PCI DSS

PCI DSS Assessment: ROC, SAQ, and the QSA

The short version

PCI DSS compliance is not self-declared; it is validated. How depends on the entity and its transaction volume. A Report on Compliance (ROC), performed by a Qualified Security Assessor or a trained internal security assessor, is the full assessment for the largest merchants and most service providers. A Self-Assessment Questionnaire (SAQ) is the lighter, self-validated path for smaller merchants. Either way the result is captured in an Attestation of Compliance (AOC), the signed statement of the assessment's outcome, and network scanning by an Approved Scanning Vendor supports the external-vulnerability requirements.

A PCI DSS assessment is the validation of an entity's compliance with the standard, which the standard treats as a discipline separate from building the program itself. The form the assessment takes is set by the type of entity and the volume of card data it handles. This guide covers the ROC, the SAQ, the AOC, the people who perform the assessment, how merchant level decides the path, and where assessments go wrong.

How compliance is validated

PCI DSS is enforced by the payment brands through the acquiring banks, and they require entities to validate compliance on a defined cycle, typically annually, with quarterly network scanning. Validation is an assessment against the standard's requirements that produces evidence, rather than a self-declaration. The two main routes are the Report on Compliance and the Self-Assessment Questionnaire.

ROC versus SAQ

PathWhat it is
Report on Compliance (ROC)The full assessment, documenting how each requirement is met. Performed by a QSA or a qualified internal security assessor. Required for the largest merchants and most service providers.
Self-Assessment Questionnaire (SAQ)A self-validated questionnaire for smaller merchants. Several SAQ types exist, each matched to how the merchant accepts and handles card data.
Attestation of Compliance (AOC)The signed statement of the assessment's result. It accompanies both the ROC and the SAQ and is what the acquirer or brand receives.

There is no single SAQ. The Council publishes several, each matched to how a merchant accepts and handles card data: SAQ A for fully outsourced e-commerce or mail and telephone order, SAQ A-EP for e-commerce merchants that partially manage the payment page, SAQ B and B-IP for imprint or standalone terminal merchants, SAQ C and C-VT for payment-application or virtual-terminal merchants, SAQ P2PE for merchants using a validated point-to-point encryption solution, and SAQ D, the most extensive, for everyone else and for service providers. Completing an SAQ that does not match how the merchant accepts and handles card data tests the wrong set of controls.

Who performs the assessment

A Qualified Security Assessor is a company the PCI Security Standards Council certifies to perform ROC assessments. A trained internal security assessor can perform a ROC for their own organization where the brand permits. An Approved Scanning Vendor runs the external vulnerability scans that several requirements depend on. The SAQ, by contrast, is completed by the merchant itself.

How merchant level sets the path

The payment brands sort merchants into levels by annual transaction volume, and the level drives the validation path. The highest-volume level generally requires an annual ROC and quarterly ASV scans; lower levels can validate by SAQ. Service providers have their own level scheme. Because the brands set the thresholds, the exact level definitions should be confirmed with the acquirer.

How to approach one

Step 1: Confirm the entity's level and the required path

The merchant or service-provider level is established with the acquirer, which sets whether a ROC or an SAQ is required and which SAQ type applies.

Step 2: Scope the cardholder data environment

Define the systems in scope, since assessment scope follows the cardholder data environment and any connected systems.

Step 3: Run the assessment and the scans

Complete the ROC or SAQ against the requirements and arrange the ASV scans the path requires.

Step 4: Sign the Attestation of Compliance

Capture the result in the AOC and provide it to the acquirer or brand.

Step 5: Maintain between assessments

Keep the controls operating and the targeted risk analyses current, since validation is a point-in-time snapshot of an ongoing obligation.

Where it goes wrong

A PCI DSS assessment is how compliance is proven to the brands and acquirers. For the wider standard, see the PCI DSS compliance guide and the PCI DSS glossary; for the analysis that justifies control frequency, see the PCI DSS risk assessment guide.

Primary sources

Common questions

What is the difference between a ROC and an SAQ?
A Report on Compliance is the full PCI DSS assessment documenting how each requirement is met, performed by a Qualified Security Assessor or a qualified internal security assessor, and required for the largest merchants and most service providers. A Self-Assessment Questionnaire is the lighter, self-validated path for smaller merchants, with several types matched to how the merchant handles card data.
What is a QSA in PCI DSS?
A Qualified Security Assessor is a company the PCI Security Standards Council certifies to perform Report on Compliance assessments. A trained internal security assessor can perform a ROC for their own organization where the payment brand permits, and an Approved Scanning Vendor runs the external vulnerability scans several requirements depend on.
What is an Attestation of Compliance?
The AOC is the signed statement of a PCI DSS assessment's result. It accompanies both the Report on Compliance and the Self-Assessment Questionnaire and is the document the acquiring bank or payment brand receives as evidence of validation.
How does merchant level affect the assessment?
The payment brands sort merchants into levels by annual transaction volume, and the level drives the validation path. The highest-volume level generally requires an annual ROC and quarterly ASV scans, while lower levels can validate by SAQ. The exact thresholds are confirmed with the acquirer.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.