Customized Approach Objective

PCIComplianceHubLast updated

The security outcome a PCI DSS requirement is intended to achieve, stated in the standard alongside each eligible requirement. Under the Customized Approach an organization is not implementing the requirement as written, so the objective becomes the thing it must demonstrate it meets. Requirements published without a customized approach objective are not eligible for the customized approach.