Contact

What are you looking for?

The TRA Trap – Decoding PCI DSS v4.0.1's TRA

Certification, Cybersecurity & Technology, Digital Trust AssuranceSeptember 10, 2026

Understand the TRA and pick your route

The Payment Card Industry Data Security Standard (PCI DSS) v4.0.1 replaced the assumption of a single annual risk assessment with a requirement-based targeted risk analysis (TRA).

Since March 31, 2025, Requirements 12.3.1 and 12.3.2 have made this mandatory and directly assessable by a Qualified Security Assessor (QSA), requiring a TRA for individual requirements rather than a broad enterprise-wide exercise. The defined and customized approaches are frequently confused with one another, creating uncertainty for organizations preparing for assessment.

In our white paper, we examine these two distinct TRA processes, the decision criteria for choosing between them and the common pitfalls observed in the field. This guide equips your organization to build a TRA program that holds up under assessment.

PCI DSS White Paper

Inside the white paper

  • A brief overview of the TRA

    We outline the TRA, its purpose and its benefits.

  • Choosing between the defined and customized approaches

    We highlight the two pathways and the criteria for selecting the right one.

  • Common pitfalls observed in the field

    We outline the mistakes organizations repeatedly make and how to avoid them.

  • Takeaways and recommendations

    We conclude with essential recommendations for your TRA journey.

Please complete the form to download your copy.

    Related White Papers

    News & Insights

    • SGS - Jordan - Amman

    Abu Dahab Complex, Nufan As-Saoud Al-Edwan St. 22, 5th Floor,

    P.O.Box 930388, 11193,

    Amman, Jordan