Skip to content

PCI SSC

What is PCI SSC?

The Payment Card Industry Security Standards Council, responsible for developing and managing PCI security standards including PCI DSS.

Compliance and Regulatory

What the standards actually require on pci ssc

Requirements naming pci ssc across 3 standards, quoted from the control text.

PCI DSS 4.01 control

External vulnerability scans are performed at least once every three months by a PCI SSC Approved Scanning Vendor (ASV) with passing scans achieved.

11.3.2 · External vulnerability scans quarterly by ASV
PCI P2PE1 control

P2PE solutions must undergo annual reassessment by a P2PE QSA and any significant change to the solution must trigger reassessment of affected domains and updates to the listing on the PCI SSC website.

Domain-6.2 · Annual Reassessment and Change Management
PCI SSF1 control

The vendor must maintain effective communication with stakeholders including customers, partners, and PCI SSC regarding security-relevant matters, software releases, and vulnerability information.

SSLC-11.1 · Stakeholder Communication

Questions people ask about pci ssc

What is PCI SSC?
The Payment Card Industry Security Standards Council, responsible for developing and managing PCI security standards including PCI DSS.
Why is PCI SSC important for compliance?
PCI SSC is a key concept in Compliance and Regulatory. Understanding pci ssc helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address PCI SSC?
PCI SSC appears in the requirement text of PCI DSS 4.0, PCI P2PE, PCI SSF. Across these standards we have identified 3 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about PCI SSC?
Explore our compliance framework pages to see how pci ssc applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how PCI SSC applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.