Earlier quoted context omitted.
PED/PTS devices have even stricter guidelines than contactless payments.
But this device doesn't need a way for the user to enter the pincode. So, all the sensitive part of the terminal is probably completely isolated from the android part. I don't know this device internal and the PED/PTS exact requirement but it seems plausible for me. You have something like a physical compartment who include the NFC and everything needed to process it like in a classical terminal. This compartment is…
Now none of these certifications or standards is bullet proof but people have a very skewed vision of the PCI certification process likely due to bias of only having interacting with the PCI-DSS requirements for merchants and low levels to boot meaning they didn't had to do anything but to fill the SAQ themselves and be on their way.