
What do you need to know about the Customized Approach before starting a PCI DSS audit?
25.09.2026
PCI DSS v4.0.1 allows organizations not only to meet the standard’s requirements but also to choose their own implementation method. This approach is called the Customized Approach.
Instead of using the solution specified by the standard, a company can develop its own control. However, simply implementing an alternative is not enough. You must describe how the solution works, assess the associated risks, and provide evidence of its effectiveness during the PCI DSS assessment.
Let’s take a look at how the Customized Approach works, what a company needs to prepare, what a Qualified Security Auditor (QSA) checks, and how this approach differs from Compensating Controls.
Two PCI DSS Approaches
PCI DSS provides for two ways to meet specific requirements: the Defined Approach and the Customized Approach. The main difference lies in who defines the controls and how the effectiveness of the solution is verified.
Defined Approach — the company implements the requirement in the manner specified by PCI DSS. The QSA verifies the solution using the testing procedures outlined in the standard.
Customized Approach — the company develops its own controls to achieve a specific security objective—the Customized Approach Objective. The QSA separately defines the procedures for verifying such a solution and tests its effectiveness.
|
Criterion |
Defined Approach |
Customized Approach |
|
What does the company do? |
Implements the requirement through a control defined by PCI DSS—Defined Requirement. |
Develops its own controls to achieve a security objective — Customized Approach Objective. |
|
Who defines the controls? |
The PCI SSC establishes the requirement, the expected control, and the standard assessment method. |
The organization itself develops and implements alternative controls. |
|
Testing procedures |
Predefined in the PCI DSS. |
The QSA develops assessment procedures for a specific control. |
|
Scope of Documentation |
Standard evidence of compliance—policies, configurations, logs, etc. |
Extended documentation package—control descriptions, Controls Matrix, targeted risk analysis, evidence of effectiveness, and other materials for assessment. |
When can a company choose the Customized Approach?
An organization cannot apply a customized approach to every PCI DSS requirement. This is possible only when the standard specifies a “Customized Approach Objective”—a security goal that must be achieved—for the relevant requirement.
PCI DSS defines the security objective, and the company can independently select the controls to achieve this objective and verify the effectiveness of the solution.
The Customized Approach is better suited for companies that:
The Self-Assessment Questionnaire (SAQ) cannot be used to demonstrate compliance under the Customized Approach. It is necessary to undergo a full assessment and prepare a Report on Compliance (ROC).
How to Demonstrate the Effectiveness of Controls
For each requirement that the company fulfills through the Customized Approach, the organization must prepare a separate set of supporting evidence:
The Controls Matrix describes the control’s purpose, scope, responsible parties, operating principle, monitoring methods, and link to the Customized Approach Objective.
The TRA explains which assets the control protects, from which threats and consequences, how the risk was assessed, and why the chosen solution ensures the desired outcome.
The document must be updated at least once every 12 months. The TRA is also reviewed following significant changes to the control, the operating environment, or related risks.
Documented evidence must be approved by the company’s senior management.
What Does a QSA Check During a Customized Approach?
A QSA auditor does not limit themselves to standard PCI DSS audit procedures. For the company’s own compliance, the auditor separately determines what needs to be checked and how.
As part of the audit, the QSA:
To conduct the audit, the QSA may analyze documentation and system configurations, interview employees, observe the control in operation, and review a sample of evidence.
This is why the Customized Approach typically requires more time and resources than the Defined Approach. It is not enough for a company to configure its controls just once. It must continuously gather evidence that the solution is working and remains effective.
Customized Approach vs Compensating Controls
These two approaches address different challenges. Compensating Controls are used when there is a documented technical or business constraint that prevents a PCI DSS requirement from being met in the prescribed manner.
The Customized Approach is used when a company deliberately chooses its own method of achieving a specific security objective.
|
Criterion |
Compensating Controls |
Customized Approach |
|
Reason for Selection |
A documented technical or business constraint that prevents the requirement from being met in a standard manner. |
The organization’s decision to implement its own control to achieve a specific security objective. |
|
Key Documentation |
Compensating Controls Worksheet (CCW). |
Controls Matrix and Targeted Risk Analysis. |
|
What Does the QSA Evaluate? |
The existence of the constraint, additional risks, the alignment of the compensating control with the objective of the original requirement, and the effectiveness of this solution. |
Whether the alternative control meets the Customized Approach Objective and whether its effectiveness has been verified. |
|
How is the audit conducted? |
The QSA applies the testing procedures defined for the original requirement and additionally evaluates the compensating control based on the CCW documentation. |
The QSA develops evaluation procedures tailored to the specific control, the associated risks, and the evidence provided. |
A lack of budget, unwillingness to comply with a requirement, or the absence of necessary controls are not grounds for applying Compensating Controls. There must be a verified technical or business constraint for this.
The CCW should describe:
Different approaches can be applied to a single requirement—depending on the system component. For example, the Defined Approach can be used for some servers, Compensating Controls for others, and the Customized Approach for cloud infrastructure.
Each option must be individually justified, documented, and evaluated.
One Requirement — 3 Ways to Implement It
Let’s consider PCI DSS requirement 5.2.1. It mandates protection against malware on all system components that could be infected.
Defined Approach
The company installs antivirus software or another form of malware protection on servers, workstations, and other systems as required.
The auditor verifies that the protection covers all required systems, is configured correctly, and is updated regularly. The auditor also reviews logs of scans, detected threats, and responses to them.
Compensating Controls
The company has an outdated server on which antivirus software cannot be installed due to technical limitations imposed by the manufacturer.
In this case, the organization documents this limitation in the CCW and implements other measures: it isolates the server on the network, blocks its access to the internet, and restricts administrator privileges. Additionally, the company monitors file transfers and collects logs in the security monitoring system.
The company must then demonstrate that these measures reduce the risk of infection and compensate for the lack of standard protection.
Customized Approach
The organization uses a cloud environment with microservices. Instead of traditional antivirus software, it allows only verified code to run, monitors code integrity, and tracks suspicious process behavior.
The system blocks unknown, unsigned, or modified code in accordance with established rules. The company documents its controls in the Controls Matrix, conducts a Targeted Risk Analysis (TRA), and collects evidence of the solution’s effectiveness.
The QSA separately determines the audit procedure and assesses whether this approach prevents malware infection or detects and blocks it in a timely manner.
How to Prepare for an Audit and Avoid Risks
The Customized Approach gives a company more flexibility in choosing controls. At the same time, it requires mature risk management, detailed documentation, continuous monitoring, and evidence of the effectiveness of its controls.
If a requirement can be met using a standard method, the Defined Approach is used. If a documented technical or business constraint prevents this, Compensating Controls may be applied. The Customized Approach is appropriate when a company has its own controls and can demonstrate that they achieve a specific security objective.
Are you planning to implement your own controls or preparing for a PCI DSS assessment? Contact us for a consultation to determine the appropriate approach, prepare the necessary evidence, and reduce the risk of non-compliance during the audit.
Author — Gennadiy Dmitriev, Information Technology Auditor, IT Specialist
IT Specialist – secure integration into the future.
Do you have any questions?
Fill out the feedback form, and our experts will provide advice as soon as possible.
