4.6 Implementing Compensating and Alternate Controls

Key Takeaways

  • A compensating control is justified only when the baseline control is genuinely infeasible for technical, architectural, or mission reasons — never because it is inconvenient or expensive.
  • The compensating control must satisfy the intent and rigor of the original requirement and provide comparable protection, not merely some protection.
  • Compensating controls require documented rationale, an assessment of the resulting risk, and formal acceptance by the Authorizing Official.
  • A compensating control differs from a scoped-out control: scoping applies when the condition the control addresses is absent, while compensation applies when the condition exists but the specified control cannot be used.
  • Compensating controls carry higher continuous monitoring obligations because they are bespoke arrangements without the assurance history of the baseline control.
Last updated: August 2026

Implementing Compensating and Alternate Controls

Task 4.2 names two implementation outputs: controls implemented consistently with compliance requirements, and "compensating or alternate security controls implemented." The second exists because real systems contain constraints the catalog authors could not anticipate — legacy platforms, safety-critical timing requirements, vendor-sealed appliances, medical or industrial devices that cannot be modified without voiding certification.


1. When Compensation Is Legitimate

A compensating control substitutes an alternative safeguard for a baseline control that cannot be implemented as specified. The justification must rest on genuine infeasibility:

Legitimate BasisExample
Technical infeasibilityA vendor-sealed medical device cannot accept a third-party endpoint agent without voiding its regulatory certification
Architectural constraintAn industrial control protocol has no capacity to carry authentication tokens
Mission/safety conflictAutomatic session termination would interrupt a continuously running flight-tracking process
Legacy platform limitationAn unsupported operating system cannot enforce the required cryptographic module

And the bases that are not legitimate — each a favourite exam distractor:

  • "It is too expensive." Cost is a factor in risk-based decisions, but budget alone does not make a control infeasible. The correct path is a risk acceptance decision by the Authorizing Official or a POA&M item, not a compensating control.
  • "It is inconvenient for users." Friction is not infeasibility.
  • "We have not got round to it." That is a planned implementation belonging in the POA&M, not a compensating control.
  • "Another baseline control already covers it." A control that is already required cannot be reused as compensation for a different requirement.

[!IMPORTANT] The "above and beyond" rule. A compensating control must be something the organization is not already obliged to do. Offering "we run quarterly vulnerability scans" as compensation for a missing control fails, because scanning is itself a baseline requirement (RA-5). Compensation requires additional protection beyond the existing obligations. PCI DSS states this most explicitly in its compensating control worksheet criteria, and the same logic governs NIST tailoring.


2. The Equivalence Standard

The substitute must meet the intent and rigor of the original control and provide comparable protection — a materially higher bar than "provides some security benefit."

Establishing equivalence requires four steps:

  1. State the security objective of the original control. Not its mechanism — its purpose. AC-12 (session termination) exists to limit the window in which an unattended authenticated session can be abused.
  2. Explain precisely why the specified mechanism cannot be used, with technical evidence rather than assertion.
  3. Describe the alternative and show how it addresses the same objective. Restricting access to hardened jump hosts with continuous session monitoring and re-authentication addresses the unattended-session window through a different mechanism.
  4. Analyze the residual difference. Equivalence is rarely perfect. Name what the substitute does not cover and quantify the resulting exposure.

That fourth step separates a credible compensating control from a rationalization, and it is the step assessors probe hardest. An analysis claiming perfect equivalence is usually an analysis that has not been done.

Compensating Controls Are Often Layered

A single substitute rarely reaches equivalence with a baseline control. The air-gapped legacy-system pattern is typical: an isolated physical enclave, plus biometric door access, plus unidirectional data diodes, plus continuous passive network monitoring, plus enhanced personnel vetting — collectively compensating for unsupported multifactor authentication and automated patching. Any one element alone would fail the comparability test.


3. Approval and Documentation

Compensating controls are never a local engineering decision. The path is fixed:

  1. The system owner or ISSO documents the constraint, the proposed alternative, and the equivalence analysis in the SSP, recording the control status as alternative implementation.
  2. The Security Control Assessor independently evaluates whether the substitute genuinely achieves the objective and tests it as implemented. The assessor may find the compensating control inadequate, which returns the item to the system owner.
  3. The Authorizing Official formally accepts the residual risk. Because the system is operating with something other than the prescribed baseline, only the AO can accept that deviation.
  4. Where a regulator, overlay, or framework owner must concur — a FedRAMP authorizing body, a card-brand acquirer, a DoD component — that concurrence is obtained as well.

The complete record contains the original control, why it is infeasible, the alternative and how it achieves the objective, the residual difference and its risk, the monitoring commitment, the assessor's evaluation, and the AO's acceptance. Missing any element makes the compensating control indefensible at audit.


4. Compensating Versus Scoping Out — The Distinction That Decides Exam Items

These are routinely confused and the exam tests them directly.

Scoped Out (Not Applicable)Compensating Control
SituationThe condition the control addresses does not exist in the boundaryThe condition exists, but the specified control cannot be used
ExamplePE-18 (wireless access) in a system with zero wireless componentsAC-12 (session termination) on a system that must run continuous background jobs
ResultNo control needed; nothing to protectAlternative safeguard required
DocumentationJustification that the condition is absentFull equivalence analysis + AO risk acceptance
Residual riskNone from this controlReal, and must be accepted

The test is a single question: does the risk the control addresses exist in this system? If no — scope it out. If yes but the control cannot be implemented as written — compensate. Answering "compensating control" for a system with no wireless interfaces is wrong; there is nothing to compensate for.

Sustainment Obligations Are Higher

A compensating control is a bespoke arrangement without the assurance history of a standard baseline control, so it inherits stronger ongoing obligations. It should be reassessed more frequently than the control it replaces; it must be revisited whenever the constraint changes — when the vendor finally ships MFA support, the compensating control should retire in favour of the baseline control; and it must be re-examined at every reauthorization, since a constraint that was genuine five years ago may simply be deferred modernization today. Compensating controls that quietly become permanent, long after the constraint that justified them has disappeared, are a standard audit finding.

Loading diagram...
Compensating Control Decision and Approval Path
Test Your Knowledge

A cloud-native database has no wireless interfaces of any kind. The ISSO proposes documenting a compensating control for PE-18 (Wireless Access). How should this be handled?

A
B
C
D
Test Your Knowledge

A team proposes satisfying a missing baseline control by citing its existing quarterly vulnerability scanning programme as the compensating control. Why does this proposal fail?

A
B
C
D
Test Your Knowledge

Why do compensating controls carry heavier continuous monitoring and reauthorization obligations than the baseline controls they replace?

A
B
C
D