PCI DSS compliance is validated with three core documents. A Report on Compliance (ROC) is the detailed assessment report written by a Qualified Security Assessor (QSA) or, where allowed, an Internal Security Assessor (ISA). A Self-Assessment Questionnaire (SAQ) is the validation form that eligible organizations complete themselves. An Attestation of Compliance (AOC) is the short, signed declaration of the result that goes with either one, and it's the document acquirers and customers usually ask for.
Which of them you need depends on your merchant or service provider level. The card brands and your acquirer set those levels, not the PCI Security Standards Council (PCI SSC).
What is a PCI Report on Compliance (ROC)?
A ROC is the full record of an assessment against PCI DSS. The assessor works through every applicable requirement, documents the evidence reviewed, the people interviewed and the systems sampled, and records a finding for each one. It's long, detailed and specific to your environment.
ROCs follow a mandatory template published by the PCI SSC. The Report on Compliance Template for PCI DSS v4.0 came out on 31 March 2022, together with the standard and the matching AOCs, as the Council's announcement set out. Assessments against v3.2.1 still use the older template.
Most ROCs are written by a QSA, an assessor employed by a QSA company. Some card brands also let merchants use an ISA, an employee who has completed the Council's ISA qualification, to assess their own organization.
Because a ROC describes your environment in depth, including network architecture, system names and any control weaknesses, it's a sensitive document. It normally goes to your acquirer or a card brand on request, not to customers.
What is a PCI Self-Assessment Questionnaire (SAQ)?
An SAQ is a validation tool for organizations that don't need a ROC. You answer each requirement that applies to your payment setup, explain anything marked not applicable, and complete the attestation at the end.
There are several SAQ types, each matching a particular way of accepting cards. They range from SAQ A, for merchants that fully outsource card-not-present payments, to SAQ D, which covers every applicable requirement. SAQ D for Service Providers is the only questionnaire a service provider can use.
The Council published the v4.0 SAQs on 29 April 2022, about a month after the standard, according to its SAQ bulletin. As with the ROC template, use the version that matches the standard you're being assessed against.
What is a PCI Attestation of Compliance (AOC)?
The AOC is the formal declaration of your compliance status. It summarizes who you are, what was assessed, the outcome and who is attesting to it.
There are separate AOCs for merchants and for service providers. After a QSA assessment, the AOC is a standalone form completed alongside the ROC. For an SAQ, the attestation is built into the questionnaire itself.
Who signs the AOC?
An executive officer of the assessed organization signs to confirm the results. If a QSA carried out or helped with the assessment, an authorized officer of the QSA company signs as well, and any ISA involvement is recorded too.
The executive signature is a personal attestation. The person signing should understand what they're confirming, not just sign what lands on their desk.
What's in a service provider AOC?
For service providers, the AOC is the document customers rely on. It lists the services that were included in the assessment and any that weren't. Customers checking your status under their own supplier monitoring requirement (12.8.4 in both v3.2.1 and v4.0) read that section closely. Make sure every service they buy from you appears on the assessed list.
How do the ROC, SAQ and AOC fit together?
| Document | Purpose | Prepared by | Usually goes to |
|---|---|---|---|
| ROC | Detailed findings for every applicable requirement | QSA, or an ISA where the brands allow | Acquirer or card brand, on request |
| SAQ | Self-assessment for eligible organizations | The organization, sometimes with QSA help | Acquirer |
| AOC | Signed summary of the compliance result | Completed with the ROC or SAQ | Acquirer, card brands and customers |
| ASV scan report | Results of quarterly external vulnerability scans | Approved Scanning Vendor | Kept as evidence; submitted when requested |
The AOC is the only one of the three built for sharing. When a customer or partner asks for "your PCI certificate", this is almost always what they mean. PCI DSS doesn't have certificates as such.
Who decides whether you need a ROC or an SAQ?
