RoC (Report on Compliance)
PCIComplianceHubLast updated
The full written record of a PCI DSS assessment, produced on the Council's reporting template by a QSA or an Internal Security Assessor. It documents, requirement by requirement, what was tested, how, and the result, and it is the document behind an Attestation of Compliance for entities that do not self-assess.
Applies to. Entities validating by assessment rather than by SAQ: typically Level 1 merchants and service providers, or any entity an acquirer or brand requires to.
Example. For 11.6.1 the ROC records which payment pages were examined, the mechanism observed, its configuration, the evidence that it runs at least weekly, and the assessor's finding, in the template's fixed format.
Limits. A ROC follows the Council's template, so an assessor cannot leave a requirement out or summarise it away; that is what makes it heavier than any SAQ. It is confidential between the entity, its assessor and its acquirer or brand; customers normally receive only the AOC. It is a snapshot on its date, and the brands set how often a new one is required.