PCI SSC Releases Version 2.0 of the Secure Software Lifecycle Standard
The PCI Security Standards Council (PCI SSC) has published the first major revision to the PCI Secure Software Lifecycle (Secure SLC) Standard and its supporting Program documents. The PCI Secure SLC Standard is one of two standards that are part of the PCI Software Security Framework (SSF). It provides security requirements and assessment procedures for software vendors to integrate into their software development lifecycles and to validate that secure lifecycle management practices are in place.
While the PCI Secure SLC Standard complements the PCI Secure Software Standard, neither standard requires an assessment to the other. However, vendors that have a listed and validated Secure SLC, and leverage it to develop their software products, are afforded program benefits for their associated listed and validated Secure Software Products.
Version 2.0 of the PCI Secure SLC Standard now aligns with version 2.0 of the PCI Secure Software Standard published earlier this year, which includes a focus on ‘sensitive assets’ and the new Sensitive Asset Identification Document (SAID). New content and requirements regarding the use of ‘digital tools’, which include accounting for artificial intelligence (AI) within a vendor’s Secure SLC processes, have also been added.
Overall, the Secure SLC Standard has been refocused solely on a software vendor’s Secure SLC, and the requirements within are objective to allow the necessary flexibility for each vendor, accommodating varying levels of maturity in their Secure SLC.
The following documents are now available in the PCI SSC Document Library:
- PCI Secure Software Lifecycle Standard v2.0
- Summary of Changes from PCI Secure Software Lifecycle Standard v1.1 to v2.0
- PCI Secure Software Lifecycle Program Guide (for use with v2.x)
- PCI Secure Software Lifecycle Report on Validation (ROV) template v2.0
- PCI Secure Software Lifecycle Attestation of Validation (AOV) template (for use with v2.x)
- PCI Software Security Framework – Assessor Qualification Requirements (2026)
The v2.0 computer-based training (CBT) is expected to be available in Q4 of 2026 to support existing Secure Software Lifecycle Assessors. Instructor-led training (ILT) is also planned for Q4 2026 to support new Secure Software Lifecycle Assessors. Once training becomes available, a 12-month transition period from v1.1 to v2.0 will begin.

