PCI SSF | A-LIGN
  • Services
    • Links
      • SOC ASSESSMENTS
        • SOC 1
        • SOC 2
      • ISO CERTIFICATIONS
        • ISO 27001
        • ISO 27701
        • ISO 22301
        • ISO 42001
      • HEALTHCARE ASSESSMENTS
        • All Healthcare
        • HITRUST
        • HIPAA
      • Federal Assessments
        • All Government
        • FedRAMP
        • StateRAMP
        • FISMA
        • CMMC
        • NIST 800-171
      • PCI Assessments
        • PCI DSS
        • PCI SSF
      • Cybersecurity
        • Penetration testing
        • Red team services
        • Ransomware preparedness assessment
        • Social engineering
        • Vulnerability assessment service
      • Privacy
        • GDPR
        • CCPA/CPRA
      • International Services
      • Additional Services
        • Microsoft SSPA
        • NIS2 Directive
        • C5 Attestation
        • SOX 404
        • CSA STAR
        • Business Continuity & Disaster Recovery
        • Limited Access Death Master File
    • FEATURED RESOURCES
      • What is SOC 2? Complete Guide to SOC 2 Reports and Compliance

        SOC 2

        Menlo Security reduces evidence collection time by 60% with consolidated audit approach 

        ISO 27001SOC 2

        ISO 42001 Checklist – Prepare for AI Compliance 

        ISO 42001

        CMMC Buyer’s Guide: How To Choose a C3PAO

        CMMC
  • Technology
  • About Us
    • Our Company
    • Meet our team
    • Board of Directors
    • Partners
    • Events
    • Careers
  • Resources
  • A-SCEND Login
  • Careers
CONTACT US

PCI SSF

Build confidence with your customers by becoming PCI SSF compliant with a Secure Software Lifecycle Standard assessment and a Secure Software assessment.  

Need assurance that your payment application and payment software is secure? As a PCI SSF Qualified Security Assessor Company, A-LIGN can help you with any part of your PCI SSF compliance journey. 

Take the first step to becoming PCI SSF compliant and gain an edge over your competitors, close deals faster and win more business.  

GET STARTED
Badge PCI SSF Dark Background 1 0
About Services Why A-LIGN Resources

Provide trust to your clients with PCI SSF compliance

PCI SSF (Payment Card Industry Software Security Framework) is a security framework designed to help software vendors develop and distribute secure payment applications to their customers. PCI SSF provides a new approach to validating the security of traditional and future payment software and applications.

The PCI SSF assessment includes two components, the Secure Software Lifecycle (SLC) Standard and the Secure Software Assessment (SSA).  

It’s important to note that these two components are mutually exclusive, and while an organization may require an assessment of their payment applications developed and distributed to their customers through a Secure SLC assessment, it does not necessarily require a separate assessment of the entity’s software through an SSA assessment. 

The benefits of PCI SSF compliance:

  • Assures appropriate security and protection mechanisms are in place to secure your customer’s card data. 
  • Helps reduce the risk associated with penalties and data breach complications. 
  • Ensures better protection against security threats and adaptation to any changes in regulatory standards. 
  • Helps win new business from customers that require PCI SFF compliance. 
  • Provides your organization with inclusion in either the Validated Payment Software registry and/or the Secure SLC-Qualified Vendor registry. 

PCI SSF services

Secure Software Life Cycle (SLC) standard
Secure Software Assessment (SSA)

The Secure Software Life Cycle (SLC) standard 

The PCI Secure SLC Standard defines a baseline of security requirements with corresponding assessment procedures and guidance for building secure payment applications. The Secure SLC Standard will aid your organization in building the necessary processes to help meet the Secure Software Assessment (SSA). This component of the PCI SSF assessment includes Penetration Testing to ensure any vulnerabilities in your payment apps and infrastructure can be identified, giving you confidence that all critical data is protected.

Our auditors will perform both on-site and remote testing procedures outlined by the PCI Security Standards Council. Testing procedures include, but are not limited to, interviewing and observing company personnel, inspecting evidence, and testing of Company’s controls to ensure compliance with PCI SSF Secure SLC Standard.  Completion results in:

  • Secure SLC Assessment Report on Compliance 
  • Secure SLC Attestation of Compliance 

The Secure Software Assessment (SSA) 

The PCI Secure Software Assessment is related to the PCI Secure SLC standard but focuses on the payment software itself as opposed to only the security controls associated with the development of the software. The Secure Software Assessment is a modular system and includes variable certification elements for different types of products as it relates to the security of the payment software itself.

Our auditors will perform both on-site and remote testing procedures outlined by the PCI Security Standards Council. Testing procedures include, but are not limited to, interviewing Company personnel, inspecting evidence, such as Company payment application development policies and procedures and related secure development records, observing Company personnel and testing of Company’s payment applications to ensure compliance with PCI SSF Secure Software Standard. Completion results in:

  • Secure Software Report on Validation (ROV)  
  • Secure Software Attestation of Validation (AOV) 

 

Why A-LIGN

2k+ PCI assessments
completed
10+ years of experience
96% client satisfaction
rating

RELATED SERVICES

PCI DSS

SOC 2

Penetration testing

A lign Convergence background

Get started with A-LIGN

Are you ready to start your compliance journey?  A-LIGN is ready to assist with any of your compliance, cybersecurity, and privacy needs.

  • Services
  • Software
  • About us
  • Partners
  • Careers
  • ISO Certificate Directory
  • Privacy Policy
  • Cookie Policy
  • Impartiality and Inquiries
  • Acceptable Use Policy
  • Sitemap
CONTACT US

Price and Associates CPAs, LLC dba A-LIGN ASSURANCE is a licensed certified public accounting firm registered with the Public Company Accounting Oversight Board (PCAOB). A-LIGN Compliance and Security, Inc. dba A-LIGN is a leading cybersecurity and compliance professional services firm.

A-LIGN 2025. All rights reserved.

  • Services
    • SOC ASSESSMENTS
      • SOC 1
      • SOC 2
    • ISO CERTIFICATIONS
      • ISO 27001
      • ISO 27701
      • ISO 22301
      • ISO 42001
    • HEALTHCARE ASSESSMENTS
      • All Healthcare
      • HITRUST
      • HIPAA
    • Federal Assessments
      • All Government
      • FedRAMP
      • StateRAMP
      • FISMA
      • CMMC
      • NIST 800-171
    • PCI Assessments
      • PCI DSS
      • PCI SSF
    • Cybersecurity
      • Penetration testing
      • Red team services
      • Ransomware preparedness assessment
      • Social engineering
      • Vulnerability assessment service
    • Privacy
      • GDPR
      • CCPA/CPRA
    • Additional Services
      • Microsoft SSPA
      • NIS2 Directive
      • C5 Attestation
      • SOX 404
      • CSA STAR
      • Business Continuity & Disaster Recovery
      • Limited Access Death Master File
  • Technology
  • About Us
    • Our Company
    • Meet our team
    • Board of Directors
    • Partners
    • Events
    • Careers
  • Resources
  • A-SCEND Login
  • Careers
CONTACT US