Understand the TRA and pick your route
The Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 replaced the assumption of a single annual risk assessment with a requirement-based targeted risk analysis (TRA).
Since March 31, 2025, Requirements 12.3.1 and 12.3.2 have made this mandatory and directly assessable by a Qualified Security Assessor (QSA), requiring a TRA for individual requirements rather than a broad enterprise-wide exercise. The defined and customized approaches are frequently confused with one another, creating uncertainty for organizations preparing for assessment.
In our white paper, we examine these two distinct TRA processes, the decision criteria for choosing between them and the common pitfalls observed in the field. This guide equips your organization to build a TRA program that holds up under assessment.
Inside the white paper
- A brief overview of the TRA
We outline the TRA, its purpose and its benefits.
- Choosing between the defined and customized approaches
We highlight the two pathways and the criteria for selecting the right one.
- Common pitfalls observed in the field
We outline the mistakes organizations repeatedly make and how to avoid them.
- Takeaways and recommendations
We conclude with essential recommendations for your TRA journey.
Abu Dahab Complex, Nufan As-Saoud Al-Edwan St. 22, 5th Floor,
P.O.Box 930388, 11193,
Amman, Jordan