PCI work since 2006
Vectra became Australia's first certified QSA Company in 2006. Our software security assessments sit inside the same PCI practice.
PCI Secure Software and Secure SLC assessments for vendors that build payment software.
The PCI Software Security Framework (SSF) is the PCI Security Standards Council's set of standards for payment software. It has two parts. The Secure Software Standard sets security requirements for the payment software itself. The Secure Software Lifecycle (Secure SLC) Standard sets requirements for how a vendor builds security into design, development, deployment and maintenance. The framework replaced PA-DSS, which PCI SSC retired in October 2022. Vectra runs PCI SSF assessments. We help software vendors define the scope of their products and processes, prepare evidence, close gaps and complete the assessment. We also help merchants and service providers understand what the framework means for the payment software they buy.
PCI SSC published Secure Software Standard v2.0 in January 2026. It is built around the software's sensitive assets, and software development kits can now be assessed.
Secure SLC Standard v2.0 followed in September 2026. It now focuses only on the vendor's lifecycle, and it covers digital tools, including artificial intelligence, used in the vendor's processes.
Security requirements for the design and management of payment software, to protect payment transactions and account data.
Security requirements for building security into every stage of the software lifecycle.
Each standard is assessed on its own. A validated Secure SLC brings program benefits for the vendor's listed software.
Each version 2.0 has a 12-month transition from the previous version, which starts once assessor training is available.
Vectra became Australia's first certified QSA Company in 2006. Our software security assessments sit inside the same PCI practice.
We run assessments for PCI DSS, PCI PIN, PCI P2PE and the Software Security Framework, so we understand how your software will be used in your customers' payment environments.
Our penetration testing team can test your applications and their supporting infrastructure, so technical findings come from the same practice.
Each step is based on evidence of the controls operating today.
Define the software product or lifecycle in scope, its sensitive assets, how it is deployed, and the teams and tools involved.
Check your software and development practices against the requirements that apply, and prioritise the gaps by risk.
Help your developers and product owners change code, processes and documentation, and gather the evidence the assessment needs.
Review documentation and evidence, interview your teams, and test the software's security functions.
Prepare the Report on Validation and Attestation of Validation, with clear findings and supporting evidence.
Assess new releases and changes to your lifecycle, so each change is documented and its impact understood.
An assessment of a payment software product or SDK against the Secure Software Standard.
An assessment of your software lifecycle against the Secure SLC Standard.
A review of your product or lifecycle against either standard, with a ranked plan to close the gaps.
Advice on the changes in version 2.0 of both standards, including sensitive asset identification and the new change process.
Advice for vendors and their customers that still depend on expired PA-DSS applications.
Penetration testing of your applications and infrastructure, to find weaknesses before the assessment does.
A clear scope for your software or lifecycle, agreed before the assessment starts.
Development practices and documentation that match the current requirements.
A plan for moving to version 2.0 of the standards that apply to you.
A ranked list of any gaps, with owners and next steps.
No. PCI SSC retired PA-DSS on 28 October 2022 and replaced it with the Secure Software Standard and the Secure SLC Standard. PA-DSS applications are now expired and listed as acceptable only for pre-existing deployments. Ask your acquirer or payment brand about using them.
Not necessarily. Neither standard requires an assessment to the other. Vendors with a validated Secure SLC that use it to build their listed software products do gain program benefits for those products.
Secure Software Standard v2.0 was published in January 2026, and Secure SLC Standard v2.0 in September 2026. Each has a 12-month transition period from the previous version, which starts once assessor training is available.
Yes. Under Secure Software Standard v2.0, software development kits can be assessed, including EMVCo 3DS SDKs.
The payment brands decide whether validated software is required. Merchants should check with their acquirer or payment brand.
Speak to us about your cyber governance and compliance requirements.