The PCI Security Standards Council has released version 2.0 of the PCI Secure Software Standard, marking the first major revision since its introduction in 2019. This significant update introduces new requirements and enhanced security measures for organizations developing payment software applications.
The PCI Security Standards Council (PCI SSC) has announced the release of version 2.0 of the PCI Secure Software Standard, representing the most significant update to the standard since its initial publication in 2019. This milestone update, discussed in the Council's "Coffee with the Council" podcast series, introduces substantial changes that will impact software vendors and organizations handling payment card data.
The Secure Software Standard v2.0 builds upon seven years of industry feedback and evolving threat landscapes. While specific details of the changes weren't fully outlined in the initial announcement, major revisions typically include:
The updated standard primarily impacts:
Organizations currently certified under the previous version will need to plan for transition to the new requirements. Typically, PCI SSC provides implementation timelines that allow for:
This major revision reflects the Council's commitment to staying ahead of evolving cybersecurity threats in the payment industry. The update likely addresses:
The release of version 2.0 signals the PCI SSC's proactive approach to payment security in an increasingly complex digital landscape. Organizations should expect this update to drive industry-wide improvements in software security practices and potentially influence other security frameworks.
The timing of this release at the beginning of 2026 suggests organizations will need to prioritize compliance planning as part of their annual security strategies. Companies that proactively adopt these enhanced standards will likely gain competitive advantages through improved security postures and customer trust.
PCI Secure Software Standard v2.0 is the first major revision since 2019, establishing enhanced security requirements for organizations developing and maintaining payment software applications.
While specific implementation timelines haven't been announced, organizations typically receive 12-18 months to transition from previous versions to new PCI standards requirements.
Software vendors, payment processors, merchants using payment software, financial institutions, and third-party developers creating payment-related applications must comply with the standard.
The Secure Software Standard focuses specifically on secure software development practices, while PCI DSS covers broader data security requirements for organizations handling cardholder data.
Benefits include enhanced payment security, reduced vulnerability risks, improved customer trust, regulatory compliance, and competitive advantages through demonstrated security commitment.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free