- What they do
- Enterprise multi-framework
- Who they help
- Tevora is an enterprise multi-framework based in Irvine, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Framework Information Security & Privacy
PCI SSF
The PCI Software Security Framework (SSF) replaced the Payment Application Data Security Standard (PA-DSS), which PCI SSC formally retired on October 28, 2022. It has two standards.
The Secure Software Standard sets security requirements for payment software products (version 1.2, published December 7, 2022, added a Web Software Module for internet-facing payment software; verify the current version in the document library).
The Secure Software Lifecycle (Secure SLC) Standard sets requirements for a vendor's development practices, so a vendor with a validated Secure SLC can self-attest to low-impact changes to its listed products.
In writing, a vendor needs a documented secure development lifecycle (threat modeling, secure design and coding standards, testing, vulnerability handling, release management), a software inventory of components and third-party libraries, an implementation guide for customers, and the assessment report and attestation.
Validated software and validated vendors are listed by PCI SSC and the listings are maintained through annual attestations and reassessment on major change.
help
Who has to comply
Voluntary for software vendors, but payment brands and acquirers often require merchants to use validated payment software, and some brand programs mandate listed software for certain merchant types. Vendors of bespoke or in-house software are not listed but may use the standard as a benchmark.
What the assessor asks to see
Software architecture and data flows; secure SDLC policy and procedures; threat models; coding standards and code review records; static and dynamic testing results; third-party component inventory; vulnerability management and patch release records; implementation guide; change control records; prior ROV and AOV.
Two standards
Secure Software Standard: applies to a specific payment software product and includes the Core requirements plus modules (for example Module A for account data protection, Module B for terminal software, the Web Software Module).
Secure SLC Standard: applies to the vendor's development organization; a validated vendor may self-attest to low-impact updates of its listed products between assessments.
Assessors
Who assesses PCI SSF
A PCI SSC qualified SSF Assessor company with employees qualified as Secure Software Assessors and/or Secure SLC Assessors, producing the Report on Validation and Attestation of Validation. Accredited by PCI Security Standards Council qualification.
Public register of assessors: https://www.pcisecuritystandards.org/assessors_and_solutions/software_security_framework_assessors/
No firm has claimed a PCI SSF assessor listing yet. Claim yours →
Consultants
Who helps with PCI SSF
Yes. SSF assessor companies and application security consultancies offer gap assessments, secure SDLC design and pre-assessment testing. Secure SLC engagements focus on process evidence; Secure Software engagements include product testing.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
- What they do
- Full-service GRC + vCISO
- Who they help
- Truvantis is a full-service GRC + vCISO based in San Francisco, CA, USA. Services, standards and pricing appear once the firm confirms its listing.
- Pricing
- Not published
Software
Tools for PCI SSF
Tools that name this framework in their own material.
Related reading
- What to know about the PCI Secure Software FrameworkExplains how the objective-based framework replaced the PA-DSS checklist and how the two SSF standards fit together.A-LIGN
- PCI Secure Software Lifecycle (Secure SLC)Covers the vendor-side standard: the development processes a qualified vendor must evidence, and what delta revalidation allows.Security Journey
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for PCI SSF
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with PCI SSF
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.