Prioritized Approach
The Prioritized Approach is a roadmap published by the PCI Security Standards Council that helps organizations work toward PCI DSS compliance by tackling security activities in order of risk. It groups compliance tasks into milestones so an organization can address the most critical areas first, achieve early wins, and show measurable progress. It is a supporting tool and does not change or replace the PCI DSS requirements themselves.
The Prioritized Approach is a PCI SSC-provided framework and accompanying tool that maps PCI DSS requirements into a sequence of risk-based milestones for organizations storing, processing, and/or transmitting cardholder data. It is intended to help entities prioritize activities, achieve incremental risk reduction, and demonstrate compliance progress; for example, one milestone focuses on removing sensitive authentication data and limiting data retention, which targets a key area of risk for compromised entities. The Prioritized Approach and its associated summary/attestation documents assist compliance efforts but do not modify, supersede, or reduce the obligations defined in the PCI DSS itself, and milestone structure and requirement wording differ across PCI DSS versions—readers should confirm details against the current published standard and the version-specific Prioritized Approach document.
Why it matters
PCI DSS compliance can involve a large number of requirements spanning network security, access control, monitoring, and data protection, and organizations working toward validation often need a way to sequence that work rather than attempting everything at once. The Prioritized Approach addresses this by organizing compliance activities into risk-based milestones, so entities can focus first on the areas that most reduce risk to cardholder data. This helps teams achieve early, measurable progress and communicate that progress to acquirers, processors, and internal stakeholders during a multi-stage compliance effort.
The ordering is significant because it reflects where risk tends to concentrate. For example, one milestone focuses on removing sensitive authentication data and limiting data retention, which the PCI SSC identifies as a key area of risk for entities that have been compromised. Sensitive authentication data—such as full track data, card verification values, and PINs or PIN blocks—must not be retained after authorization, even in encrypted form, so addressing storage of this data early can meaningfully reduce the impact of a potential breach. Cardholder data such as the PAN may be stored under defined controls, which is a separate consideration handled elsewhere in the requirements.
It is important to understand what the Prioritized Approach is not. It is a supporting tool and roadmap; it does not modify, supersede, or reduce the obligations defined in PCI DSS itself. Achieving an early milestone is intended to demonstrate incremental risk reduction and progress, not to substitute for full compliance with the applicable standard. Because milestone structure and requirement wording differ across PCI DSS versions, organizations should confirm details against the current published standard and the version-specific Prioritized Approach document rather than relying on a fixed milestone or requirement number.
Who it's relevant to
Inside Prioritized Approach
Common questions
Answers to the questions practitioners most commonly ask about Prioritized Approach.