Framework AI Governance & Privacy Frameworks
SLC
Partly resolved label. "SLC" appears with no expansion under the "AI Governance & Model Safety" heading on Coalfire's frameworks page.
The most plausible reading, given that Coalfire was the first firm qualified by the PCI Security Standards Council to assess against it, is the PCI Secure Software Lifecycle (Secure SLC) Standard, one half of the PCI Software Security Framework that replaced PA-DSS.
The placement under AI governance does not fit, so treat the identification as probable rather than confirmed and ask the vendor for the full title.
The PCI Secure SLC Standard sets requirements for how a payment software vendor governs, designs, builds, tests, and maintains software so that security is designed in throughout the lifecycle.
A vendor that passes a Secure SLC assessment is listed by PCI SSC as a Secure SLC Qualified Vendor and gains the right to make certain low-impact changes to its listed payment software without re-assessment. Version 1.1 of the standard and program, published in 2021, widened eligibility so that vendors without a listed payment application can also qualify.
In writing, the standard expects a documented software security policy and governance structure, threat identification and risk assessment records for each product, secure design and coding standards, vulnerability detection and remediation procedures, change management and version control evidence, and guidance for customers on secure implementation.
help
Who has to comply
Voluntary. Software vendors that develop payment software and want to be listed as Secure SLC Qualified Vendors, or that need the listing to satisfy acquirers and merchants. No law mandates it; the pull comes from card brand programs and customer requirements.
What the assessor asks to see
Software security governance policy and responsibilities; asset and product inventory; threat and risk assessment records; secure design standards and design review evidence; coding standards and code review or static analysis results; vulnerability management and disclosure procedures; testing records; change management, versioning, and release approval records; customer implementation guidance; remediation tracking for findings.
Why the identification is uncertain
The only place the bare label "SLC" appears is a vendor list where it sits under AI governance next to another unresolved acronym, "CPSA". Coalfire's public record as the first PCI SSC-qualified Secure SLC assessor makes the PCI reading the most likely, but the directory has not confirmed it with the vendor.
The PCI SSC assessor listing is a dynamic search page, so no assessor names are reproduced here.
Assessors
Who assesses SLC
Software Security Framework (SSF) Assessor companies qualified by PCI SSC to perform Secure SLC assessments. Individual assessors must be employed by a qualified company and complete PCI SSC training. Accredited by PCI Security Standards Council qualifies and lists SSF Assessor companies.
Public register of assessors: https://www.pcisecuritystandards.org/assessors_and_solutions/software_security_framework_assessors/
No firm has claimed a SLC assessor listing yet. Claim yours →
Consultants
Who helps with SLC
Payment security consultancies help vendors document their lifecycle, run readiness reviews, and prepare evidence before the assessor arrives. Some firms hold both SSF assessor status and offer readiness work, but not for the same client.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a SLC consultant listing yet. Claim yours →
Software
Tools for SLC
Tools that name this framework in their own material.
No firm has claimed a SLC tool listing yet. Claim yours →
Need a hand implementing it?
Find a Consultant for SLC
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with SLC
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.