PCI

Blog space

PCI SSF (Secure Software Framework) – When It Is Required and How to Get Certified

In this article you will learn

  • What is the PCI Secure Software Standard
  • how PCI SSS differs from PCI SLC
  • how to prepare a product for QSSE assessment and PCI SSC listing
PCI SSF certification

Updated: 4 July 2026

What is PCI SSF? PCI Secure Software Framework (SSF) is the set of PCI SSC security standards for payment software developers, which replaced the older PA-DSS standard in October 2022. SSF comprises two distinct standards: PCI Secure Software Standard (SSS) – defining security requirements for software that processes payment data – and PCI Secure Software Lifecycle (SLC) – defining requirements for the processes used to develop and maintain secure software. PCI SSF certification is required of providers whose payment software must appear on the PCI SSC list – a requirement that acquirers and card schemes are enforcing with increasing frequency.

PCI SSF certification – at a glance:

  1. PA-DSS was retired on 28 Oct 2022 – firms with PA-DSS certificates had to transition to PCI SSS or PCI SLC; PA-DSS certificates expired on 28 Oct 2024
  2. PCI SSS (Secure Software Standard) applies to a specific payment software product – like PA-DSS, the certificate is tied to a product version
  3. PCI SLC (Secure Software Lifecycle) applies to the provider’s development processes and practices – an organisational certificate, not a product certificate
  4. Providers holding a PCI SLC certificate may use a simplified certification path for their PCI SSS product certifications
  5. The Validated Secure Software list maintained by PCI SSC is public, and merchants or acquirers increasingly require a listing before accepting payment software.
  6. Patronusec as an accredited QSA conducts PCI SSS evaluations and supports software providers preparing for PCI SLC certification


What distinguishes PCI SSS from PCI SLC – and which standard applies to your organisation?

Every payment software provider facing SSF certification asks this question. The answer depends on whether the certificate covers a product or an organisation.

PCI SSS (Secure Software Standard):

PCI SSS is a product standard – the evaluation covers a specific version of a specific payment software product. A PCI SSS certificate confirms that the product meets PCI SSC security requirements for software handling cardholder data.

PCI SSS is appropriate when:

  • Your product stores, processes, or transmits cardholder data
  • A client or acquirer requires your product to appear on the PCI SSC Software Security Framework list
  • You develop a standalone payment application (terminal software, payment gateway, e-commerce checkout)
  • Each major product version requires a separate evaluation

PCI SLC (Secure Software Lifecycle):

PCI SLC is an organisational standard – the evaluation covers the development processes and practices of the organisation. A PCI SLC certificate confirms that the organisation applies secure SDL (Secure Development Lifecycle) practices.

PCI SLC is appropriate when:

  • You want to build a durable capability for producing secure software, not just certify a single product
  • You have multiple payment products or plan to develop new ones
  • You want to shorten PCI SSS certification time for future products (SLC holders use a simplified SSS path)

Comparison:

FeaturePCI SSSPCI SLC
Subject of evaluationSpecific product (version)Organisational processes
Certificate typeProductOrganisational
ReplacesPA-DSSNo direct predecessor
ValidityVersion-dependent + 3 years3 years with annual review
EvaluatorQualified Software Security Evaluator (QSSE)QSSE

Patronusec Insight: Payment software providers frequently ask “which standard should we choose?” The standard recommendation is PCI SSS if you have a single product and need a PCI SSC listing quickly. PCI SLC if you have multiple products or want to build a sustainable security programme – because PCI SLC eliminates the need for a full evaluation with each new product version. The mature path for established organisations is to achieve both – PCI SLC as the foundation, PCI SSS for the current product listing. We help clients choose the optimal path as part of our PCI certification service.

What are the key PCI SSS requirements for payment software?

PCI SSS v1.0 defines requirements across 15 security objectives in two domains: Core Requirements (applicable to all applications) and Payment Sensitive Data Requirements (for applications handling sensitive payment data).

Key PCI SSS requirement areas:

Data management: Software must minimise storage of sensitive data, encrypt cardholder data, and include mechanisms to delete data after processing. Requirements specify encryption methods (AES-256, RSA-2048 or above) and key management procedures.

Authentication and authorisation: Authentication mechanisms within the application must meet requirements for strong passwords, account lockout, and session management. MFA is required for administrative access.

Vulnerability management: Software must be tested for known vulnerabilities (SAST, DAST) before every release. The provider must have a documented vulnerability response process (Vulnerability Disclosure Policy).

Attack protection: Requirements cover protection against OWASP Top 10, buffer overflow, injection attacks, and other common payment application attack vectors.

Secure communications: All network connections must use current encryption protocols (TLS 1.2 or higher). SSLv3, TLS 1.0, and TLS 1.1 are prohibited.


Your payment software needs to appear on the PCI SSC list and you are not sure where to begin?

Patronusec as an accredited QSA conducts PCI SSS pre-assessments – an evaluation of product readiness before the formal QSSE evaluation. Within 2 to 3 weeks, we deliver a list of gaps and a pre-certification work schedule.

