Generally speaking, the actions permitted to be conducted by a Secure SLC Qualified Vendor are similar to the permitted wildcard activities that were allowed under the PA-DSS program (retiring on June 30, 2021), but are expanded in several ways.
What are some other benefits of being listed on the PCI Security Standards Council list of approved solutions as a Secure SLC Qualified Vendor?
- Upon completion of the initial assessment, the SSF assessor will submit necessary documents, and the company will be listed on the PCI SSC as being a Secure SLC Qualified Vendor
- Listed Secure SLC Qualified Vendors will be empowered to perform and self-attest to their own software “delta” assessments (as part of validation of their payment software products to the Secure Software Standard) with reduced assessor involvement or oversight.
- Secure SLC Qualified Vendors can perform their own annual revalidation and designated change validations without involving a SLC security assessor.
- Secure SLC Qualified Vendors can login and make administrative changes to their own listings on the PCI SSC web site without involving a SLC security assessor.
Datassurant is a long-time leader in information, data and application security and compliance services. Datassurant is an expert in providing your organization with high quality payment application gap-analysis, payment application testing, code review, software security guidance documentation assistance and several other key Secure Software Standard (SSF) and Secure Software Lifecycle Standard (SLC) related services.
For further details, please contact us.
Cloud
Solutions
and Testing





