PCI Rewrites Its Secure Software Standard (09/28/2026)
- › PCI SSC released version 2.0 of the Secure Software Lifecycle Standard, its first major revision, aligned with the Secure Software Standard v2.0.
- › The new version adds a sensitive asset identification document and addresses AI and other digital tools in vendor development processes.
- › The 12 month transition from version 1.1 starts once training is available, which PCI SSC expects in the fourth quarter.
- › The SEC settled charges with Zoe Financial for failing to fully disclose conflicts of interest to clients.
- › Standard know-your-customer screening can miss ownership connections in Mexico, which puts more weight on deeper diligence.
The PCI Security Standards Council has rewritten the standard that governs how payment software vendors build their products, and the new version asks those vendors to account for AI in their development process. If you buy payment software, this changes what you can reasonably ask your vendor to show you. If you build it, the transition clock starts once training is available later this year.
Top 5 Critical Compliance Alerts
1. PCI SSC Releases Secure Software Lifecycle Standard v2.0
PCI SSC published version 2.0 of the Secure Software Lifecycle Standard, the first major revision, aligned with the Secure Software Standard v2.0 released earlier in 2026, per the PCI SSC Blog. The new version centers on sensitive assets through a Sensitive Asset Identification Document, adds content on the use of digital tools including AI within vendor processes, and focuses on objective requirements that allow for different maturity levels. Computer-based and instructor-led training are expected in the fourth quarter of 2026, and the 12 month transition from version 1.1 begins once training is available.
Operator Note: If your payment software vendor uses AI coding tools, this standard gives you a basis to ask how that use is governed. Add the question to your next vendor review.
2. SEC Settles Conflict of Interest Charges With Zoe Financial
The SEC announced settled charges against New York investment adviser Zoe Financial for failing to fully and fairly disclose material facts about conflicts of interest, per the SEC. This follows last week’s action against OTC Link and the risk alert on adviser compliance reviews, which makes disclosure of conflicts a clear current priority.
3. Federal Officials Put Cybercrime Squarely on Compliance’s Desk
Federal officials are making the case that cybersecurity is an ethics and compliance concern and not a problem to hand entirely to IT, per Corporate Compliance Insights. Compliance teams that already run investigations, hotlines, and third-party diligence have most of the muscles this needs.
4. Standard Due Diligence Can Miss Ownership in Mexico
Know-your-customer screening does not always reveal the ownership connections that matter in Mexico, per Corporate Compliance Insights. Database checks confirm what is registered, and in some markets the risk sits in what is not.
Operator Note: Where screening comes back clean on a high-risk counterparty, that tells you what the databases know. Budget for local enhanced diligence on the relationships where the exposure justifies it.
5. A California Critical Access Hospital Reports a Cyber Incident
Modoc Medical Center and Vista Del Mar Child and Family Services in California are among the organizations announcing breaches, per the HIPAA Journal. Critical access hospitals are small rural facilities, usually with lean IT staffing, and an outage there can mean patients travel much farther for care.
Additional Compliance Alerts
Regulatory Updates
- A reminder that Texas’s AI law has been in force since January: An explainer on the Texas Responsible Artificial Intelligence Governance Act, which took effect January 1, 2026. JD Supra
- The SEC enforcement director reflects on a transitional year: Director David Woodcock’s September 18 remarks on the fiscal year closing out for the Division. JD Supra
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.