Frequently Asked Questions

< Back to search page

Is the Prioritized Approach mandatory?

FAQ Response

The PCI SSC does not mandate the use of any one approach to PCI DSS compliance. The Prioritized Approach is designed as a reporting tool to help entities understand where they can act to reduce risk earlier in the compliance process, and to provide a means to track their progress towards compliance. 

In some cases, acquirers (merchant banks) or the payment brands may require use of this reporting tool as part of the payment brands' compliance programs. Organizations should check with their acquirer or payment brand, to determine if the Prioritized Approach reporting tool should be included in their compliance reporting.

March 2009
Article Number 1171