PCI Secure Software Standard
The PCI Software Security Framework standard for payment software design and development, replacing the retired PA-DSS lineage. Part of the family beyond bare PCI DSS that a payments-processing SaaS enterprise is routinely asked about.
v2.0 · PCI Security Standards Council — Software Security Framework · published 2026-01-01
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
PCI Secure Software Standard is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely downloadable from PCI SSC; PCI SSC's terms permit identifiers and structure, not verbatim requirement text, without a separate license.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Secure software lifecycle · Threat and vulnerability management · Sensitive data protection · Software integrity
- Applies to
- payments · software vendors · global
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
03Version ledger
| v2.0 | Current edition | 2026-01-01 |
06Related frameworks
- PCI DSSv4.0.1
Also applies to payments · The cardholder-data standard every merchant and service provider that touches payment card data is measured against. v4.0 retired 2024-12-31; the 51 future-dated v4.x requirements became mandatory 2025-03-31.
Also applies to payments · PCI SSC's physical- and logical-security requirements for card production and provisioning facilities (two companion documents under one program).
Also applies to payments · PCI SSC's standard for accepting contactless card payments on a commercial off-the-shelf mobile device without a separate secure card reader. In its formal sunset window now, with MPoC as the designated successor.
Also applies to payments · PCI SSC's standard for accepting PINs on commercial off-the-shelf mobile devices via a software-based PIN-entry application. In its formal sunset window now, with MPoC as the designated successor.