Answers to the questions practitioners most commonly ask about Defined Approach.
Is the Defined Approach the same as the old, pre-existing way of validating PCI DSS, meaning it is being phased out?
No. The Defined Approach reflects the traditional method of meeting a requirement by implementing the controls exactly as stated and validating against the stated testing procedures, but it remains a fully supported and valid validation method. It sits alongside the Customized Approach as one of two ways an entity may meet applicable requirements, rather than being a deprecated predecessor. Confirm the specifics against the current published version of PCI DSS, since wording and structure differ between versions.
Does choosing the Defined Approach mean an assessor has no discretion and simply checks a box?
Not exactly. The Defined Approach uses the prescribed requirements and their associated testing procedures, which gives a consistent, well-established basis for assessment. However, the assessor still gathers and evaluates evidence to determine whether the control is properly implemented and effective in the assessed environment. The structured nature of the approach reduces ambiguity but does not remove the need for the assessor to examine evidence and exercise professional judgment about whether the requirement is met.
How do I decide between the Defined Approach and the Customized Approach for a given requirement?
The choice is made per requirement, not for the whole assessment. Many entities use the Defined Approach for most requirements because it is prescriptive and well understood, and consider the Customized Approach only where they meet the requirement's objective through controls that differ from the stated ones. Factors include the maturity of your control documentation, your ability to support the additional analysis the Customized Approach requires, and your assessor's and stakeholders' expectations. Review the current standard to confirm how each approach is documented and validated.
What documentation should I prepare when validating a requirement under the Defined Approach?
Prepare evidence that maps to each stated testing procedure for the requirement, such as configurations, policies, procedures, records, and interviews that demonstrate the control is implemented as described. Because the Defined Approach relies on the prescribed testing procedures, aligning your evidence to those procedures helps the assessor evaluate the requirement efficiently. Confirm the exact testing procedures against the current published version, since numbering and wording vary between versions.
Can I mix the Defined Approach and the Customized Approach within the same assessment?
Yes, the choice is generally made on a per-requirement basis, so an entity can meet some requirements using the Defined Approach and others using the Customized Approach. This lets an organization keep the prescriptive method where it fits and apply customization only where its controls differ from the stated ones. Document which approach applies to each requirement and validate accordingly, following the current standard's guidance for each method.
How does using the Defined Approach affect the reporting for an assessment?
When a requirement is met using the Defined Approach, it is documented and reported against the stated requirement and its testing procedures, reflecting that the prescribed controls were assessed as implemented. This differs from the Customized Approach, which involves additional analysis and documentation to show the requirement's objective is met by alternative controls. Follow the reporting templates and instructions in the current published version of PCI DSS to ensure the approach used is recorded correctly for each requirement.