Framework · Last verified

Secure Software Lifecycle (Secure SLC) Standard

Secure SLC Standard is PCI SSC's organization-level standard for a software vendor's secure development lifecycle, assessed by PCI Secure SLC Assessors. PCI SSC assesses the vendor's development lifecycle itself, not the software product — the distinction from the product-level Secure Software Standard.

Class
Framework
Owner
PCI Security Standards Council (PCI SSC)
Last verified

What it is

This is an organization-level standard: software vendors whose lifecycle processes pass assessment are added to PCI SSC's "Secure SLC-Qualified Software Vendors" list — distinct from the product-level Secure Software Standard. PCI SSC states its Intended Audience directly: "Software vendors that develop software that is commonly deployed in a payment environment."

The current version is Secure SLC Standard v1.1, last updated 2021-02-18 per PCI SSC's own document-library data — no later version was found.

The Secure SLC Standard is one of two standards PCI SSC named as successors when it retired the Payment Application Data Security Standard (PA-DSS): "The Payment Application Data Security Standard (PA-DSS) is retired as of 28 October 2022." The other named successor is the separate, product-level Secure Software Standard.

PCI SSC itself does not mandate the standard: "Compliance programs for all PCI SSC standards are managed by the payment brands."

Who owns it

The standard is owned and published by the PCI Security Standards Council (PCI SSC).

Who assesses it

PCI SSC states this directly: "PCI Secure SLC Assessors are qualified and trained by PCI SSC to perform independent assessments against the PCI Secure SLC Standard and in accordance with the Secure SLC Program Guide."

Who asks for it

Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself imposes no mandate for the Secure SLC Standard.

PCI SSC's own page puts the decision to require validation with the payment brands: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself names no universal requirement.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Secure Software Lifecycle (Secure SLC) Standard." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/pci-secure-slc

All frameworks & audits →