HomeFrameworksInformation Security & PrivacyPCI SSF

Framework  Information Security & Privacy

PCI SSF

The PCI Software Security Framework (SSF) replaced the Payment Application Data Security Standard (PA-DSS), which PCI SSC formally retired on October 28, 2022. It has two standards.

The Secure Software Standard sets security requirements for payment software products (version 1.2, published December 7, 2022, added a Web Software Module for internet-facing payment software; verify the current version in the document library).

The Secure Software Lifecycle (Secure SLC) Standard sets requirements for a vendor's development practices, so a vendor with a validated Secure SLC can self-attest to low-impact changes to its listed products.

In writing, a vendor needs a documented secure development lifecycle (threat modeling, secure design and coding standards, testing, vulnerability handling, release management), a software inventory of components and third-party libraries, an implementation guide for customers, and the assessment report and attestation.

Validated software and validated vendors are listed by PCI SSC and the listings are maintained through annual attestations and reassessment on major change.

AI-compiled
Share
Sponsored
PCI
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with PCI SSF
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Voluntary for software vendors, but payment brands and acquirers often require merchants to use validated payment software, and some brand programs mandate listed software for certain merchant types. Vendors of bespoke or in-house software are not listed but may use the standard as a benchmark.

What the assessor asks to see

Software architecture and data flows; secure SDLC policy and procedures; threat models; coding standards and code review records; static and dynamic testing results; third-party component inventory; vulnerability management and patch release records; implementation guide; change control records; prior ROV and AOV.

Two standards

Secure Software Standard: applies to a specific payment software product and includes the Core requirements plus modules (for example Module A for account data protection, Module B for terminal software, the Web Software Module).

Secure SLC Standard: applies to the vendor's development organization; a validated vendor may self-attest to low-impact updates of its listed products between assessments.

Assessors

Who assesses PCI SSF

A PCI SSC qualified SSF Assessor company with employees qualified as Secure Software Assessors and/or Secure SLC Assessors, producing the Report on Validation and Attestation of Validation. Accredited by PCI Security Standards Council qualification.

Public register of assessors: https://www.pcisecuritystandards.org/assessors_and_solutions/software_security_framework_assessors/

No firm has claimed a PCI SSF assessor listing yet. Claim yours →

Consultants

Who helps with PCI SSF

Yes. SSF assessor companies and application security consultancies offer gap assessments, secure SDLC design and pre-assessment testing. Secure SLC engagements focus on process evidence; Secure Software engagements include product testing.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

TevoraIrvine, CA, USANot yet verified
What they do
Enterprise multi-framework
Who they help
Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published
TruvantisSan Francisco, CA, USANot yet verified
What they do
Full-service GRC + vCISO
Who they help
Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
Pricing
Not published

Related reading

  1. What to know about the PCI Secure Software FrameworkExplains how the objective-based framework replaced the PA-DSS checklist and how the two SSF standards fit together.A-LIGN
  2. PCI Secure Software Lifecycle (Secure SLC)Covers the vendor-side standard: the development processes a qualified vendor must evidence, and what delta revalidation allows.Security Journey

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for PCI SSF

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with PCI SSF

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.