If you’re evaluating a fleet card, loyalty or closed-loop payment platform, you’ve likely seen two acronyms in the vendor’s security documentation: PCI DSS and PCI SSF. Discover the difference between the two standards, why it matters when choosing a vendor, and the questions worth asking before you sign.
Introduction
PCI DSS and PCI SSF both come from the PCI Security Standards Council, but they certify different things, for different parties. Knowing the difference matters when you’re the one deciding which vendor handles your payment data.
PCI DSS: Securing the Environment
Payment Card Industry Data Security Standard (PCI DSS) applies to anyone who accepts, processes, stores or transmits cardholder data, merchants, service providers, acquirers. It covers the operating environment: networks, servers, access controls, encryption and monitoring.
Put simply, PCI DSS answers: is the building secure?
The standard is currently on version 4.0.1, mandatory since April 2025. The update added requirements around browser-layer security, including maintaining an inventory of scripts running on payment pages and detecting tampering with those scripts, a response to attacks increasingly targeting the client side rather than the server.
If your business processes card payments in any form, PCI DSS compliance sits with you, or with your acquirer depending on how your systems are set up.
PCI SSF: Securing the Software
Payment Card Industry Software Security Framework (PCI SSF) applies to the vendors who build the payment software itself, not the environment it runs in. It replaced PA-DSS, a standard retired in October 2022 because it was built for an era when payment software was installed on-premises rather than run in the cloud with continuous updates.
PCI SSF has two parts:
- Secure Software Standard. Assesses the software product itself, how it handles payment data and resists known attack patterns. A product that passes gets listed as “Validated” on the PCI SSC website.
- Secure Software Lifecycle (Secure SLC) Standard. Assesses the vendor’s development process, how code changes are reviewed, tested and released. This qualifies the organisation, not a single product version.
The second part is the one buyers tend to overlook. A product can pass a point-in-time security assessment and still ship a vulnerability in the next update if the vendor’s development process isn’t disciplined. Secure SLC certification tells you the vendor’s ongoing practices, not just today’s software version, are held to a standard.
What This Means When You’re Comparing Vendors
A few questions worth asking directly:
- Is the software validated under PCI SSF’s Secure Software Standard, and is that listing current?
- Is the vendor’s organisation Secure SLC qualified, or only the product?
- When was the last validation done, and against which version of the standard?
Watch for outdated references: if a vendor still references PA-DSS compliance, that’s a retired standard. It doesn’t automatically mean the software is insecure, but it does mean they haven’t gone through the current assessment. If your own RFP template still asks for PA-DSS, it’s worth updating to ask for PCI SSF instead.
Why It Matters for Closed-Loop Platforms Specifically
Closed-loop payment platforms sit at the centre of high-volume, real-time transaction authorisation, exactly the kind of software PCI SSF was built to assess. Certification here isn’t a formality; it’s evidence that security was part of how the platform was built, not added afterward.
Case in point: Cardtrend became the first company in ASEAN to achieve PCI SSF certification in 2022, and followed it with ISO 27001:2022 certification in 2024. Those aren’t just badges on a page, they’re the answer to the exact questions above.
Conclusion
PCI DSS tells you your environment is secure. PCI SSF tells you the software running in it was built and is maintained securely. A vendor evaluation that only checks one side of that is only doing half the job.
Contact Cardtrend today to learn how our PCI SSF certified platform can give your business the security assurance it needs, backed by a track record as ASEAN’s first PCI SSF certified provider.