About Us · Licenses

Licensed, certified and audited

Noqoody is a Qatar Central Bank–licensed Payment Service Provider, authorised across both online payment gateways and POS payment acquiring.

Noqoody — a dual-licensed PSP

Noqoody is a Qatar Central Bank–licensed Payment Service Provider (PSP), authorised to operate across both online payment gateways and POS payment acquiring. With dual licensing, businesses can accept and process digital payments securely through e-commerce platforms, mobile apps and physical POS terminals.

This dual capability positions Noqoody as a comprehensive PSP — bridging online and in-store payments with full compliance, reliability and scalability for merchants across Qatar.

Regulated by Qatar Central BankVisa certifiedMastercard certified
Vault dial in front of the Qatar Central Bank building, symbolising Noqoody's regulated PSP licence
"Connecting businesses with secure online & POS payment solutions."

Scope of our licence

Online Payment Gateway

Authorised to acquire and process e-commerce payments for websites, mobile apps and payment links across Qatar.

POS Payment Acquiring

Licensed to deploy and acquire on physical smart POS terminals, SoftPOS and self-service kiosks.

Multi-Bank Settlement

Direct integration with Qatar Central Bank rails and settlement through multiple local banking partners.

01 — Noqoody compliance

With security standards and certifications

PCI DSS 4.0.1

Payment Card Industry Data Security Standard
Requirement:
A global security standard defining protocols for secure payment processing.
Compliance:
Secure data storage, strong encryption, vulnerability management and segmented, hardened networking across the full estate.

EMV

Europay, Mastercard and Visa
Requirement:
The standard for chip card payments and acceptance devices, including POS terminals.
Compliance:
Every Noqoody terminal accepts chip-enabled cards and applies EMV-level cryptography on each transaction.

SSL / TLS

Transport Layer Security
Requirement:
Cryptographic protocols providing secure communication over a network.
Compliance:
All traffic between terminals, gateway and banking hosts is encrypted with modern TLS ciphers only.

E2EE

End-to-End Encryption
Requirement:
Card data readable only by the intended communicating endpoints.
Compliance:
Card data is encrypted at the read head and tokenised — it is never exposed in merchant systems.
Security shield with padlock surrounded by encryption and secure chip cards

Certificate of PCI DSS Compliance

Awarded to Noqoody Payment Services following a successful audit against the Payment Card Industry Data Security Standard version 4.0.1, assessed by Panacea Infosec — a PCI SSC qualified security assessor.

Classification
Service Provider
Standard
PCI DSS v4.0.1

Assurance at a glance

100%
Platform uptime
0
Security breaches since 2015
100%
Card data tokenised
100%
Encrypted transaction traffic

Licensing milestones

  1. 2015

    Noqoody Payment Services founded in Doha

    01
  2. 2019

    Visa & Mastercard certification achieved

    02
  3. 2022

    QCB Payment Service Provider licence granted

    03
  4. 2025

    PCI DSS 4.0.1 certificate of compliance issued

    04

How we keep card data safe

Tokenisation

Card numbers are replaced by tokens before they reach any merchant system.

Hardened terminals

EMV-level cryptography and signed firmware on every deployed device.

Continuous audit

Quarterly vulnerability scans and annual QSA assessment against PCI DSS.

Apply for an account in minutes

Get your Noqoody account today!