PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

AoC — Attestation of Compliance

An Attestation of Compliance (AoC) is the signed declaration that accompanies a completed SAQ or Report on Compliance, stating the assessment result for the entity and the environment assessed.

What it means in practice

The AoC summarises the assessed entity, the scope, the assessment method and the compliance outcome. It is the artefact acquirers and payment brands typically ask to see.
An AoC exists for both self-assessments and QSA-led assessments; the form differs. A signed AoC covering a formal engagement is produced by a Qualified Security Assessor.
Completing a self-assessment for readiness purposes is not the same as producing a validated, signed AoC.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.