Framework · Last verified
Secure Software Standard
Secure Software Standard is PCI SSC's product-level standard for payment software, assessed by PCI Secure Software Assessors — successor to the retired PA-DSS. The current version is v2.0, last updated 2026-01-15 per PCI SSC's own document-library data; the prior v1.2.1 remains in effect in parallel.
- Class
- Framework
- Owner
- PCI Security Standards Council (PCI SSC)
- Last verified
What it is
This is a product-level standard: software that passes assessment is added to PCI SSC's "Validated Payment Software" list. PCI SSC states its intended audience directly: "Software vendors that develop payment software to support or facilitate payment transactions."
The current version is Secure Software Standard v2.0, last updated 2026-01-15 per PCI SSC's own document-library data; the prior version, v1.2.1 (last updated 2023-05-22), remains in effect in parallel — no earlier version was found archived.
The Secure Software Standard is one of two standards PCI SSC named as successors when it retired the Payment Application Data Security Standard (PA-DSS): "The Payment Application Data Security Standard (PA-DSS) is retired as of 28 October 2022." The other named successor is the separate, organization-level Secure SLC Standard.
PCI SSC itself does not mandate the standard: "Compliance programs for all PCI SSC standards are managed by the payment brands."
Who owns it
The standard is owned and published by the PCI Security Standards Council (PCI SSC).
Who assesses it
Independent assessments are performed by PCI Secure Software Assessors, PCI SSC's own qualification, distinct from the QSA program used for PCI DSS.
Who asks for it
Voluntary. PCI SSC's own page states: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself imposes no mandate for the Secure Software Standard.
PCI SSC's own page puts the decision to require validation with the payment brands: "Compliance programs for all PCI SSC standards are managed by the payment brands." PCI SSC itself names no universal requirement.
Sources
- PCI Security Standards Council — Secure Software Standard page (scheme owner) ↗ — accessed
- PCI SSC — PA-DSS standard page (confirms PA-DSS retirement and its two named successor standards) ↗ — accessed
- PCI SSC official document-library endpoint — confirms Secure Software Standard v2.0 (last updated 2026-01-15) is the current non-archived version (v1.2.1, last updated 2023-05-22, also in effect in parallel) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.