Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
PCI SSF: Cybersecurity Controls
Technical cybersecurity measures (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-06 | Network security and segmentation |
| PCI-SSF-07 | Endpoint protection and detection |
| PCI-SSF-08 | Application security controls |
| PCI-SSF-09 | Encryption and key management |
| PCI-SSF-10 | Secure configuration standards |
PCI SSF: Incident Management & Reporting
Incident handling for financial services (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-21 | Incident detection and classification |
| PCI-SSF-22 | Incident response and containment |
| PCI-SSF-23 | Regulatory reporting requirements |
| PCI-SSF-24 | Customer notification procedures |
| PCI-SSF-25 | Post-incident review and improvement |
PCI SSF: Information Security Governance
IT governance for financial institutions (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-01 | Information security program management |
| PCI-SSF-02 | Board and management oversight |
| PCI-SSF-03 | Risk appetite and tolerance for IT risk |
| PCI-SSF-04 | Security policy framework |
| PCI-SSF-05 | Roles and responsibilities definition |
PCI SSF: Operational Resilience
Business continuity and resilience (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-11 | Business continuity planning and testing |
| PCI-SSF-12 | Disaster recovery procedures |
| PCI-SSF-13 | Third-party dependency management |
| PCI-SSF-14 | Critical service identification |
| PCI-SSF-15 | Communication and escalation procedures |
PCI SSF: Third-Party Risk Management
Managing vendor and supplier risks (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-16 | Due diligence and onboarding |
| PCI-SSF-17 | Contractual security requirements |
| PCI-SSF-18 | Ongoing monitoring and assessment |
| PCI-SSF-19 | Concentration risk management |
| PCI-SSF-20 | Exit strategy and transition planning |
Maps to 606 other frameworks
Frequently Asked Questions
What is PCI SSF?
PCI SSF is a compliance framework from International with 5 domains and 25 controls. PCI Software Security Framework It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does PCI SSF have?
PCI SSF has 25 controls organised across 5 domains. The largest domains are PCI SSF: Cybersecurity Controls (5 controls), PCI SSF: Incident Management & Reporting (5 controls), PCI SSF: Information Security Governance (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does PCI SSF map to?
PCI SSF maps to 606 other compliance frameworks. The top mapping partners are GLBA (64% coverage), HKMA SPM (64% coverage), OSFI B-13 (64% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with PCI SSF compliance?
Start your PCI SSF compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCI SSF requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required