The card brands and your acquirer do. The PCI SSC writes the standard and the reporting documents, but each card brand runs its own compliance program and defines the levels that determine how you validate. Your acquirer, the bank that processes your card transactions, applies those rules and can add stricter ones.
What are the PCI merchant levels?
Merchant levels are based on annual transaction volume, and each brand defines its own. Visa's levels are a common reference point:
| Visa merchant level | Annual Visa transactions | Typical validation |
|---|---|---|
| Level 1 | More than 6 million, across all channels | Annual ROC, quarterly ASV scans, AOC |
| Level 2 | 1 million to 6 million | Annual SAQ, quarterly ASV scans where applicable, AOC |
| Level 3 | 20,000 to 1 million e-commerce | Annual SAQ, quarterly ASV scans where applicable, AOC |
| Level 4 | Fewer than 20,000 e-commerce, and all others up to 1 million | Set by the acquirer, usually an SAQ |
Mastercard, American Express, Discover and JCB each have their own definitions and validation rules. A brand can also place a merchant in a higher level if it thinks the risk warrants it. Ask your acquirer to confirm your level in writing rather than working it out yourself.
What are the PCI service provider levels?
Service providers generally have two levels. Visa draws the line at 300,000 transactions a year. Above it, you're Level 1 and need an annual ROC by a QSA. Below it, you're Level 2 and can usually validate with SAQ D for Service Providers.
Your customers can raise that bar. Some make a QSA-assessed AOC a contractual condition, so check your agreements before assuming an SAQ will do.
Where do ASV scan reports fit?
ASV scan reports are evidence for the external vulnerability scanning requirement: 11.2.2 in v3.2.1 and 11.3.2 in v4.0. They're separate documents from the ROC and SAQ, but they feed into both.
- In a QSA assessment, the assessor reviews your passing scans from the last four quarters.
- For an SAQ, scans are needed only if your questionnaire includes the scanning requirement. The v4.0 SAQs tell you to submit the SAQ and AOC with any other requested documentation, such as ASV scan reports, to whoever asked for them.
- Each scan report opens with an Attestation of Scan Compliance, attested by both you and the ASV. Some acquirers want that page every quarter, while others ask for it only at annual validation.
Which version should your documents use: v3.2.1 or v4.0?
Both versions of PCI DSS stay active until v3.2.1 retires on 31 March 2024. You can validate against either until then, but everything in one assessment has to match. A v4.0 SAQ goes with a v4.0 AOC, and a v3.2.1 ROC goes with a v3.2.1 AOC.
Agree the version with your acquirer, and your QSA if you use one, before you start. One sensible approach is to validate against v3.2.1 this cycle while mapping your gaps against v4.0. Many of the new v4.0 requirements are best practices until 31 March 2025, which gives you room to plan.
Frequently asked questions
Can we give customers our ROC instead of the AOC?
You can, but you usually shouldn't. The AOC is designed to be shared, while the ROC exposes internal detail most customers don't need. If a customer insists on seeing more, share it only under a non-disclosure agreement.
How long is an AOC valid?
The card brands require annual validation, so an AOC is generally treated as current for 12 months after it's completed. Customers of service providers check the date as part of their own annual monitoring.
Does an SAQ require a QSA?
Not by default. Some brands and acquirers require QSA or ISA involvement for certain merchant levels, and you can always choose to hire one. If a QSA helps, they sign the relevant part of the attestation.
What if we can't answer "yes" to every requirement?
Mark the gaps honestly as not in place. The AOC includes an action plan section for non-compliant requirements, and your acquirer may ask you to complete it with target dates. Raise the issue with your acquirer early rather than submitting a surprise.
Next steps
- Confirm your merchant or service provider level with your acquirer, in writing.
- Work out which validation route that level requires: a ROC or an SAQ.
- Choose the PCI DSS version for this cycle and use the matching templates throughout.
- Line up four quarters of passing ASV scans if your validation requires them.
- Brief the executive who will sign the AOC on what they're attesting to.
- If you're a service provider, check that your AOC lists every service your customers depend on.