Skip to site content

What regulatory frameworks apply to financial services software?

Financial services software faces a dense regulatory environment. Relevant frameworks typically include:

  • PCI DSS: Required for any system that stores, processes, or transmits payment card data. PCI DSS v4.0.1 is the current active standard as of 2025.
  • SOC 2: Required by most enterprise customers and financial institutions as a baseline for third-party vendors.
  • SOX (Sarbanes-Oxley): Requires public companies to maintain effective internal controls over financial reporting, which extends to the software that supports those processes.
  • GLBA (Gramm-Leach-Bliley Act): Requires financial institutions to protect customer financial information.
  • NIST standards: Widely referenced as best practices across financial services.

A code audit maps your software against the specific controls each applicable framework requires and identifies the gaps that pose the most risk.

Reference
PCI DSS Document Library – PCI Security Standards Council – pcisecuritystandards.org