PCI SSF
Get your payment software validated and your development lifecycle qualified under the PCI Software Security Framework, assessed by qualified PCI SSC assessors.
0
0 +
0 +
What is the PCI Software Security Framework?
The PCI Software Security Framework (SSF) is the PCI Security Standards Council's framework for the secure design and development of payment software. It replaced PA-DSS, which expired on 28 October 2022, and reflects how payment software is built and shipped today.
The framework contains two standards, with a separate validation program behind each. Which one applies depends on what you want assessed.
Why PCI SSF matters for your payment software
The framework sets what your customers and the card brands expect payment software to meet. What you get from working to it:
-
Security built into the lifecycle: Requirements apply through design, development, deployment and maintenance, rather than landing as a review at the end.
-
Coverage for how software is built now: Validation extends to traditional, modern and emerging payment software architectures.
-
Room for the way your team works: The framework is designed to sit alongside agile and iterative development, without forcing a waterfall cadence on your release cycle.
How the PCI SSF assessment process works
Scope definition
Getting scope right at the start saves time and budget across the whole engagement. Working with your key stakeholders, we align on the business, regulatory and compliance requirements that apply, then agree on responsibilities, timelines and budget before any assessment work begins.
Gap analysis, testing and code review
Gap analysis, code review and control testing show where your software, security controls and systems need attention. Remediation is targeted at what the standard requires, based on a clear picture of where you stand.
Assessment and listing
As a qualified PCI Security Standards Council assessor, Integrity360 evaluates your software and software lifecycle against the applicable standard and takes you through to listing.
-
Independent assessment against the Secure Software Standard, the Secure SLC Standard, or both.
-
A PCI SSC listing your card brands and customers can verify for themselves.
Speak to an expert
Whether you're preparing a product for validation or qualifying your development lifecycle, the starting point depends on which standard applies and how far your current practices already go. Talk to an advisor about the right first step.
Dublin: +353 01 293 4027
London: +44 20 3397 3414
Sofia: +359 2 491 0110
Cape Town: +27 08 606 25673
Johannesburg: +27 08 606 25673