Discuss PCI SSS certification with an expert


What does the PCI SSF certification process look like step by step?

PCI SSF certification differs from PCI DSS – it applies to the software provider, not to merchants or service providers. The evaluator is a Qualified Software Security Evaluator (QSSE) approved by PCI SSC, not a QSA.

PCI SSS certification stages:

  1. Pre-assessment: The provider or an independent consultant conducts an initial readiness evaluation. Identifies gaps before the formal evaluation.
  2. QSSE selection: The provider selects a QSSE from the PCI SSC-approved list.
  3. Documentation review: The QSSE verifies documentation: software specification, security test results, vulnerability management policy, encryption certificates.
  4. Technical evaluation: The QSSE conducts technical testing – source code review (optional or mandatory depending on scope), penetration testing, configuration verification.
  5. Report and listing: The QSSE issues a report. Following a positive result, the product is listed on the PCI SSC Software Security Framework Applications list.
  6. Maintaining certification: The provider must notify the QSSE of significant product changes. Major versions may require a new evaluation.

Patronusec Insight: The largest trap in PCI SSS certification is making significant changes to the product after obtaining the certificate without notifying the QSSE. PCI SSC has detailed requirements on which changes require a new evaluation and which require only notification. Providers that do not track these requirements risk losing their certificate without knowing it – and discover this only when a client checks the PCI SSC list. In our post-certification support model, we help clients manage product changes in line with PCI SSC requirements.

When do acquirers and card schemes require PCI SSF certification?

PCI SSF certification requirements are increasingly written into acquirer agreements and Visa and Mastercard service provider programmes.

When an SSF certificate is mandatory:

  • The product is on a list required by a card scheme (Visa, Mastercard) for a specific segment
  • An acquirer requires a PCI SSC listing as a condition for accepting the product
  • A client (merchant or bank) requires the certificate in an RFP
  • The product replaces a previously PA-DSS certified solution

When an SSF certificate is a strategic advantage:

  • In tenders for software supplied to banks and financial institutions
  • When entering EU or UK markets where compliance requirements are more stringent
  • When building brand credibility in the fintech and payments segment

FAQ – PCI SSF certification

Can PA-DSS be renewed or must companies move to PCI SSS?

PA-DSS cannot be renewed – the PA-DSS programme ended on 28 Oct 2022. Applications with PA-DSS certificates remained on the list until 28 Oct 2024. After that date, PA-DSS certificates expired, and providers must complete PCI SSS certification to return to the PCI SSC list.

How does PCI SSF differ from PCI DSS for a software provider?

PCI DSS covers the environment in which cardholder data is stored, processed, and transmitted – a PCI DSS certificate may be required from a SaaS provider hosting payment software. PCI SSF (SSS/SLC) covers the security of the payment software itself – an SSF certificate confirms the product is securely built. A software provider may need both certificates.

How much does PCI SSS certification cost?

Cost depends on product complexity, number of modules, code review requirements, and the timeline. QSSE costs are typically higher than QSA costs for PCI DSS, due to the specialised nature of the evaluation. Patronusec can help with a pre-assessment that shortens and reduces the cost of the formal QSSE evaluation.

How long does PCI SSF certification take from start to listing?

For a well-prepared product (documented, with security testing history): 3 to 6 months. For a product requiring remediation: 9 to 18 months. A pre-assessment conducted before the formal evaluation shortens the timeline by addressing gaps early.

How does Patronusec help with PCI SSF certification?

We conduct PCI SSS pre-assessments – evaluating documentation and product against PCI SSC requirements. The output is a prioritised gap list and a pre-certification work schedule. As a QSA, we can also assess the provider’s SaaS environment against PCI DSS in parallel with the SSF process – which often shortens the overall project for providers needing both certificates.

Is PCI SLC necessary if I have a single product?

Not mandatory – a single product can be certified via PCI SSS without PCI SLC. PCI SLC is recommended when: you have multiple products (it eliminates full evaluation for each product), when you are building a long-term security programme, or when a client requires organisational evidence of development security maturity.


PCI SSF certification – free consultation

Patronusec as an accredited QSA supports payment software developers in preparing for PCI SSF certification. We advise on the choice between PCI SSS and PCI SLC, conduct pre-assessments, and coordinate preparation with selected QSSEs.

In a free 30-minute consultation we will help you:

  • Determine whether your product requires PCI SSS, PCI SLC, or both
  • Assess the current readiness of your product and identify key gaps
  • Plan a realistic certification timeline and budget
  • Clarify the relationship between SSF certification and PCI DSS requirements for your SaaS environment

Free consultation | PCI DSS certification | Gap analysis PCI | Penetration testing | vCISO

Don't buy a pig in a poke -
request a free consultation and check how we can assist you.

Free consultation
Contact form

Use the contact form or contact us directly.

Patronusec Sp z o. o.

Head Office:
ul. Święty Marcin 29/8
61-806 Poznań, Polska

KRS: 0001039087
REGON: 525433988
NIP: 7831881739
D-U-N-S: 989454390
LEI: 259400NAR8ZOX1O66C64

To top