From 11 March to 11 April, eligible PCI SSC stakeholders are invited to review and provide feedback on the currently published version of the PCI Secure Software Standard during a 30-day request for comments (RFC) period.
The RFC will be available through the PCI SSC portal, including instructions on how to access the documents and submit feedback. Eligible stakeholders will also receive instructions via email. As a reminder, participants are required to accept a Non-Disclosure Agreement (NDA) to download the document. Please review the RFC Process Guide for more information.
Please note that PCI SSC can only accept comments that are submitted via the PCI SSC portal and received within the defined RFC period.
Background on the PCI Secure Software Standard
PCI SSC is planning a revision to the currently published version of the Secure Software Standard v1.2.1 and its supporting Program documentation. The PCI Secure Software Standard is one of two standards in the PCI Software Security Framework (SSF). The PCI Secure Software Standard and associated security requirements help ensure that payment software is designed, developed, and maintained in a manner that protects payment transactions and data, minimizes vulnerabilities, and defends the software from attacks.