• Skip to primary navigation
  • Skip to main content
  • Skip to footer
ControlCase No Tag LOGO md

ControlCase

IT Certifications, Continuous Compliance and Cybersecurity Services Provider

  • Company
    • About Us
    • Careers
    • Locations
    • Team
  • Industries
    • Business Process Outsourcing
    • Cloud Service Providers
    • Retail
    • Telecom | Entertainment
    • Managed Service Providers
  • Certifications
    • PCI DSS Certification
    • CSA STAR Certification
    • GDPR Assessment
    • HIPAA Assessment
    • HITRUST Certification
    • ISO 27001 Certification
    • FedRAMP 3PAO Services and NIST 800-53
    • CMMC Certification
    • MARS-E Assessment
    • PCI SSF
    • P2PE Certification
    • SOC2 Report
  • Solutions
    • Continuous Compliance Solution
    • One Audit
    • Card Data Discovery Software
    • Data Security Rating
  • Testing
    • Application Reviews
    • Application Security Training
    • Code Reviews
    • Card Data Discovery
    • External Vulnerability Scans
    • Firewall Security Reviews
    • Internal Vulnerability Scans
    • Log Monitoring
    • Penetration Testing
  • Resources
    • Events
    • News
    • Webinars
    • Courses
    • Blog
    • Tools
    • Become a Partner
  • Contact Us
  • English

PCI Software Security Framework

Request DatasheetRequest QuoteRequest Demo
You are here: Home / Certifications / PCI Software Security Framework
ControlCase delivers comprehensive PCI SSF assessments that "Reduce Audit Fatigue" to guarantee:
  • - On-time Compliance
  • - Fixed Price
  • - Partnership Approach - Avoid checkbox auditors
  • - Automated Evidence Collection
  • - Business as Usual

The PCI SSF (Software Security Framework) is a blend of traditional and modern software security requirements. Validation of payment software to Secure Software Standards (S3) assures that the Payment Software that is designed protects the integrity of the software and the confidentiality of the sensitive data it captures, stores, processes, and transmits. The latest framework supports evolving technologies, software types, and development methodologies.

The PCI SSF (Software Security Framework) is a collection of standards and programs for the secure design and development of payment software.

The new SSF is comprised of:

1. A Secure SLC Standard, and

2. A Secure Software Standard.

The Secure SLC Standard defines a set of security requirements and associated test procedures for software vendors to validate how to properly manage the security of payment software throughout the software life-cycle. Secure SLC is applied to software vendors that develop software for the payments industry.

The Secure Software Standard defines a set of security requirements and associated test procedures to help ensure payment software adequately protects the integrity and confidentiality of payment transactions and data. The Secure Software Standard is applied to payment software that is sold, distributed, or licensed to third parties.

Why choose PCI SSF over PA DSS?

  • The PCI SSF is separate and distinct from PA-DSS.
  • The PA-DSS program will eventually be integrated into the PCI SSF.
  • PCI SSF includes some components of PA-DSS.
  • All PA-DSS validated payment applications will continue to be governed by the PA-DSS standard until the applications reach their expiration date.
  • It is recommended to assess new payment applications using PCI SSF instead of continue using PA-DSS.
  • The PCI Council will accept new PA-DSS validations through mid-2020, and these applications will be valid through late 2022.

 

How Does It Work?

ControlCase has a streamlined methodology for SSF (Software Security Framework) Certification featuring an easy to understand questionnaire and sample templates, which explain the types of evidence required. We assist you in driving towards achieving certification in an efficient and cost-effective manner.

The PCI SSF will assist auditors in evaluating the security of software and the development lifecycle. It will replace the current PA-DSS with updated requirements aligned with industry standards that support a broader array of payment software types, technologies, and development methodologies.

The methodology consists of the following steps:

ControlCase PCI SSF, SLC Methodology

Six Phases of Certification Process: Compliance validation is demonstrated and assessed in following six progressive steps.

1. Strategy Call: Strategy call to identify the point of contact from both organizations, timelines for assessment, high level requirement and roadmap for the project.
2. SkyCAM Setup: Configuring tools to collect evidence automatically, to do remote application vulnerability assessment.
3. Scoping: Identify the boundaries of the scope of assessment and inclusion and dependency of any third party.
4. Pre-Assessment/Gap Assessment: Interviews, reviews of documentation and walk-through to identify gaps and provide recommendations.
5. Remediation/ Advisory Support : Assistance as partners to provide advisory support for mitigating gaps and collecting evidence.
6. Compliance Certification: Conduct the certification phase, and on successful completion, provide the reports and attestation documentation/certification. Also support client to list the payment application details with the PCI SSC.

The deliverables include:

  • Report on Compliance (ROC) for SLC
  • Attestation of Compliance (AOC) for SLC
  • Report on Validation (ROV) for SSA
  • Attestation of Validation (AOV) for SSA
  • Certificate of Compliance (COC) SSF / SLC
  • Web Seal
  • Card brand registration support

 

Benefits to our approach include:

ADAPTIBILITY
This approach is adaptable to most ticketing systems.
SIMPLICITY
This approach is repeatable.
TRANSPARENCY
Track progress against only applicable questions.
TRACKABILITY
Stay organized with assessor comments and date stamps.

Featured Resources

SOC 2 Type 2 for MSPs and their clients Webinar

Upcoming Webinar
SOC 2 Type 2 for MSPs and their clients Webinar

How Compliance Can Be a Revenue Generator for MSPs

Blog
How Compliance Can Be a Revenue Generator for MSPs

ControlCase Launches Free Compliance Self-Assessment Tool for MSPs

News
ControlCase Launches Free Compliance Self-Assessment Tool for MSPs

PCI SSF

Data Sheet
November 1, 2020
PCI SSF

Need more information?

Contact Us
  • Facebook
  • LinkedIn
  • Twitter
  • YouTube

Footer

Connect

Corporate Headquarters
3975 FAIR RIDGE DR STE T25S-D
FAIRFAX, VA 22033

Send us a message

Call Us

Search

About Us

ControlCase is a United States based company, headquartered in Fairfax, Virginia with locations in North America, Europe, Latin America, Asia/Pacific, Australia and the Middle East to serve our clients globally.

Quick Links

  • Company
  • Careers
  • Locations
  • Covid-19 Notice

Certifications, Assessments and Reports

  • PCI DSS Certification
  • CSA STAR Certification
  • GDPR Assessment
  • HIPAA Assessment
  • HITRUST Certification
  • ISO 27001 Certification
  • FedRAMP and 3PAO Services
  • MARS-E Assessment
  • PCI SSF
  • P2PE Certification
  • SOC2 Report

© ControlCase LLC 2025 | Privacy Policy | Impartiality Statement | Legal Notices

  • English
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}