PCI DSS Validation Explained: AOC, ROC and the SAQ Types
Being compliant with PCI DSS and being able to prove it are different things. The proof is a set of validation documents, and knowing which applies to whom is the practical part of the standard. For the requirements themselves, see the PCI DSS article linked at the end. The three documents SAQ — Self-Assessment Questionnaire. A structured checklist the merchant completes themselves, with a yes/no answer for each applicable requirement. Used by merchants who are not required to undergo an external audit. ROC — Report on Compliance. A detailed report produced by a Qualified Security Assessor after an on-site assessment, documenting how each requirement was tested and what evidence was examined. Required for the largest merchants and many service providers. AOC — Attestation of Compliance. The signed declaration that the assessment was completed and states the outcome. It accompanies either an SAQ or a ROC. The relationship matters and is the most likely exam point: the SAQ or R...