PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

Compensating control

A compensating control is an alternative measure used when an entity cannot meet a PCI DSS requirement as stated, because of a legitimate technical or documented business constraint.

What it means in practice

Each compensating control needs a Compensating Control Worksheet setting out the constraint, the objective of the original requirement, the control that meets it, and how it is validated.
Compensating controls must go above and beyond the original requirement and are re-evaluated at every assessment.
They are distinct from the customised approach, which is a formally defined v4.x method of meeting a requirement's objective differently.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.