Attestation of Compliance
An Attestation of Compliance (AOC) is a formal document in which an organization declares that it has met the requirements of the PCI DSS for protecting payment card data. It is completed as part of a validation process, typically by a Qualified Security Assessor (QSA) or, in some cases, by the organization's own internal audit function. In short, it is a signed statement confirming the outcome of a PCI DSS assessment.
The Attestation of Compliance (AOC) is a standardized PCI SSC form used to declare the results of a PCI DSS validation for a given entity and assessment scope. Per the evidence, the merchant AOC is completed by a Qualified Security Assessor (QSA) or by the merchant where a merchant internal audit function performs the validation, and it accompanies the corresponding assessment documentation (such as a Report on Compliance or Self-Assessment Questionnaire, though those are distinct deliverables). The AOC attests to compliance status against PCI DSS requirements as of the assessment; practitioners should note that AOC templates, form variants, and requirement wording differ by PCI DSS version and by validation type, and the current published PCI SSC documents should be confirmed rather than assuming a fixed format. The AOC pertains specifically to PCI DSS and should not be conflated with attestations or validation artifacts under separate standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS.
Why it matters
The Attestation of Compliance is the artifact that other parties actually rely on to confirm an entity's PCI DSS validation status. Acquirers, payment processors, and larger merchants routinely request an AOC from the organizations they do business with, because it provides a signed, standardized summary of the assessment outcome without requiring the recipient to review the full underlying Report on Compliance or Self-Assessment Questionnaire. In practice, the AOC functions as the shareable proof of validation, while the more detailed assessment documentation remains more sensitive and is exchanged more selectively.
Because the AOC declares compliance status as of a specific assessment and scope, its accuracy matters. An AOC that misstates the assessed environment, the validation type, or the applicable requirements can give downstream parties a false sense of assurance. It is important to recognize that an AOC reflects the outcome of a point-in-time validation against the PCI DSS requirements that were in effect for that assessment; it is not a continuous guarantee of security, and it does not by itself address controls governed by separate standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS.
Because AOC templates, form variants, and requirement wording differ by PCI DSS version and by validation type, both the party completing the AOC and the party relying on it should confirm the current published PCI SSC form rather than assuming a fixed format. Treating an AOC as a durable certification, rather than a declaration tied to a particular assessment period and scope, is a common source of misunderstanding in vendor and merchant risk reviews.
Who it's relevant to
Inside AOC
Common questions
Answers to the questions practitioners most commonly ask about AOC.