---
title: "Request for Comments: PCI Secure Software Standard v1.2.1 "
description: From 11 March to 11 April, eligible PCI SSC stakeholders are invited to review and provide feedback on the currently published version of the PCI Secure Software Standard during a 30-day request for comments (RFC) period.
image: https://blog.pcisecuritystandards.org/hubfs/RFC-Secure-Software-Standard.jpg
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1#)

# [Request for Comments: PCI Secure Software Standard v1.2.1 ](https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1)

 Posted by [Alicia Malone](https://blog.pcisecuritystandards.org/author/alicia-malone) on 11 Mar, 2024 in [Software Product Family](https://blog.pcisecuritystandards.org/topic/software-product-family) and [Participation](https://blog.pcisecuritystandards.org/topic/participation) and [Request for Comments](https://blog.pcisecuritystandards.org/topic/request-for-comments) and [Software Security Framework](https://blog.pcisecuritystandards.org/topic/software-security-framework)

![RFC-Secure-Software-Standard](https://blog.pcisecuritystandards.org/hs-fs/hubfs/RFC-Secure-Software-Standard.jpg?width=800&name=RFC-Secure-Software-Standard.jpg "RFC-Secure-Software-Standard")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1&url=https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1&source=tweetbutton&text=Request%20for%20Comments:%20PCI%20Secure%20Software%20Standard%20v1.2.1 > 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1)

From 11 March to 11 April, eligible PCI SSC stakeholders are invited to review and provide feedback on the currently published version of the PCI Secure Software Standard during a 30-day request for comments (RFC) period.    * *

The RFC will be available through the [PCI SSC portal](https://programs.pcissc.org/), including [instructions](https://www.pcisecuritystandards.org/wp-content/uploads/2024/03/READ-ME-FIRST-SSW-v1_2_1-RFC-Q22024.pdf) on how to access the documents and submit feedback. Eligible stakeholders will also receive instructions via email. As a reminder, participants are required to accept a Non-Disclosure Agreement (NDA) to download the document. Please review the [RFC Process Guide](https://listings.pcisecuritystandards.org/pdfs/RFC_Process_Guide.pdf) for more information.    

*Please note that PCI SSC can only accept comments that are submitted via the PCI SSC portal and received within the defined RFC period.    *

Background on the PCI Secure Software Standard 

PCI SSC is planning a revision to the currently published version of the Secure Software Standard v1.2.1 and its supporting Program documentation. The PCI Secure Software Standard is one of two standards in the [PCI Software Security Framework (SSF)](https://docs-prv.pcisecuritystandards.org/Software%20Security/General%20Guidance/SSF_At-a-Glance.pdf). The PCI Secure Software Standard and associated security requirements help ensure that payment software is designed, developed, and maintained in a manner that protects payment transactions and data, minimizes vulnerabilities, and defends the software from attacks. 

[![ Access the PCI SSC Portal and Provide Comments](https://no-cache.hubspot.com/cta/default/281302/51578da7-75d0-48e0-b1c3-d6343c04cc60.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/51578da7-75d0-48e0-b1c3-d6343c04cc60)

 

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Alicia Malone](https://blog.pcisecuritystandards.org/hubfs/Malone%2c%20Alicia.jpg)

[ Alicia Malone ](https://blog.pcisecuritystandards.org/author/alicia-malone)

[Email](mailto:amalone@pcisecuritystandards.org)

 As Director, Communications/Public Relations for PCI SSC, Ms. Malone develops and executes proactive communications and stakeholder engagement programs to educate and drive global collaboration in the payments industry.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/request-for-comments-pci-secure-software-standard-v1-2-1#)