---
title: "Request for Comments: SPoC Unsupported Operating Systems Annex"
description: From 6 January 2021 to 4 February 2021, PCI SSC stakeholders can participate in a Request for Comments (RFC) on the new SPoC Unsupported Operating Systems Annex draft.
image: https://blog.pcisecuritystandards.org/hubfs/2019_Blog%20Images/RFC-SPoC-Unsupported-Operating-Systems-Annex.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex#)

# [Request for Comments: SPoC Unsupported Operating Systems Annex](https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex)

 Posted by [Alicia Malone](https://blog.pcisecuritystandards.org/author/alicia-malone) on 6 Jan, 2021 in [Participation](https://blog.pcisecuritystandards.org/topic/participation) and [Mobile Product Family](https://blog.pcisecuritystandards.org/topic/mobile-product-family) and [Request for Comments](https://blog.pcisecuritystandards.org/topic/request-for-comments) and [Software-based PIN Entry on COTS (SPoC)](https://blog.pcisecuritystandards.org/topic/software-based-pin-entry-on-cots-spoc) and [PIN Security Standard](https://blog.pcisecuritystandards.org/topic/pin-security-standard)

![RFC-SPoC-Unsupported-Operating-Systems-Annex](https://blog.pcisecuritystandards.org/hs-fs/hubfs/2019_Blog%20Images/RFC-SPoC-Unsupported-Operating-Systems-Annex.jpg?width=800&name=RFC-SPoC-Unsupported-Operating-Systems-Annex.jpg "RFC-SPoC-Unsupported-Operating-Systems-Annex")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex&url=https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex&source=tweetbutton&text=Request%20for%20Comments:%20SPoC%20Unsupported%20Operating%20Systems%20Annex> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex)

 

From 6 January 2021 to 4 February 2021, PCI SSC stakeholders can participate in a [Request for Comments (RFC) ](https://www.pcisecuritystandards.org/get_involved/request_for_comments)on the new SPoC Unsupported Operating Systems Annex draft.

**Background on the SPoC Unsupported Operating Systems Annex  
**The Council has drafted a new, optional, Software-based PIN Entry on COTS (SPoC)™ Annex for Unsupported Operating Systems (“Unsupported OS Annex”). The purpose of this optional Annex is to provide additional security and testing requirements for SPoC solutions, to allow solution providers to develop SPoC solutions that merchants can use on COTS devices with unsupported operating systems.

Adding support for COTS devices with unsupported operating systems allows merchants without access to modern COTS devices, and merchants who are unable to upgrade their COTS devices, to use the security of a SPoC solution. The security and testing requirements, described in the Unsupported OS Annex, are intended to protect the confidentiality and integrity of PINs captured on COTS devices with an unsupported operating system.

**RFC Process**  
The RFC will be available through the [PCI SSC portal](https://programs.pcissc.org/), including instructions on how to access the document and submit feedback. Primary contacts for each eligible organization can access the SPoC Unsupported Operating Systems Annex draft via the Portal. Eligible RFC participants will be required to accept a Non-Disclosure Agreement (NDA) to download the document.

Per the RFC process, every piece of feedback will be reviewed and considered, and PCI SSC will prepare a summary for RFC participants showing all feedback received and how it was addressed. Please review the [RFC Process Guide](https://blog.pcisecuritystandards.org/understanding-the-rfc-process-new-guidance) for more information.

Please note that PCI SSC can only accept comments that are received via the PCI SSC portal within the defined RFC period.

Also on the blog: [What to Know Before Participating in a PCI SSC RFC](https://blog.pcisecuritystandards.org/what-to-know-before-participating-in-a-pci-ssc-rfc)

[![Access the PCI SSC portal and provide comments](https://no-cache.hubspot.com/cta/default/281302/c57a5715-e372-452d-8722-cc618fd9c4bd.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/c57a5715-e372-452d-8722-cc618fd9c4bd)

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Alicia Malone](https://blog.pcisecuritystandards.org/hubfs/Malone%2c%20Alicia.jpg)

[ Alicia Malone ](https://blog.pcisecuritystandards.org/author/alicia-malone)

[Email](mailto:amalone@pcisecuritystandards.org)

 As Director, Communications/Public Relations for PCI SSC, Ms. Malone develops and executes proactive communications and stakeholder engagement programs to educate and drive global collaboration in the payments industry.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/request-for-comments-spoc-unsupported-operating-systems-annex#)