惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
Y
Y Combinator Blog
I
InfoQ
美团技术团队
罗磊的独立博客
B
Blog RSS Feed
GbyAI
GbyAI
小众软件
小众软件
IT之家
IT之家
Engineering at Meta
Engineering at Meta
Blog — PlanetScale
Blog — PlanetScale
V
V2EX
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
Jina AI
Jina AI
MyScale Blog
MyScale Blog
博客园 - 聂微东
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
The GitHub Blog
The GitHub Blog
T
The Blog of Author Tim Ferriss

PCI Perspectives

Just Published: Security Considerations for AI Systems Just Published: PCI Key Management and Operations (KMO)™ Standard v1.0 The AI Exchange: Innovators in Payment Security Featuring Integrity360 Coffee with the Council Podcast: Celebrating 20 Years of Securing Payment Data The Quantum Leap: Preparing for Post Quantum Cryptography Featuring Futurex 2026 Asia-Pacific Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring GM Sectec Coffee with the Council Podcast: Meet This Year’s Europe Community Meeting Keynote Speaker, Ken Hughes Join Us at the Payment Industry Events of the Year Coffee with the Council Podcast: Meet This Year’s Asia-Pacific Community Meeting Keynote Speaker, CJ Meadows 2026 Europe Community Meeting Agenda Highlights The AI Exchange: Innovators in Payment Security Featuring atsec Mapping PCI DSS v4.0.1 to the NIST Cybersecurity Framework 2.0 2026 North America Community Meeting Agenda Highlights Meet the Council’s New Head of Business Operations and Risk Management The AI Exchange: Innovators in Payment Security Featuring PCA Cyber Security Enhance Your Community Meeting Experience with Interactive Workshops The AI Exchange: Innovators in Payment Security Featuring PROSA Bring PCI SSC Training to Your Organization with the New Training Venue Host Program The AI Exchange: Innovators in Payment Security Featuring Utimaco Coffee with the Council Podcast: Meet This Year’s North America Community Meeting Keynote Speaker, Sharon Gai Welcome Our Newest Associate Participating Organizations The AI Exchange: Innovators in Payment Security Featuring SecurityMetrics PCI SSC Publishes New Guidance on Compensating Controls and the Customized Approach Spotlight On: Dreamplug Technologies Private Limited (CRED), a New Principal Participating Organization Request for Comments: PCI Data Security Standard (PCI DSS) v4.0.1 The AI Exchange: Innovators in Payment Security Featuring In-Solutions Global Ltd Coffee with the Council Podcast: Nominate Now for the Global Executive Assessor Roundtable (GEAR) PCI SSC Publishes PCI PTS HSM v5.0 Request for Comments: PCI Secure Software Lifecycle Standard v2.0
PCI SSC Releases Version 2.0 of the PCI Secure Software S...
Alicia Malone · 2026-01-16 · via PCI Perspectives

The PCI Security Standards Council (PCI SSC) has published the first major revision to the PCI Secure Software Standard and its supporting Program Guide. This revision is the result of more than 18 months of collaboration with the PCI SSC stakeholder community.

The PCI Secure Software Standard helps provide assurance that software is designed, developed, and maintained in a manner that protects payment-related data and payment-related functionality.

Version 2.0 of the PCI Secure Software Standard includes a new companion document to help identify and document sensitive assets of the software. In addition, software development kits (SDKs) are now eligible to be assessed, which includes EMVCo© 3DS SDKs. The PCI Secure Software Standard v2.0 is intended to provide an alternate path for the assessment of 3DS SDKs, eventually replacing the need for the PCI 3DS SDK Standard to align with the PCI SSC roadmap initiatives for standards consolidation. As part of this transition, the PCI 3DS Data Matrix has been updated to version 1.2, which now includes information regarding 3DS SDK sensitive data elements.

Other highlights of the major revision include the introduction of the use of wildcards to account for non-security impacting software changes, a revised delta change process with a new change impact template, Portal access to submit annual attestations and administrative changes by the software vendor, and improved Portal and listing features.

The following documents are now available in the PCI SSC Document Library: 

  • PCI Secure Software Standard v2.0
  • PCI Secure Software Standard – Sensitive Asset Identification (for use with v2.x)
  • Summary of Changes from PCI Secure Software Standard v1.2.1 to v2.0
  • PCI Secure Software Program Guide (for use with v2.x)
  • PCI 3DS Data Matrix, v1.2  

The supporting v2.x ROV, AOV, and new Change Impact templates are expected to be available in early February 2026.

The v2.0 computer-based training (CBT) is expected to be available within Q1 of 2026 to support existing secure software assessors. Instructor-led training (ILT) is planned for Q2 to support new secure software assessors. Once training becomes available, a 12-month transition period from v1.2.1 to v2.0 will begin.    

The first major revision to the PCI Secure Software Lifecycle Standard will be released soon to complement the PCI Secure Software Standard as part of the PCI Software Security Framework. 

Download the PCI Secure Software Standard v2.0