Customized Approach

PCIComplianceHubLast updated

A method introduced in PCI DSS v4.0 that lets an organization meet the stated objective of a requirement through controls of its own design, rather than by implementing the requirement exactly as written. It is aimed at mature environments using technologies or architectures the standard did not anticipate. Using it requires a targeted risk analysis, a documented controls matrix, and an assessor who derives and performs bespoke testing procedures. Not every requirement is eligible, and those that are not are marked in the standard. Because it depends on assessor-designed testing, the customized approach is used in assessments documented in a Report on Compliance rather than in a Self-Assessment Questionnaire. It is distinct from a compensating control, which exists because a requirement cannot be met at all.

Applies to. Entities with mature risk management that want to meet a requirement's stated objective by a different control. Only for requirements that permit it; those that do not are marked in the standard.
Example. A requirement calls for a review at a set interval that a highly automated environment meets continuously by other means. The entity documents the control, performs a targeted risk analysis under 12.3.2, and its assessor derives tests for the control as built.
Limits. It is not a lighter option. Appendix D sets out what the entity must provide, including a controls matrix and a targeted risk analysis, and the assessor must derive and perform bespoke testing procedures, which is why it belongs in assessments reported on a ROC rather than in a self-assessment. It is distinct from a compensating control, which exists because a requirement cannot be met; the customised approach is a design choice to meet the objective differently.
In PCI DSS v4.0.1. 12.3.2