The PCI Software Security Framework (SSF) is a collection of two independent programs — the Secure Software Lifecycle Program (SLC) and the Secure Software Standard (SSS or 3S) — developed to secure the design and development of payment software. PCI SSC lists the company and the validated products on its website.
The Secure Software Standard applies to software products involved in or supporting payment transactions that store, process or transmit clear-text account data and are sold, distributed or licensed to third parties. Core requirements apply to all certified software; Module A covers clear cardholder data; Module B covers PCI-PTS terminals; Module C covers web-based interfaces.
SSS and SLC are both three-year programs. SLC validates the security controls and practices of design and development; SSS reviews the overall effectiveness of software security. Secure SLC validation simplifies maintaining validation when making low-impact changes.
Kickoff and Planning. Define the certification process, points of contact, timelines and roadmap.
Preparation Phase. Tailored support: SSF training/workshop; SSF scoping; Pre-Assessment or full Gap Assessment; remediation/advisory support.
Formal validation. Accredited auditors check the company's processes and applications in scope.
Reporting. Within 3 weeks of completion; the report is sent to the PCI Council for review, after which a certificate is issued and the company is listed on the PCI website.
Deliverables:
| SLC | SSA |
|---|---|
| Report on Compliance (RoC) | Report on Validation (RoV) |
| Attestation of Compliance (AoC) | Attestation of Validation (AoV) |
| Certificate of Compliance | Certificate of Compliance |
Continual Support after certification.