Low New document global

PCI SSC publishes Secure Software Standard

Original title: Secure Software Standard

PCI SSC has published the Secure Software Standard, establishing requirements for organizations developing and managing software to ensure security throughout the development lifecycle. This standard applies to software vendors, developers, and organizations that create or maintain software used in payment systems and cardholder data environments. Organizations subject to PCI DSS or developing payment-related software must align their development practices with these new security requirements.

What changed

  • New PCI Secure Software Standard has been established to address secure software development practices
  • Standard provides requirements for software vendors and developers to implement secure coding, testing, and lifecycle management practices
  • Organizations developing software for payment systems must comply with security controls outlined in this standard

Who is affected

Software vendors, software developers, payment service providers, and any organization creating or maintaining software used in payment card industry systems globally

Language
EN

Frameworks

PCI DSS

Open the original source