Get Demo
↑

PCI DSS ROC and AOC Explained: Report vs Attestation of Compliance

PCI DSS ROC vs AOC - what the Report on Compliance documents, what the Attestation of Compliance signs, and how both relate to SAQs.

Published: September 2026 Compliance · PCI DSS 8-12 min read

Per the PCI SSC Glossary: a Report on Compliance (ROC) is the reporting tool used to document detailed results from an entity's PCI DSS assessment. An Attestation of Compliance (AOC) is the official PCI SSC form for merchants and service providers to attest to the results of a PCI DSS assessment, as documented in a Self-Assessment Questionnaire (SAQ) or Report on Compliance (ROC).

Related: SAQ vs ROC · QSA vs ISA vs ASV · SAQ types · Compliance levels.

Gotcha: The AOC is not a substitute for the ROC or SAQ body - it attests to those results. PCI DSS requirements are not "in place" if controls are unfinished or scheduled for a future date. Official ROC content must follow the PCI DSS ROC Reporting Template.

Assessment Flow

  1. Confirm the scope of the PCI DSS assessment
  2. Perform the assessment of the environment
  3. Complete the applicable report (ROC Template or SAQ)
  4. Complete the applicable AOC in its entirety (official AOCs only from PCI SSC)
  5. Submit documentation and AOC (plus requested artifacts such as ASV reports) to the requesting organization
  6. Remediate open items and provide an updated report if required

Who Typically Needs What

QSAs typically perform ROC assessments. ISAs support their employer's internal program; they are not a substitute public QSA credential.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across SAQ and ROC validation paths.

Frequently Asked Questions

Is an AOC alone proof of compliance?

It attests to assessment results documented in a ROC or SAQ. Requesters usually want the paired report or questionnaire and supporting artifacts such as ASV scan reports.

Can an ISA sign a ROC for any company?

ISA qualification is for the sponsor employer's assessments under the ISA program - not a general public QSA credential. ROC assessments for third parties require a QSA Company.

Do SAQs include an AOC?

Yes. Each SAQ includes Attestation of Compliance sections aligned with ROC AOC structure for v4.x.

SAQ vs ROC · SAQ D · QSA vs ISA vs ASV · ASV scans · PCI hub

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!