Get Demo
↑

PCI DSS Customized Approach vs Defined Approach

What the PCI DSS Customized Approach is per Appendix D, how it differs from the Defined Approach, eligibility limits, and how Requirement 12.3.

Published: September 2026 Compliance · PCI DSS 8–12 min read

PCI DSS v4.x offers two ways to meet most requirements: the Defined Approach (implement the prescribed control and testing procedures) or the Customized Approach (meet the requirement’s stated Customized Approach Objective with entity-designed controls). This page follows Appendix D of PCI DSS v4.0.1 and Requirement 12.3.2.

Related: TRA required elements · 51 future-dated IDs · What is PCI DSS v4.0.1 · 12-requirement hub · Gap assessment.

Not a shortcut: Customized controls are expected to meet or exceed the security provided by the Defined Approach requirement. Documentation and assessor-derived testing are heavier than following the Defined Approach.

What Appendix D Says

Appendix D states the Customized Approach is for entities that meet a requirement’s stated Customized Approach Objective in a way that does not strictly follow the defined requirement. The entity designs the security controls needed to meet that objective for its organization.

Per Appendix D, the entity must:

The assessor must review that evidence, derive and document appropriate testing procedures, test each customized control against the Customized Approach Objective, and document results in the ROC (including ROC Appendix E). QSAs must maintain independence: a QSA involved in designing or implementing a customized control must not also assess that control.

Defined Approach vs Customized Approach

Aspect
Defined Approach
Customized Approach
Focus
Prescribed requirement text and Defined Approach testing procedures
Stated Customized Approach Objective for that requirement
Testing procedures
Published in the standard
Assessor-derived for the specific implementation
Security bar
Implement as written
Meet or exceed Defined Approach protection
Documentation
Policies, configs, and evidence for the defined control
Controls matrix + 12.3.2 TRA + testing + ongoing monitoring evidence
Intended for
Most entities following the traditional path
Risk-mature entities with robust risk management

Entities following the Defined Approach may use the Customized Approach Objective as guidance, but the objective does not replace or supersede the Defined Approach Requirement.

Eligibility Limits

Requirement 12.3.2 — Immediate When Customized Is Used

12.3.2 is not a future-dated requirement. The Summary of Changes from v3.2.1 to v4.0 marks it effective immediately for entities undergoing a v4.x assessment and using a customized approach. It is not in the 51 March 31, 2025 IDs.

When Customized is used, 12.3.2 requires a targeted risk analysis for each PCI DSS requirement met that way, including:

Full element lists for 12.3.1 (frequency flexibility) and 12.3.2 (Customized) are on the TRA required-elements page. In v4.0.1, Appendix E points to sample templates on the PCI SSC website: template format is optional; the information those templates define is still required.

How CyberSilo Helps

Decide Defined vs Customized Per Requirement

Map where Customized is worth the documentation cost — and where the Defined Approach is the clearer path for v4.0.1 assessments.

Frequently Asked Questions

Can an SAQ merchant use the Customized Approach?

No. Entities that complete a Self-Assessment Questionnaire are not eligible to use a customized approach. They may elect to have a QSA or ISA perform the assessment and document it in a ROC Template.

Is Requirement 12.3.2 future-dated until March 31, 2025?

No. 12.3.2 is effective immediately for entities using the Customized Approach. It is not part of the 51 future-dated requirement IDs.

Can compensating controls be used with the Customized Approach?

No. Appendix D states compensating controls are not an option with the customized approach.

TRA required elements · 51 future-dated IDs · What is PCI DSS v4.0.1 · 12-requirement hub · Gap assessment · PCI DSS hub