Validated Secure Software Lifecycles
The PCI Secure Software Lifecycle (SSLC) Standard is part of the PCI Software Security Framework (SSF) and helps software vendors to ensure that security is designed and integrated at each stage of the software lifecycle. Software vendors can engage a Secure SLC Assessor to have their SSLC assessed and validated in accordance with the PCI Secure SLC Standard. The assessment and validation are documented by the Secure SLC Assessor in a Report on Validation (ROV). Validated Secure SLCs are listed on PCI SSC's List of Validated Secure SLCs upon Acceptance.
Although PCI SSC reviews these reports for quality management purposes, PCI SSC does not independently confirm the reports or the data or information they contain, nor does the PCI SSC perform any testing or analysis of software lifecycles, products, functionality, performance, suitability, or compliance with the Standard.
Filter by
Secure SLC Status: Denotes if the Listed Secure Software Lifecycle (SSLC) is a Validated Secure Software Lifecycle or if it has transitioned to being an Expired Secure Software Lifecycle per the Program. Refer to the associated PCI Secure Software Lifecycle Program Guide for details. Note: formerly referred to as ‘Payment Software Status' for v1.x
For v2.x Secure Software Lifecycle listings, dates in orange indicate the Annual Attestation process has not been completed in accordance with the Secure Software Lifecycle Program Requirements (up to 45 calendar days overdue).
For v1.x Secure Software Lifecycle listings, dates in orange indicate the Annual Attestation process has not been completed in accordance with the Secure Software Lifecycle Program Requirements (up to 90 calendar days overdue). Dates in red indicate the Annual Attestation process has not been completed in accordance with the Secure Software Lifecycle Program Requirements (more than 90 days overdue).
Validated: Newly Accepted Validated Secure Software Lifecycles are initially denoted as 'Validated’ and will retain this designation until denoted as 'Expired.'
Expired: This status is assigned to Validated Secure Software Lifecycles when either (i) annual revalidation requirements are not satisfied by the Vendor, causing early administrative expiry, or (ii) the Validated Secure Software Lifecycle reaches its Reassessment Date (based on the version of the PCI Secure Software Lifecycle Standard under which it was validated).
Annual Attestation Date: Validated Secure Software Lifecycles are required to undergo an Annual (Vendor) Attestation process. Refer to the associated PCI Secure Software Lifecycle Program Guide for details. Note: formerly referred to as ‘Revalidation Date’ for v1.x.
Reassessment: The 3-year Reassessment Date for Validated Secure Software Lifecycles. Refer to the associated PCI Secure Software Lifecycle Program Guide for details. Note: formerly referred to as ‘Expiry Date’ for v1.x. is the date by which a Vendor must have the Payment Software re-evaluated against the then-current version of the PCI Secure Software Lifecycle Standard in order to maintain PCI SSC Acceptance.
For v1.x Listings, refer to the associated v1.x Secure Software Lifecycle Standard and Program Guide.
For v2.x Listings, refer to the associated v2.x Secure Software Lifecycle Standard and Program Guide.