicator
What it reveals
Alert rule to set
What to do
Magstripe fallback rate, per terminal
A worn chip reader, before it fails
Any sustained rise on a single terminal
Replace the reader during off-peak hours
Decline rate by reason code and by store
A configuration gap, rarely fraud
A store out of line with its country average
Compare enabled kernels, CVM list, and floor limit
Terminals with no batch upload
Authorized revenue never submitted
24 hours with no batch submitted
Resubmit the batch the same day, before the authorization expires
Software versions in service
Fleet drift, support becomes impossible
More than one major version apart
Schedule a campaign through the terminal management system
Approval expiration by model
New deployments about to be barred
12 months before the deadline
Freeze orders for the model and qualify its successor
Time to replace a failed terminal
Whether the service contract is actually honored
Any breach of the contractual commitment
Draw on the local buffer stock, then take it up with the supplier
The fleet dashboard (six indicators, six actions)
March 1, 2024
In Greece, terminals and registers form a single system
Register systems and terminals must work as an interconnected whole, and the procedures had to be completed by February 29, 2024 (AADE).
January 1, 2025
In France, CB 6.0 becomes mandatory for new terminals
The CB 6.0 standard, known as FRV6, builds on the nexo standards, while the installed CB5.5 fleet migrates gradually (GIE Cartes Bancaires).
October 31, 2025
In Italy, the technical pairing specifications are published
The Agenzia delle Entrate, Italy’s tax agency, publishes provvedimento No. 424470, which sets the rules for pairing terminals with the registratore telematico (electronic cash register).
December 1, 2025
In Greece, IRIS Commerce becomes mandatory in retail
The obligation to accept instant payments applies to both physical stores and online shops, covering about 1.2 million terminals (DIAS, 2025 statistics).
January 1, 2026
In Italy, terminal-register pairing takes effect
The requirement comes from the 2025 Budget Law, Law No. 207/2024, Article 1, paragraphs 74 to 77. Pairing is an online service, not a physical connection.
April 20, 2026
In Italy, the deadline for the installed fleet
Pairing deadline for terminals active as of January 31, 2026. Failure to pair counts as failure to record sales, with a penalty of €1,000 to €4,000 (Law No. 207/2024).
Terminal ID (TID) and merchant ID (MID), linked to the point of sale and to the country's legal entity.
Serial number and model, the only data that link a terminal to its approval and its expiration date.
Software version and configuration version, collected automatically, never entered by hand.
Regulatory pairing reference, where the country requires one, with the date it was obtained.
Key injection date and injection method, which determine the emergency replacement procedure.
Service status and date of last communication, the basis for the batch upload alert and for managing after-sales service.
⚠️
A poorly identified fleet puts the merchant in breach of the law, not just behind on compliance
In Italy, the terminal's unique identifier must reach the merchant in a form usable in the portal of the Agenzia delle Entrate, Italy's tax agency. Pairing is done point of sale by point of sale and terminal by terminal, so for a chain with several hundred stores it is not a simple filing formality. The work is about reference data, and its deadline is legally binding. The penalty falls on the merchant. Commercial liability, however, traces back to the provider that delivered a poorly identified fleet.
🎯 Quick question
Why track the PCI PTS POI approval expiration date for each model in the fleet?