Glossary

ROC vs SAQ

PCI DSS compliance is validated one of two ways. A Self-Assessment Questionnaire (SAQ) is exactly what it sounds like: your organization attests to its own compliance using the questionnaire matching how you handle card data. A Report on Compliance (ROC) is a formal assessment performed by an independent Qualified Security Assessor (QSA) who tests your controls and writes the report.

What determines your path

Primarily transaction volume, set by the card brands and your acquirer. Level 1 merchants (over six million transactions annually, roughly, and any merchant after a breach) need a ROC. Lower levels self-assess with an SAQ — but which SAQ matters enormously: SAQ A (fully outsourced payments, e.g. Stripe Checkout) is a few dozen requirements, while SAQ D (you touch cardholder data) approaches the full standard.

The architecture shortcut

The cheapest PCI strategy is scope reduction, not control implementation. Outsourcing payment handling entirely — hosted fields, redirects, tokenized flows — can move you from SAQ D territory to SAQ A, shrinking the requirement set by an order of magnitude. Decide your payments architecture with your SAQ type in mind, not after.

Who asks for what

Your acquirer or payment processor collects the attestation annually. Enterprise customers occasionally ask for your Attestation of Compliance (AOC) — the summary certificate from either path — during security reviews, alongside SOC 2 reports and questionnaires.

Related Terms

Continuous Monitoring — Continuous monitoring is the automated, ongoing testing of security controls — replacing point-in-time evidence scrambles with always-current audit readiness.

Gap Assessment — A gap assessment maps your current controls against a framework's requirements and produces the remediation plan that makes audit readiness plannable.