Back to Field Notes
International Standards/Field Note

PCI DSS 4.0 — The Customized Approach Demystified

The Customized Approach is the biggest change in PCI DSS in a decade — but only mature programs should use it. Here is the bar.

Author

Mark Velasquez

Principal Standards Architect

Published

January 4, 2026

Read

10 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01PCI DSS 4.0 became fully effective March 2025. The Customized Approach lets you meet a requirement's intent with your own design — at a significantly higher burden of proof than the Defined Approach.
  • 02Required artifacts to use the Customized Approach: a documented Targeted Risk Analysis, an assessor-testable control description, specified test procedures, operating-effectiveness evidence over the assessment period, and annual re-evaluation.
  • 03Use it where you have a defensibly modern control the standard does not anticipate (passkey-only authentication exceeding MFA, RASP in lieu of WAF for specific assets). Do NOT use it to skip controls you find inconvenient.
  • 04Targeted Risk Analyses are now required even in the Defined Approach for several requirements (anti-malware, log review cadence, scan cadence for non-CDE). Build a TRA template once, run it annually.

PCI DSS 4.0, fully effective March 2025, introduced the Customized Approach: an alternative to the prescriptive Defined Approach where you can demonstrate that your control design meets the stated 'Customized Approach Objective' for a requirement, even if you do not implement the standard's defined testing procedure.

It sounds liberating. In practice it raises the burden of proof significantly.

What the Customized Approach actually requires

  • 01A documented Targeted Risk Analysis (TRA) for the requirement
  • 02A control description sufficient for an independent assessor to test
  • 03Specific test procedures the assessor will perform
  • 04Evidence of operating effectiveness over the assessment period
  • 05Annual re-evaluation of the customized control

When to use it — and when not to

Use the Customized Approach where you have a defensible, modern control that the standard's prescriptive language does not anticipate — for example, a passkey-only authentication flow that exceeds the multi-factor requirement, or runtime application self-protection in place of a traditional WAF for specific assets.

Do not use it as a way to skip a control you find inconvenient. Assessors are explicitly trained to scrutinize customized controls more than defined ones.

Targeted Risk Analyses are the new normal

Even in the Defined Approach, several requirements (anti-malware, log review frequency, vulnerability scanning frequency for non-CDE systems) now require a TRA to set the cadence. Build a TRA template once, run it annually, and you eliminate one of the most common 4.0 findings.

#PCI DSS#Payments#Compliance

/WRITTEN_BY

Mark Velasquez

Principal Standards Architect · Alexa Cybersecurity