We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI SSC-qualified QSA Company

PCI DSS RoC assessment services

A Report on Compliance (RoC) is the formal, on-site PCI DSS assessment a QSA produces for Level 1 entities — and for aggregators and gateways their acquirers push to Level 1. It documents testing against every applicable requirement and testing procedure, and is accompanied by a signed Attestation of Compliance (AoC). CyberSigma is a PCI SSC-listed QSA Company that performs the full RoC assessment: scoping, evidence sampling, on-site testing, and the RoC/AoC your bank and card networks accept as evidence of validation.

Get a free RoC scope →Book a 20-minute QSA call
RoC vs SAQ

RoC vs self-assessment (SAQ)

A Self-Assessment Questionnaire (SAQ) is self-attestation for lower-volume merchants. A Report on Compliance is a formal QSA assessment: the QSA does not accept yes/no answers — they sample systems, pull evidence, interview staff, observe tasks and write against every applicable requirement. Level 1 entities, and most aggregators/gateways, require a RoC.

Process

How a RoC assessment runs

Scoping & gap
CDE definition, gap analysis and remediation roadmap.
On-site testing
Evidence sampling, interviews and testing-procedure execution.
RoC + AoC
The documented RoC and signed Attestation of Compliance.
Evidence

What the RoC tests

  • Segmentation and CDE boundary
  • Access control, MFA and key management
  • Logging, monitoring and retention
  • Vulnerability management, ASV scans and penetration testing
  • Policies and the new v4.0.1 targeted risk analyses
Timeline & cost

Timeline and cost

Timeline
First-time RoC: three to six months end to end.
Cost factors
CDE size, first-time vs repeat, remediation and recurring ASV/pentest.
Proof

See how we’ve done it before

Relevant case study
How a Level 1 entity moved from an incomplete SAQ to a clean RoC. Read case studies →
Redacted sample deliverable
Inspect a redacted gap report first. Request a redacted sample →

Not sure how close you are to a clean ROC?

Get a free PCI DSS v4.0.1 readiness snapshot from a listed QSA — share your work email and we map your gaps and scope before the assessment.

PCI DSS RoC — FAQs

What is a PCI DSS RoC?

A Report on Compliance — the formal, on-site assessment a QSA produces for Level 1 entities, documenting testing against every applicable requirement, accompanied by a signed Attestation of Compliance (AoC).

Do we need a RoC or can we self-assess?

It depends on your level and your acquirer. Level 1 entities need a RoC; aggregators and gateways are usually pushed to Level 1 regardless of volume. We confirm during scoping.

Talk to a listed QSA about your RoC

We scope, test and produce your RoC/AoC end to end. Reply within four business hours.

Book a 20-minute QSA call →

Ready to discuss your PCI DSS RoC assessment requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.