HomeIntelligenceBrief
BREACH BRIEF⚪ Informational Advisory

Walmart Adds Apple Pay and Google Pay to In‑Store Checkout, Expanding Tokenized Payments

Walmart will now accept Apple Pay, Google Pay and other NFC wallets, reducing card‑data exposure through tokenization. The move highlights the need for vendor‑risk monitoring and SOC 2 evidence of third‑party controls.

LiveThreat™ Intelligence · 📅 August 21, 2026· 📰 zdnet.com
Severity
Informational
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
zdnet.com

Walmart Adds Apple Pay and Google Pay to In‑Store Checkout

What Happened – Walmart announced it will accept tap‑to‑pay transactions from Apple Pay, Google Pay and other NFC wallets, joining roughly 85 % of U.S. retailers that already support tokenized mobile payments. The change coexists with Walmart Pay, which remains available via QR‑code scanning.

Why It Matters for Compliance & Audit Readiness

  • Tokenization limits the scope of PCI‑DSS and SOC 2 Security controls because card data never touches Walmart’s point‑of‑sale systems.
  • Integrating Apple Pay/Google Pay introduces third‑party service‑provider risk; continuous vendor‑risk monitoring is required to keep SOC 2 Vendor‑Management evidence up‑to‑date.
  • The shift creates a clear audit trail (token‑to‑transaction mapping) that can be captured as continuous compliance evidence.

Who Is Affected – Large‑scale retailers, payment processors, and any organization that relies on third‑party mobile‑wallet services.

Recommended Actions

  • Map the new tokenization flow to your SOC 2 Security principle controls (e.g., CC6.1 Logical Access, CC6.2 Encryption).
  • Initiate or update a vendor‑risk assessment for Apple Pay and Google Pay, documenting due‑diligence and ongoing monitoring.
  • Capture token‑generation logs as part of your continuous‑evidence program to demonstrate control effectiveness during audits.

Technical Notes – Tap‑to‑pay uses NFC to exchange a one‑time‑use payment token generated by the wallet app; the token is decrypted only by the issuing bank, reducing exposure of PAN data. No new CVEs or vulnerabilities were disclosed. Source: ZDNet Security

📰 Original Source
https://www.zdnet.com/article/walmart-now-accepts-google-pay-apple-pay/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →