PCI DSS RoC assessment services
A Report on Compliance (RoC) is the formal, on-site PCI DSS assessment a QSA produces for Level 1 entities — and for aggregators and gateways their acquirers push to Level 1. It documents testing against every applicable requirement and testing procedure, and is accompanied by a signed Attestation of Compliance (AoC). CyberSigma is a PCI SSC-listed QSA Company that performs the full RoC assessment: scoping, evidence sampling, on-site testing, and the RoC/AoC your bank and card networks accept as evidence of validation.
RoC vs self-assessment (SAQ)
A Self-Assessment Questionnaire (SAQ) is self-attestation for lower-volume merchants. A Report on Compliance is a formal QSA assessment: the QSA does not accept yes/no answers — they sample systems, pull evidence, interview staff, observe tasks and write against every applicable requirement. Level 1 entities, and most aggregators/gateways, require a RoC.
How a RoC assessment runs
What the RoC tests
- Segmentation and CDE boundary
- Access control, MFA and key management
- Logging, monitoring and retention
- Vulnerability management, ASV scans and penetration testing
- Policies and the new v4.0.1 targeted risk analyses
Timeline and cost
See how we’ve done it before
Not sure how close you are to a clean ROC?
Get a free PCI DSS v4.0.1 readiness snapshot from a listed QSA — share your work email and we map your gaps and scope before the assessment.
PCI DSS RoC — FAQs
What is a PCI DSS RoC?
A Report on Compliance — the formal, on-site assessment a QSA produces for Level 1 entities, documenting testing against every applicable requirement, accompanied by a signed Attestation of Compliance (AoC).
Do we need a RoC or can we self-assess?
It depends on your level and your acquirer. Level 1 entities need a RoC; aggregators and gateways are usually pushed to Level 1 regardless of volume. We confirm during scoping.
Talk to a listed QSA about your RoC
We scope, test and produce your RoC/AoC end to end. Reply within four business hours.
Book a 20-minute QSA call →Ready to discuss your PCI DSS RoC assessment requirement?
CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.
