Framework · Last verified
Secure Software Lifecycle (Secure SLC) Standard
Secure SLC Standard is PCI SSC's organization-level standard for a software vendor's secure development lifecycle, assessed by PCI Secure SLC Assessors. PCI SSC assesses the vendor's development lifecycle itself, not the software product — the distinction from the product-level Secure Software Standard.
- Class
- Framework
- Owner
- PCI Security Standards Council (PCI SSC)
- Last verified
What it is
This is an organization-level standard: software vendors whose lifecycle processes pass assessment are added to PCI SSC's "Secure SLC-Qualified Software Vendors" list — distinct from the product-level Secure Software Standard. PCI SSC states its Intended Audience directly: "Software vendors that develop software that is commonly deployed in a payment environment."
The current version is Secure SLC Standard v1.1, last updated 2021-02-18 per PCI SSC's own document-library data — no later version was found.
The Secure SLC Standard is one of two standards PCI SSC named as successors when it retired the Payment Application Data Security Standard (PA-DSS): "The Payment Application Data Security Standard (PA-DSS) is retired as of 28 October 2022." The other named successor is the separate, product-level Secure Software Standard.
PCI SSC itself does not mandate the standard: "Compliance programs for all PCI SSC standards are managed by the payment brands."
Who owns it
The standard is owned and published by the PCI Security Standards Council (PCI SSC).
Who assesses it
PCI SSC states this directly: "PCI Secure SLC Assessors are qualified and trained by PCI SSC to perform independent assessments against the PCI Secure SLC Standard and in accordance with the Secure SLC Program Guide."
Who asks for it
Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself imposes no mandate for the Secure SLC Standard.
PCI SSC's own page puts the decision to require validation with the payment brands: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself names no universal requirement.
Sources
- PCI Security Standards Council — Secure Software Lifecycle (Secure SLC) Standard page (scheme owner) ↗ — accessed
- PCI SSC — PA-DSS standard page (confirms PA-DSS retirement and its two named successor standards) ↗ — accessed
- PCI SSC official document-library endpoint — confirms Secure SLC Standard v1.1 (last updated 2021-02-18) is the current non-archived version ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.