Customized Approach
PCIComplianceHubLast updated
A method introduced in PCI DSS v4.0 that lets an organization meet the stated objective of a requirement through controls of its own design, rather than by implementing the requirement exactly as written. It is aimed at mature environments using technologies or architectures the standard did not anticipate. Using it requires a targeted risk analysis, a documented controls matrix, and an assessor who derives and performs bespoke testing procedures. Not every requirement is eligible, and those that are not are marked in the standard. Because it depends on assessor-designed testing, the customized approach is used in assessments documented in a Report on Compliance rather than in a Self-Assessment Questionnaire. It is distinct from a compensating control, which exists because a requirement cannot be met at all.