Defined Approach

PCIComplianceHubLast updated

The traditional method of meeting PCI DSS, in which an organization implements each requirement as written and the assessor tests it against the defined testing procedures published in the standard. It remains the default, and it is the only route available to an organization completing a Self-Assessment Questionnaire. Compensating controls are available under the defined approach; they have no equivalent under the Customized Approach.