Secure SLC (Secure Software Lifecycle Standard)

PCIComplianceHubLast updated

The half of the PCI Software Security Framework that assesses how a vendor builds software rather than the finished product: threat modelling, secure design, code review, vulnerability management and change control across the development lifecycle. A vendor with Secure SLC qualification can self-attest to certain low-impact changes without a full reassessment of the product, which is what makes frequent release cycles workable under the framework.