• Skip to primary navigation
  • Skip to main content
  • Skip to footer
ControlCase No Tag LOGO md

ControlCase

IT Certifications, Continuous Compliance and Cybersecurity Services Provider

  • Company
    • About Us
    • Careers
    • Locations
    • Team
  • Industries
    • Business Process Outsourcing
    • Cloud Service Providers
    • Retail
    • Telecom | Entertainment
    • Managed Service Providers
  • Certifications
    • PCI DSS Certification
    • CSA STAR Certification
    • GDPR Assessment
    • HIPAA Assessment
    • HITRUST Certification
    • ISO 27001 Certification
    • FedRAMP 3PAO Services and NIST 800-53
    • CMMC Certification
    • MARS-E Assessment
    • PCI SSF
    • P2PE Certification
    • SOC2 Report
  • Solutions
    • Continuous Compliance Solution
    • One Audit
    • Card Data Discovery Software
    • Data Security Rating
  • Testing
    • Application Reviews
    • Application Security Training
    • Code Reviews
    • Card Data Discovery
    • External Vulnerability Scans
    • Firewall Security Reviews
    • Internal Vulnerability Scans
    • Log Monitoring
    • Penetration Testing
  • Resources
    • Events
    • News
    • Webinars
    • Courses
    • Blog
    • Tools
    • Become a Partner
  • Contact Us
  • English

PCI SSF

request datasheetrequest quoterequest demo
You are here: Home > Certifications > PCI SSF

STREAMLINE PCI SSF COMPLIANCE

6 OF THE TOP 10 RETAILERS USE CONTROLCASE TO HELP WITH COMPLEX PCI ASSESSMENTS.

ControlCase’s unique, tested, and proven process-based Payment Products Assessment and Certification provides a seamless customer experience.

  • Audit Visibility via Compliance Hub
  • |
  • Skilled Technical Team
  • |
  • State-of-the-art Payment App. Lab
  • |

About the Regulation

The PCI Software Security Framework (SSF) is a collection of standards and programs for the secure design and development of payment software. Payment software must be designed, developed, and implemented securely to facilitate reliable and accurate payment transactions.

The SSF replaces the Payment Application Data Security Standard (PA-DSS) with updated security controls and requirements that support a broader array of payment software types, technologies, and development methodologies. PCI SSF consists of two standards:

Secure Software Standard (SSS)

Intended for payment software that is sold, distributed, or licensed to third parties. Includes payment software to be installed on customer systems and deployed to customers “as a service” over the internet.

Secure Software Lifecycle Standard (SSLC)

A set of security requirements and associated test procedures for software vendors to validate how they properly manage the security of payment software throughout the software lifecycle.

Major ControlCase Benefits

  • Certification tracking mechanism using ControlCase Compliance Hub
  • State-of-the-art lab for payment application testing
  • Team of skilled technical professionals
  • In-depth knowledge of payment ecosystems combined with an advanced skill-set
  • Experience in handling complex and heterogeneous software implementations
  • Document templates repository

Why ControlCase

1,000+ Customers
10,000+ IT Security Certifications
100+ BPO Customers
icon

CONSULTATIVE AND PARTNERSHIP APPROACH

Unlike traditional firms, we bring a partnership approach versus an auditor mentality to every engagement. We provide the expertise, guidance and automation needed to more efficiently and cost effectively demonstrate compliance to regulations including SOC 1, SOC 2, PCI DSS, HITRUST, FedRAMP, NIST 800-53, and ISO 27001.

icon

INVESTMENT IN TECHNOLOGY

Over the past decade ControlCase has invested in simplifying regulatory compliance through efficient questionnaires within the ControlCase Compliance Hub™ platform. We have also automated evidence collection for more than half of those questions. Additionally, we have operationalized workflows to make compliance business as usual (continuous compliance) instead of an annual one-time audit.

icon

CONTINUOUS COMPLIANCE MANAGEMENT

We learn your environment and become experts at recommending process improvements and identifying compliance risks before they become security threats. Finally, we assist our customers to address common non-compliant situations that can leave companies vulnerable throughout the year.

Hear it from our customers

We are required to comply with PCI DSS, ISO 27001 and SOC 2 across multiple locations. The ControlCase “Compliance Hub” platform really simplified the entire process.

  • monetique
  • siriusxm
  • wipro
  • wns

Related Content

CEIC West 2025 conference
Events

ControlCase to Exhibit at CEIC West 2025

Read More
AvePoint OnPoint Roadshow Events - Chicago
Events

AvePoint OnPoint Roadshow Events – Chicago, IL

Read More
AvePoint OnPoint Roadshow Events - Irvine
Events

AvePoint OnPoint Roadshow Events – Irvine, CA

Read More

Request for Services

Find out how we can help your organization navigate and satisfy your IT Certification, Compliance/Regulation, and Cybersecurity requirements. Let us know your areas of interest so we can provide services to fit the needs of your organization.

  • This field is for validation purposes and should be left unchanged.
  • Facebook
  • LinkedIn
  • Twitter
  • YouTube

Footer

Connect

Corporate Headquarters
3975 FAIR RIDGE DR STE T25S-D
FAIRFAX, VA 22033

Send us a message

Call Us

Search

About Us

ControlCase is a United States based company, headquartered in Fairfax, Virginia with locations in North America, Europe, Latin America, Asia/Pacific, Australia and the Middle East to serve our clients globally.

Quick Links

  • Company
  • Careers
  • Locations
  • Covid-19 Notice

Certifications, Assessments and Reports

  • PCI DSS Certification
  • CSA STAR Certification
  • GDPR Assessment
  • HIPAA Assessment
  • HITRUST Certification
  • ISO 27001 Certification
  • FedRAMP and 3PAO Services
  • MARS-E Assessment
  • PCI SSF
  • P2PE Certification
  • SOC2 Report

© ControlCase LLC 2025 | Privacy Policy | Impartiality Statement | Legal Notices

  • English
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}