PA-DSS (Payment Application Data Security Standard)

PCIComplianceHubLast updated

A retired standard that set security requirements for commercially sold payment applications handling cardholder data. PA-DSS closed on 28 October 2022 and was replaced by the PCI Software Security Framework, made up of the Secure Software Standard and the Secure Software Lifecycle (Secure SLC) Standard. Applications previously validated under PA-DSS moved to an acceptable-only-for-pre-existing-deployments list, and all new validations are performed under the Software Security Framework.