Compensating Controls

PCIComplianceHubLast updated

Alternative controls used when an organization cannot meet a PCI DSS requirement as written because of a documented technical or business constraint. A compensating control must go beyond what the original requirement demands, address the extra risk the deviation creates, and be recorded in a Compensating Control Worksheet that an assessor reviews and validates at every assessment. Compensating controls are not the same as the Customized Approach introduced in v4.0: a compensating control exists because a requirement cannot be met, while the Customized Approach is a deliberate design decision to meet the requirement objective by a different method.

Applies to. Entities that cannot meet a requirement as written because of a documented, legitimate technical or business constraint, and that can put something else in place that goes beyond it.
Example. A legacy system cannot support a required authentication method and cannot be replaced before the assessment. The entity restricts and monitors access to it more tightly than the requirement asks, documents the constraint and the extra control on a Compensating Control Worksheet, and the assessor validates it.
Limits. Appendix B sets the conditions: the constraint is legitimate and documented, the control meets the intent and rigour of the original requirement, goes above and beyond it, addresses the additional risk, and is reviewed and validated at every assessment. A preference is not a constraint. It is not the customised approach, which is a deliberate design decision rather than a workaround.