PCI Compliance Attestation
The Payment Card Industry Data Security Standard (PCI DSS) requires organizations that store, process, or transmit cardholder data to validate their compliance annually. The formal declaration of this validation is the Attestation of Compliance (AOC).
What an AOC is
- A snapshot, not a plan — The AOC attests to what the organization is doing now, not what it plans to do or hopes to achieve. Any material change to the cardholder data environment (CDE) can invalidate the attestation.
- Forward-looking by convention — Although the AOC describes the current state, it is generally treated as forward-looking. If a breach occurs, investigators review the current AOC to determine whether the organization was actually compliant at the time of the incident.
- Signed by a QSA or internal audit — Merchants can self-attest (if internal audit performs validation) or use a Qualified Security Assessor (QSA). Service providers typically require a QSA.
Key documents
| Document | Purpose |
|---|---|
| ROC (Report on Compliance) | Detailed assessment findings, produced by the QSA |
| AOC (Attestation of Compliance) | Short-form declaration signed by the merchant/service provider and QSA |
| SAQ (Self-Assessment Questionnaire) | For smaller merchants eligible to self-assess |
Important nuance
The PCI Security Standards Council (SSC) does not issue certifications. There is no “PCI certified” status — only an AOC on file. The card brands (Visa, Mastercard, etc.) and acquiring banks determine whether an organization’s AOC is acceptable.
Related: test-credit-card-entry-forms (testing without real PANs), cybersecurity certifications (QSA and other credentials).
Sources
- PCI Security Standards Council — Document Library
- PCI DSS — Attestation of Compliance for Onsite Assessments — Merchants
See also
- test-credit-card-entry-forms
- cybersecurity certifications