---
title: "Final Request for Comments: Draft PCI Software Security Framework"
description: From 31 July to 7 September, PCI SSC stakeholders are invited to review and provide final feedback on the draft PCI Software Security Framework, a new approach to securely designing and developing modern payment software.
image: https://blog.pcisecuritystandards.org/hubfs/2018_Blog/microphones.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework#)

# [Final Request for Comments: Draft PCI Software Security Framework](https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework)

 Posted by [Laura K. Gray](https://blog.pcisecuritystandards.org/author/laura-k-gray) on 31 Jul, 2018 in [Software Product Family](https://blog.pcisecuritystandards.org/topic/software-product-family) and [Apps](https://blog.pcisecuritystandards.org/topic/apps) and [PA-DSS](https://blog.pcisecuritystandards.org/topic/pa-dss) and [Participation](https://blog.pcisecuritystandards.org/topic/participation) and [Request for Comments](https://blog.pcisecuritystandards.org/topic/request-for-comments) and [Software Security Framework](https://blog.pcisecuritystandards.org/topic/software-security-framework)

![microphones.jpg](https://blog.pcisecuritystandards.org/hs-fs/hubfs/2018_Blog/microphones.jpg?width=800&name=microphones.jpg "microphones.jpg")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework&url=https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework&source=tweetbutton&text=Final%20Request%20for%20Comments:%20Draft%20PCI%20Software%20Security%20Framework> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework)

From 31 July to 7 September, PCI SSC stakeholders are invited to review and provide final feedback on the draft PCI Software Security Framework, a new approach to securely designing and developing modern payment software.

**Update on PCI Software Security Framework **

As **[previously announced](https://blog.pcisecuritystandards.org/securing-modern-payment-software-with-new-software-security-framework)**, the PCI SSC is developing a new [PCI Software Security Framework](https://blog.pcisecuritystandards.org/topic/software-security-framework) to support both existing as well as emerging payment software practices. The framework includes the creation of two new standards, a supporting validation program for software products, and a certification program for software vendors.

The Payment Application Data Security Standard (PA-DSS) and its validation program will be incorporated into the Software Security Framework once the framework is published. Existing validation expiration dates for PA-DSS validated applications will be honored (e.g. PA-DSS version 3.2 validations expire in 2022). A migration path is also being developed to support the transition of current Payment Application Qualified Security Assessors (PA-QSA) to the PCI Software Security Framework.

Payment card industry stakeholder feedback plays an important part in the development of the PCI Software Security Framework and the PA-DSS transition plan. An **[initial request for comments](https://blog.pcisecuritystandards.org/request-for-comments-pci-software-security-standard-framework)** (RFC) was held in March 2018 that generated more than two hundred comments and suggestions.  Every comment and suggestion has been reviewed by PCI SSC, and the draft Secure Software Standard, Secure Software Life Cycle Standard and Software Security Framework documents have been updated to address this feedback. 

**Participate in the Final Request for Comments Period for the PCI Software Security Framework**

PCI SSC Participating Organizations (which include Affiliate and Strategic Members), Qualified Security Assessors (QSA), Payment Application Qualified Security Assessors (PA-QSA) and PCI-Recognized Labs are invited to review and provide feedback on the latest draft PCI Software Security Framework documents during a final RFC period, running from **31 July to 7 September 2018.**

In addition to incorporating the feedback received from the first RFC, the following updates have been made to the framework documents:

- **Secure Software Standard and Secure Software Life Cycle Standard: **Detailed test requirements and guidance added.
- **Software Security Framework Overview: **Additional details on the proposed validation program and a consolidated glossary of terms and definitions for the framework documents have been incorporated.

Feedback received during this RFC period will play an important part in finalizing the PCI Software Security Framework and the PA-DSS transition plan. PCI SSC plans to publish the two standards by the end of 2018, with the validation program to follow in 2019. PCI SSC will continue to keep stakeholders informed on the development process and publication timeline.

For additional background on the framework and its development, read PCI Perspectives Blog post [***3 Things to Know About the PCI Software Security Framework in 2018***](https://blog.pcisecuritystandards.org/3-things-to-know-about-the-pci-software-security-framework-in-2018).

[![Click Here to Provide Comments](https://no-cache.hubspot.com/cta/default/281302/4edbd2d1-4f1c-4d0b-a4e3-9056a5a9ed0d.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/4edbd2d1-4f1c-4d0b-a4e3-9056a5a9ed0d)

 

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Laura K. Gray](https://blog.pcisecuritystandards.org/hubfs/Headshots/laura-gray.jpg)

[ Laura K. Gray ](https://blog.pcisecuritystandards.org/author/laura-k-gray)

[Twitter ](https://www.twitter.com/pcissc) [Email](mailto:blog@pcisecuritystandards.org) [Website](http://www.pcisecuritystandards.org)

 The PCI Security Standards Council (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/final-request-for-comments-draft-pci-software-security-framework#)