Attestation of Compliance (AOC)
PCIComplianceHubLast updated
The Council's form on which an entity declares the result of its PCI DSS assessment: which SAQ or ROC it completed, the scope covered, the date, and whether it was compliant. The entity signs it; for a QSA-led assessment the QSA signs too. It is the document acquirers and customers ask for as proof of compliance.
Applies to. Every entity that validates, whether by SAQ or ROC. Customers of a service provider ask for the provider's AOC when monitoring its status under 12.8.4.
Example. A hosting provider sends its customers an AOC for SAQ D for Service Providers, dated, listing the hosting services assessed. A customer checks that the service it buys is one of those named and that the date is within the last 12 months.
Limits. An AOC states a result for a described scope on a date. It does not say which of the customer's requirements the provider manages; that is 12.8.5 and the responsibility matrix. A service not named in its scope is not covered by it. It is not a certificate and it does not transfer: a merchant using a compliant provider still validates its own environment. Payment brands and acquirers decide what they will accept and how often.