PCI SSF
What is PCI SSF?
PCI Software Security Framework. It comprises 49 controls organised across 25 domains, published by PCI Security Standards Council, and applies in International.
How PCI SSF maps to other frameworks
All 49 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 25 domains PCI SSF groups its controls into
Where PCI SSF overlaps with the standards you already hold
What PCI SSF means in your sector
What PCI SSF means for your job
Questions people ask about PCI SSF
What is PCI SSF?
How many controls does PCI SSF have?
Where does PCI SSF apply?
What frameworks does PCI SSF map to?
How do I get started with PCI SSF compliance?
Query PCI SSF programmatically
PCI SSF, its 49 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
PCI SSF API reference and MCP config →What PCI SSF requires, control by control
Each page carries the requirement text for one PCI SSF control and what an assessor expects to see as evidence.
- PCI-SSF-03 Risk appetite and tolerance for IT risk
- PCI-SSF-05 Roles and responsibilities definition
- PCI-SSF-06 Network security and segmentation
- PCI-SSF-07 Endpoint protection and detection
- PCI-SSF-08 Application security controls
- PCI-SSF-09 Encryption and key management
- PCI-SSF-10 Secure configuration standards
- PCI-SSF-11 Business continuity planning and testing
- PCI-SSF-12 Disaster recovery procedures
- PCI-SSF-14 Critical service identification
How ready are you for PCI SSF?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.