IT Practice Exams

CS0-004 · Vulnerability Management · Updated July 26, 2026

PCI DSS Compensating Controls: What You Must Demonstrate and How the AOC Reflects It

A compensating control is an alternative safeguard an organization implements when a legitimate technical or business constraint prevents it from meeting a Payment Card Industry Data Security Standard (PCI DSS) requirement as written. To use one, the organization must demonstrate that the alternative meets the intent and rigor of the original requirement, provides a similar level of defense, goes above and beyond what other PCI DSS requirements already demand, and offsets the additional risk created by not following the requirement literally. The control is then documented on a Compensating Control Worksheet, and the requirement is reported as in place — not as a failure and not as “not applicable.”

What a compensating control actually is

PCI DSS is prescriptive: encrypt stored cardholder data, change vendor defaults, restrict access by need to know, and so on. Real environments do not always cooperate. A legacy point-of-sale (POS) platform may have no supported encryption module; a mainframe application may not integrate with a modern access-management stack; replacing either might take months of disruptive migration work.

The standard anticipates this. Rather than forcing a choice between an unachievable requirement and a non-compliant assessment, PCI DSS allows the entity to substitute a different control — but only under strict conditions, and only when a documented constraint makes the original requirement genuinely impractical. “It’s expensive” or “we’d rather not” does not qualify. A defensible constraint looks like: the vendor no longer supports the platform, the encryption requirement cannot be met without breaking payment processing, and a migration is scheduled but not yet complete. The same mechanism comes into play when an unfixable finding would otherwise fail a quarterly PCI ASV scan.

The four things you must demonstrate

For an assessor to accept a compensating control, the organization has to show all of the following:

  1. Meets the intent and rigor of the original requirement. If the requirement exists to keep stored primary account numbers (PANs) unreadable, the substitute must achieve comparable protection of that data — not merely something vaguely security-flavored.
  2. Provides a similar level of defense. The alternative must defend against the same threat the original requirement addresses, at comparable strength. Logging access to unencrypted data does not, by itself, stop an attacker from reading it; a substitute for encryption needs to actually restrict exposure.
  3. Is “above and beyond” other PCI DSS requirements. You cannot reuse a control the standard already obligates you to have. A firewall you were required to deploy anyway cannot double as your compensating control for encryption. However, doing an existing control type far more rigorously than required — for example, network segmentation that fully isolates the legacy system, plus continuous monitoring well beyond baseline logging expectations — can qualify.
  4. Is commensurate with the additional risk. Skipping the literal requirement creates extra risk; the compensating control must be sized to that risk. The riskier the gap, the stronger the substitute must be — sizing that risk draws on the same context factors (data sensitivity, exposure, compliance scope) used in risk-based prioritization of scan findings.

There is a fifth, forward-looking expectation: the control must remain effective over time and be re-evaluated at every annual assessment. Compensating controls are reviewed each year — they are intended as a maintained bridge, not a permanent excuse to avoid remediation.

How it gets documented: the worksheet, the ROC, and the AOC

Three documents matter here, and the exam expects you to know which does what:

  • Compensating Control Worksheet (CCW). The formal record of the constraint, the original requirement’s objective, the identified risk, the substitute control, how it was validated, and how it is maintained. One worksheet per requirement being compensated.
  • Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ). The detailed assessment record. The affected requirement is marked as in place via compensating control, with the CCW attached or referenced — the assessor tests the compensating control just as they would test the original requirement.
  • Attestation of Compliance (AOC). The summary document the merchant or service provider signs and submits to its acquiring bank and, when requested, to the card brands. The AOC indicates that compensating controls were used and for which requirements.

The critical discrimination: a properly implemented and documented compensating control results in a compliant finding. The requirement is not marked non-compliant, and it is not marked “not applicable” — “not applicable” is reserved for requirements that genuinely do not exist in the environment (for example, wireless requirements when there is no wireless in scope). Marking a compensated requirement N/A misrepresents the environment; leaving it non-compliant ignores the mechanism the standard provides.

Compensating control vs. customized approach

PCI DSS version 4.0 added a second flexibility mechanism, and the two are easy to confuse:

Compensating controlCustomized approach
Why it existsA constraint prevents meeting the requirement as writtenThe entity chooses a different way to meet the requirement’s objective
PrerequisiteDocumented legitimate technical or business constraintNo constraint needed — but requires mature, risk-based security practices
DocumentationCompensating Control WorksheetTargeted risk analysis plus assessor-designed testing procedures
CharacterA stopgap, re-validated annually, ideally retired when the constraint is removedA deliberate, ongoing alternative implementation

On the CS0-003 exam, “legacy system cannot support the requirement” points to a compensating control. A mature organization innovating its own way to satisfy a requirement’s objective points to the customized approach.

For how compensated and remediation-pending findings should be presented to assessors and remediation teams, see the companion article on PCI DSS compliance reporting.

How the CS0-003 exam tests this

  • A scenario describes a legacy POS or server that cannot be encrypted or patched without major disruption, then asks what the organization must demonstrate to substitute another control. The credited answer bundles the criteria: meets the intent and rigor of the original requirement, exceeds other existing PCI DSS obligations, and addresses the added risk. Distractors offer partial versions — “any additional security control” or “management approval alone.”
  • A scenario states that extra monitoring and segmentation were implemented in place of a requirement, then asks how the AOC must reflect it. The credited answer: the requirement is reported as in place/compliant with a documented compensating control worksheet. Distractors mark it non-compliant or “not applicable.”
  • A question contrasts a compensating control with the customized approach, testing whether you know the compensating control requires a documented constraint while the customized approach does not.

Compensating-control questions land in the Vulnerability Management domain; see the full CS0-003 study guide for the exam’s overall structure. Distractor-heavy items like these are exactly what timed practice questions train you to pick apart.

Quick reference

  • Compensating controls substitute for a PCI DSS requirement only when a legitimate, documented technical or business constraint exists.
  • Must meet the intent and rigor of the original requirement and provide a similar level of defense.
  • Must be above and beyond other PCI DSS requirements — no double-counting controls you already owe.
  • Must be commensurate with the additional risk of not meeting the requirement literally.
  • Documented on a Compensating Control Worksheet; the assessor validates it during the assessment.
  • On the ROC/SAQ and AOC, the requirement is reported in place via compensating control — never N/A, never non-compliant.
  • Re-evaluated at every annual assessment; treated as a bridge until the constraint is removed.
  • PCI DSS 4.0’s customized approach is the choice-driven alternative; compensating controls are the constraint-driven one.
Choose your exam → Lifetime access
from $59, once