Advisory

PCI Software Security Framework (SSF)

PCI Secure Software and Secure SLC assessments for vendors that build payment software.

Payment software, secure by design.

The PCI Software Security Framework (SSF) is the PCI Security Standards Council's set of standards for payment software. It has two parts. The Secure Software Standard sets security requirements for the payment software itself. The Secure Software Lifecycle (Secure SLC) Standard sets requirements for how a vendor builds security into design, development, deployment and maintenance. The framework replaced PA-DSS, which PCI SSC retired in October 2022. Vectra runs PCI SSF assessments. We help software vendors define the scope of their products and processes, prepare evidence, close gaps and complete the assessment. We also help merchants and service providers understand what the framework means for the payment software they buy.

PCI Software Security Framework (SSF)

Both standards moved to version 2.0 in 2026.

PCI SSC published Secure Software Standard v2.0 in January 2026. It is built around the software's sensitive assets, and software development kits can now be assessed.

Secure SLC Standard v2.0 followed in September 2026. It now focuses only on the vendor's lifecycle, and it covers digital tools, including artificial intelligence, used in the vendor's processes.

  • Secure Software Standard

    Security requirements for the design and management of payment software, to protect payment transactions and account data.

  • Secure SLC Standard

    Security requirements for building security into every stage of the software lifecycle.

  • Separate assessments

    Each standard is assessed on its own. A validated Secure SLC brings program benefits for the vendor's listed software.

  • Transition periods

    Each version 2.0 has a 12-month transition from the previous version, which starts once assessor training is available.

Software security inside one PCI practice.

PCI work since 2006

Vectra became Australia's first certified QSA Company in 2006. Our software security assessments sit inside the same PCI practice.

Across the PCI standards

We run assessments for PCI DSS, PCI PIN, PCI P2PE and the Software Security Framework, so we understand how your software will be used in your customers' payment environments.

Testing in the same team

Our penetration testing team can test your applications and their supporting infrastructure, so technical findings come from the same practice.

From scoping to validation.

Each step is based on evidence of the controls operating today.

  1. Step 1: Scope

    Define the software product or lifecycle in scope, its sensitive assets, how it is deployed, and the teams and tools involved.

  2. Step 2: Readiness review

    Check your software and development practices against the requirements that apply, and prioritise the gaps by risk.

  3. Step 3: Fix the gaps

    Help your developers and product owners change code, processes and documentation, and gather the evidence the assessment needs.

  4. Step 4: Assess

    Review documentation and evidence, interview your teams, and test the software's security functions.

  5. Step 5: Report

    Prepare the Report on Validation and Attestation of Validation, with clear findings and supporting evidence.

  6. Step 6: Manage change

    Assess new releases and changes to your lifecycle, so each change is documented and its impact understood.

Software security work we run.

Secure Software assessment

An assessment of a payment software product or SDK against the Secure Software Standard.

Secure SLC assessment

An assessment of your software lifecycle against the Secure SLC Standard.

Gap assessment

A review of your product or lifecycle against either standard, with a ranked plan to close the gaps.

Version 2.0 transition

Advice on the changes in version 2.0 of both standards, including sensitive asset identification and the new change process.

PA-DSS migration

Advice for vendors and their customers that still depend on expired PA-DSS applications.

Application security testing

Penetration testing of your applications and infrastructure, to find weaknesses before the assessment does.

What you have at the end.

  • A clear scope for your software or lifecycle, agreed before the assessment starts.

  • Development practices and documentation that match the current requirements.

  • A plan for moving to version 2.0 of the standards that apply to you.

  • A ranked list of any gaps, with owners and next steps.

PCI SSF questions.

Is PA-DSS still valid?

No. PCI SSC retired PA-DSS on 28 October 2022 and replaced it with the Secure Software Standard and the Secure SLC Standard. PA-DSS applications are now expired and listed as acceptable only for pre-existing deployments. Ask your acquirer or payment brand about using them.

Do we need both standards?

Not necessarily. Neither standard requires an assessment to the other. Vendors with a validated Secure SLC that use it to build their listed software products do gain program benefits for those products.

Which versions apply now?

Secure Software Standard v2.0 was published in January 2026, and Secure SLC Standard v2.0 in September 2026. Each has a 12-month transition period from the previous version, which starts once assessor training is available.

Can a software development kit be assessed?

Yes. Under Secure Software Standard v2.0, software development kits can be assessed, including EMVCo 3DS SDKs.

Must merchants use validated software?

The payment brands decide whether validated software is required. Merchants should check with their acquirer or payment brand.

Start with a conversation.

Speak to us about your cyber governance and compliance requirements.