PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

ROC — Report on Compliance

A Report on Compliance (ROC) is the detailed assessment report produced by a QSA (or a qualified Internal Security Assessor) documenting how every applicable PCI DSS requirement was tested and the result.

What it means in practice

A ROC is required for Level 1 merchants and Level 1 service providers, and whenever an acquirer or payment brand mandates one.
It records the assessed scope, sampling rationale, testing performed for each requirement, and any compensating controls or customised approach implementations.
A ROC is always accompanied by an Attestation of Compliance.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.