Contact

What are you looking for?

The TRA Trap – Decoding PCI DSS v4.0’s TRA

September 07, 2026

With the dozens of changes Payment Card Industry Data Security Standard (PCI DSS) v4.0 presents, it is easy to get lost in the requirements, rewording and all-around confusing nature of the DSS.

Targeted risk analysis (TRA) poses a particular risk of confusion when considering what approach to take when completing the Report on Compliance (ROC). 

We aim to summarize the key considerations for determining whether your organization will take the defined or customized approach, and how to deal with the frequency requirements specifically.

TRA for identifying and assessing risks

TRA involves identifying and assessing specific risks that may impact your organization's cardholder data environment (CDE). It requires you to thoroughly evaluate your systems, processes and vulnerabilities to determine potential threats and their likelihood of occurrence. This analysis enables you to prioritize security measures based on identified risks.

If your organization decides to utilize a customized approach, you must understand that appendices E1 and E2 will be used to account for the approach, conduct risk analysis and implement the controls to meet the requirement.

E2 sample TRA template

The following is a sample TRA template an entity may use for its customized implementation. While an entity is not required to follow this specific format, its customized approach documentation must include all the information defined in this template.

TRA a

The document can be found here.

There is, however, a different form for frequency requirements outlined in 12.3.1. The DSS gives your organization the freedom to self-define the frequency of several activities, so long as those activities are defined and accounted for using a TRA, but instead of the standard Appendix E2, a stripped-down version, specific to frequency requirements, is used.

The form below is for your frequency requirements.

TRA b

The document can be found here.

This PCI DSS v4.x TRA template is for all frequency requirements where your organization can decide how often a task will be performed. Those requirements are:

  • 2.3.1
  • 3.2.1
  • 2.5.1
  • 6.3
  • 5.1.2.1
  • 4.2.1
  • 3.1.1
  • 6.1 (*in some cases)
  • 10.4.1

We hope this helps your organization avoid completing appendices E1 and E2 unnecessarily, saving valuable time and effort.

Questions about PCI DSS compliance?

Navigating PCI DSS v4.0.1, from scoping and ROC work to Approved Scanning Vendor (ASV) scans, penetration testing and PCI Security Standards Council (PCI SSC) assessment, requires a team with deep, hands-on experience across the full standard.

Whether you are preparing for your first assessment, closing gaps before an audit cycle or exploring how a combined audit approach could streamline PCI alongside SOC 2, ISO or SSAE 23 requirements, our team of experienced Qualified Security Assessors (QSAs) and technical testing professionals is ready to help.

We welcome the opportunity to discuss your organization's specific compliance needs and how we can support your team through the process.

For more information, visit our PCI DSS service page. For questions or to start a conversation about PCI DSS compliance, please reach out to:

Patrick Ibrahim

Patrick

Ibrahim

Senior Director, Digital Trust

About SGS

SGS is the world’s leading Testing, Inspection and Certification company. We operate a network of over 2,500 laboratories and business facilities across 115 countries, supported by a team of over 100,000 dedicated professionals. With more than 145 years of service excellence, we combine the precision and accuracy that define Swiss companies to help organizations achieve the highest standards of quality, compliance and sustainability.

Our brand promise – when you need to be sure – underscores our commitment to trust, integrity and reliability, enabling businesses to thrive with confidence. We proudly deliver our expert services through the SGS name and a portfolio of trusted specialized brands, including Applied Technical Services, Brightsight, Bluesign and Nutrasource.

SGS is publicly traded on the SIX Swiss Exchange under the ticker symbol SGSN (ISIN CH1256740924, Reuters SGSN.S, Bloomberg SGSN SW).

News & Insights

  • SGS - Indonesia - Jakarta

The Garden Center, Kawasan Komersial Cilandak (KKC), Jl. Raya Cilandak KKO,

12560,

South Jakarta, Special Capital Region of Jakarta, Indonesia