Software Security Framework
The Software Security Framework (SSF) is a collection of standards and programs from the PCI Security Standards Council aimed at the secure design and development of payment software. It sets security requirements that software vendors follow to help protect payment data, and it changes how software vendors and the payment software they create are assessed and validated. Assessments are performed by independent organizations qualified by the PCI Security Standards Council.
The PCI Software Security Framework (SSF) is a collection of standards and programs maintained by the PCI Security Standards Council for the secure design and development of payment software. It addresses security requirements intended to protect cardholder data (CHD) and sensitive authentication data handled by payment software, and it represents a shift in how software vendors are assessed and how their payment software is validated. Validation activities under the SSF are conducted by SSF Assessor companies qualified by the PCI Security Standards Council. The SSF is distinct from PCI DSS and from other PCI standards; practitioners should confirm applicable standards, programs, and their current requirements against the currently published SSF documentation. Note that this SSF should not be confused with the unrelated NIST Secure Software Development Framework (SSDF).
Why it matters
Payment software sits directly in the path of cardholder data and sensitive authentication data, so weaknesses in how that software is designed and built can undermine other controls that protect payment data. The PCI Software Security Framework (SSF) matters because it establishes security requirements that software vendors follow, intended to help protect the cardholder data and sensitive authentication data handled by payment software. By defining these expectations for secure design and development, the SSF gives vendors, assessors, and the organizations that rely on payment software a common reference for evaluating software security.
The SSF also represents a shift in how software vendors are assessed and how the payment software they create is validated. Validation activities are performed by independent SSF Assessor companies that have been qualified by the PCI Security Standards Council, which supports consistency in how assessments are conducted. For organizations evaluating or selecting payment software, this structure provides a defined program under which software security can be assessed rather than relying solely on vendor assertions.
Because the SSF is distinct from PCI DSS and from other PCI standards, and because its standards, programs, and requirements can change over time, practitioners should not assume it substitutes for other applicable requirements. Its scope is the security of payment software, and it should not be confused with the unrelated NIST Secure Software Development Framework (SSDF). Confirm applicable standards, programs, and their current requirements against the currently published SSF documentation.
Who it's relevant to
Inside SSF
Common questions
Answers to the questions practitioners most commonly ask about SSF.