Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

PCI SSF Validation

The PCI SSF (Secure Software Framework) aims to directly address security associated with software vendors providing products that store, process, or transmit cardholder data.

Contact a Specialist

SSF Middle

What is PCI SSF?

The PCI Secure Software Framework (SSF) is a set of standards currently made up of the PCI Secure Software Lifecycle (PCI SSLC) and the PCI Secure Software Standard (PCI SSS). Currently, there are two (2) standards under PCI SSF; however, this is dynamic and in the future there may be others that get added to better suit the needs of different software vendors and entities.

The PCI SSLC standard is for companies that would like to test and show their observance to secure development lifecycles.

The PCI SSS is for companies looking to validate a specific piece of software (similar to PA-DSS) and will undergo a rigorous examination including hands-on application testing for the specific product.

Both standards will result in a listing on the PCI SSC website. PCI SSLC will list the company, the products developed under these processes, and what kind of product categories the vendor develops. the PCI SSS will result in a list of the specific products that were validated.

SSF Middle

Our Process

We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.

Image

Planning

After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the Client are fully aware of the what, who, when, why, and how prior to the beginning of testing.

Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.

Image

Understanding and Kickoff

The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the client with any questions.

By including communication prior to starting, Schellman ensures that no last-minute changes to the project or team have occurred and the Client has the plan prior to the testing and on-site visit.

Image

Testing and Gathering

Testing and gathering is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of gathering the evidence needed for the objectives discussed.

Schellman has a no surprise policy and has daily contact with the stakeholders during the testing and gathering activities. Furthermore, Schellman will begin documentation of the draft deliverable to be able to provide it to the Client efficiently after this phase. The Client will have confidence the Schellman team has completed this phase timely and completely.

Image

Reporting

Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.

Schellman’s report takes into account the entire process and customizes a report for each Client. The draft report will be provided within 2 weeks of the last day of testing and gathering phase, and a final report will be provided within 30 days. This timing is unsurpassed by the industry.

Frequently Asked Questions

Have a question? See a list of commonly asked questions below. If you still can't find an answer, contact us!

What exactly is the PCI SSF?

Does the PCI SSF apply to all payment software developed? Is it now a part of the PCI DSS for companies who internally develop their own payment software?

I am a merchant. Does the credit card payment software I purchased have to be validated under the PCI SSS?

Does the PCI SSF replace the PA-DSS?

If my application was validated under the PA-DSS, will it be automatically validated under the PCI SSS?

If my company develops payment applications, do I have to be validated for both SSF standards (Secure SLC and SSS) or can I just have my individual applications be validated under the SSS?

If my company develops many applications, will we have to be validated under the Secure SLC for every application?

I read that the PCI SSF uses an “objective-based approach” to the requirements. What does that mean?

Our company’s payment applications were validated under the PA-DSS. What should we be doing to transition to the SSF?

Your PCI SSF Specialist,
Joe O'Donnell

Joe O'Donnell is a Manager with Schellman mainly dedicated to the PCI and PCI specialty service lines. Before focusing his career on IT auditing services, Joe worked as an Enterprise Operations Computing Analyst where he gained experience in IT systems analysis and data center operations.
  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

How much will your audit cost?

Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.

The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.

Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing:

  • Fixed-Fee Using an outcome-based, fixed-fee pricing model based on our extensive experience
  • Scope Creep We see less than 5% of our clients that see amendments and are often the result of a scope expansion
  • Low Overhead Low overhead means a flexible financial structure

Contact Us

Fill out this form to talk with one of our specialists. We'll be in touch soon to continue the conversation and help you find what you're looking for.

Contact Us

Fill out this form to talk with one of our specialists. We'll be in touch soon to continue the conversation and help you find what you're looking for.