PCI SSF is a compliance framework from International with 25 domains and 49 controls that map to 195 other frameworks. The largest domains are PCI SSF: Cybersecurity Controls (5 controls), PCI SSF: Incident Management & Reporting (5 controls), PCI SSF: Information Security Governance (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Access Control
| Code | Title |
|---|---|
| SSS-4.1 | Authentication and Access Control |
Account Data
Asset Management
Change Control
| Code | Title |
|---|---|
| SSLC-9.1 | Change Management |
Communication
| Code | Title |
|---|---|
| SSLC-11.1 | Stakeholder Communication |
Cryptography
| Code | Title |
|---|---|
| SSS-3.1 | Critical Asset Cryptographic Protection |
Data Protection
| Code | Title |
|---|---|
| SSS-2.1 | Sensitive Data Inventory and Protection |
Documentation
| Code | Title |
|---|---|
| SSS-8.1 | Vendor Security Guidance |
Governance
| Code | Title |
|---|---|
| SSLC-1.1 | Security Responsibility and Resources |
Implementation
| Code | Title |
|---|---|
| SSLC-6.1 | Secure Coding Practices |
Integrity
| Code | Title |
|---|---|
| SSLC-10.1 | Software Integrity |
PCI SSF: Cybersecurity Controls
Technical cybersecurity measures (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-06 | Network security and segmentation |
| PCI-SSF-07 | Endpoint protection and detection |
| PCI-SSF-08 | Application security controls |
| PCI-SSF-09 | Encryption and key management |
| PCI-SSF-10 | Secure configuration standards |
PCI SSF: Incident Management & Reporting
Incident handling for financial services (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-21 | Incident detection and classification |
| PCI-SSF-22 | Incident response and containment |
| PCI-SSF-23 | Regulatory reporting requirements |
| PCI-SSF-24 | Customer notification procedures |
| PCI-SSF-25 | Post-incident review and improvement |
PCI SSF: Information Security Governance
IT governance for financial institutions (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-01 | Information security program management |
| PCI-SSF-02 | Board and management oversight |
| PCI-SSF-03 | Risk appetite and tolerance for IT risk |
| PCI-SSF-04 | Security policy framework |
| PCI-SSF-05 | Roles and responsibilities definition |
PCI SSF: Operational Resilience
Business continuity and resilience (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-11 | Business continuity planning and testing |
| PCI-SSF-12 | Disaster recovery procedures |
| PCI-SSF-13 | Third-party dependency management |
| PCI-SSF-14 | Critical service identification |
| PCI-SSF-15 | Communication and escalation procedures |
PCI SSF: Third-Party Risk Management
Managing vendor and supplier risks (PCI SSF)
| Code | Title |
|---|---|
| PCI-SSF-16 | Due diligence and onboarding |
| PCI-SSF-17 | Contractual security requirements |
| PCI-SSF-18 | Ongoing monitoring and assessment |
| PCI-SSF-19 | Concentration risk management |
| PCI-SSF-20 | Exit strategy and transition planning |
Policy Management
| Code | Title |
|---|---|
| SSLC-2.1 | Software Security Policy |
Risk Management
| Code | Title |
|---|---|
| SSLC-4.1 | Threat Identification and Risk Mitigation |
Secure Design
| Code | Title |
|---|---|
| SSLC-5.1 | Software Design Security |
Terminal Software
| Code | Title |
|---|---|
| SSS-11.1 | Terminal Software Module Requirements (Module B) |
Testing
| Code | Title |
|---|---|
| SSLC-7.1 | Security Testing |
Threat Detection
| Code | Title |
|---|---|
| SSS-5.1 | Attack Detection |
Update Management
Vulnerability Management
Workforce
| Code | Title |
|---|---|
| SSLC-3.1 | Software Security Personnel Skills |
Your Compliance Coverage
If you comply with PCI SSF, you already cover:
PSD2 SCA
33%
16 controls mapped
Compare →FFIEC IT Examination Handbook
33%
16 controls mapped
Compare →PCI PIN Security
33%
16 controls mapped
Compare →+ 192 more: PCI P2PE (33%), Singapore Government Instruction Manual on ICT&SS Management (IM8) (29%)
See all 195 mapped frameworks ↓Maps to 195 other frameworks
What is PCI SSF and who does it apply to?
PCI SSF is a compliance framework from International with 25 domains and 49 controls. PCI Software Security Framework It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does PCI SSF actually require?
PCI SSF has 49 controls organised across 25 domains. The largest domains are PCI SSF: Cybersecurity Controls (5 controls), PCI SSF: Incident Management & Reporting (5 controls), PCI SSF: Information Security Governance (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of PCI SSF do I already cover?
PCI SSF maps to 195 other compliance frameworks. The top mapping partners are PSD2 SCA (33% coverage), FFIEC IT Examination Handbook (33% coverage), PCI PIN Security (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement PCI SSF?
Start your PCI SSF compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PCI SSF requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 49 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required