Skip to main content
Category: PCI DSS Compliance

Attestation of Compliance

Also known as: AOC, AoC, PCI DSS Attestation of Compliance
Simply put

An Attestation of Compliance (AOC) is a formal document in which an organization declares that it has met the requirements of the PCI DSS for protecting payment card data. It is completed as part of a validation process, typically by a Qualified Security Assessor (QSA) or, in some cases, by the organization's own internal audit function. In short, it is a signed statement confirming the outcome of a PCI DSS assessment.

Formal definition

The Attestation of Compliance (AOC) is a standardized PCI SSC form used to declare the results of a PCI DSS validation for a given entity and assessment scope. Per the evidence, the merchant AOC is completed by a Qualified Security Assessor (QSA) or by the merchant where a merchant internal audit function performs the validation, and it accompanies the corresponding assessment documentation (such as a Report on Compliance or Self-Assessment Questionnaire, though those are distinct deliverables). The AOC attests to compliance status against PCI DSS requirements as of the assessment; practitioners should note that AOC templates, form variants, and requirement wording differ by PCI DSS version and by validation type, and the current published PCI SSC documents should be confirmed rather than assuming a fixed format. The AOC pertains specifically to PCI DSS and should not be conflated with attestations or validation artifacts under separate standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS.

Why it matters

The Attestation of Compliance is the artifact that other parties actually rely on to confirm an entity's PCI DSS validation status. Acquirers, payment processors, and larger merchants routinely request an AOC from the organizations they do business with, because it provides a signed, standardized summary of the assessment outcome without requiring the recipient to review the full underlying Report on Compliance or Self-Assessment Questionnaire. In practice, the AOC functions as the shareable proof of validation, while the more detailed assessment documentation remains more sensitive and is exchanged more selectively.

Because the AOC declares compliance status as of a specific assessment and scope, its accuracy matters. An AOC that misstates the assessed environment, the validation type, or the applicable requirements can give downstream parties a false sense of assurance. It is important to recognize that an AOC reflects the outcome of a point-in-time validation against the PCI DSS requirements that were in effect for that assessment; it is not a continuous guarantee of security, and it does not by itself address controls governed by separate standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS.

Because AOC templates, form variants, and requirement wording differ by PCI DSS version and by validation type, both the party completing the AOC and the party relying on it should confirm the current published PCI SSC form rather than assuming a fixed format. Treating an AOC as a durable certification, rather than a declaration tied to a particular assessment period and scope, is a common source of misunderstanding in vendor and merchant risk reviews.

Who it's relevant to

Merchants
Merchants complete or receive an AOC as the formal declaration of their PCI DSS validation outcome. Where a merchant's internal audit function performs the validation, the merchant itself may complete the AOC; otherwise a QSA typically completes it. Merchants should ensure the assessment scope and validation type reflected on the form match their actual environment.
Qualified Security Assessors (QSAs)
QSAs complete the AOC as part of the validation process, attesting to the assessment results for a defined entity and scope. They must use the current PCI SSC form appropriate to the validation type and PCI DSS version, and ensure the AOC aligns with the accompanying Report on Compliance or Self-Assessment Questionnaire.
Acquirers and payment processors
Acquirers and processors often request an AOC to confirm a merchant's or service provider's PCI DSS validation status. They rely on the AOC as a shareable summary of the outcome, but should recognize it reflects a point-in-time assessment against a specific scope and version rather than a continuous guarantee.
Merchant risk and compliance teams
Compliance officers and vendor risk teams use AOCs to assess the PCI DSS status of partners and vendors. They should verify that the AOC matches the current published PCI SSC form, covers the relevant scope, and is not confused with validation artifacts under separate standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, or PCI 3DS.

Inside AOC

Assessment Result
A declaration of the compliance status resulting from a PCI DSS assessment, indicating whether the assessed entity was found compliant, non-compliant, or compliant with legal exception at the time of the assessment.
Entity and Assessor Identification
Details identifying the assessed entity (merchant or service provider) and, where applicable, the Qualified Security Assessor (QSA) or Internal Security Assessor (ISA) involved, along with signatures affirming the accuracy of the attestation.
Assessment Type and Scope Summary
A description of the environment assessed, the type of assessment performed, and a summary of the cardholder data environment covered, noting that scope depends on how systems store, process, or transmit account data.
Reference to Underlying Documentation
A linkage to the corresponding Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ), which contains the detailed findings; the AOC summarizes rather than replaces that supporting evidence.
Attestation Signatures and Date
Signed affirmations by the responsible parties as of a specific date, reflecting compliance status at that point in time rather than a continuous guarantee of ongoing compliance.
Form Version Correspondence
An indication of which PCI DSS version and which AOC form template were used, since form structure and content differ between versions and readers should confirm against the current published standard.

Common questions

Answers to the questions practitioners most commonly ask about AOC.

Does an AOC by itself prove that an organization is fully PCI DSS compliant?
No. The AOC is a summary attestation that accompanies the underlying assessment documentation, such as a Report on Compliance (ROC) or the relevant Self-Assessment Questionnaire (SAQ). It attests to the results of an assessment at a point in time; it is not a substitute for the detailed evidence, and compliance status can change as environments, scope, and the published standard evolve. Readers should treat the AOC as one component of a larger validation package rather than standalone proof.
Is the AOC the same thing as the Report on Compliance (ROC)?
No, they are separate documents that serve different purposes. The ROC (or the applicable SAQ) contains the detailed assessment findings and evidence, while the AOC is a shorter form that summarizes and attests to the outcome. They are typically used together, and the AOC references the assessment it corresponds to. Confirm the current required forms and formats against the standard and program materials published at the time of your assessment.
Who is required to sign the AOC?
The AOC generally includes attestation sections to be completed by the assessed entity and, where an assessment was performed by a qualified assessor, by that assessor. The specific signatories, roles, and sections vary by the type of assessment and the form version in use. Confirm the exact signing requirements against the current AOC template for your assessment type rather than assuming a fixed structure.
Which AOC form applies to my organization?
The applicable AOC corresponds to the assessment path you followed, for example an AOC associated with a ROC for a full assessment, or the AOC form tied to the specific SAQ type that matches your environment and eligibility criteria. Because eligibility for a given SAQ depends on how you accept and handle account data, determine your correct assessment path first, then use the matching AOC. Verify current form availability and version with your acquirer or the relevant payment brand program.
How long is an AOC valid, and how often must it be renewed?
An AOC reflects the state of the assessment at the time it was completed. Validation cadence and how long a given attestation is accepted are driven by the requirements of the entities requesting it, such as acquirers or payment brands, and by their program rules, which vary by region and change over time. Confirm the accepted validity period and renewal expectations directly with the party requesting your AOC.
Who typically requests an AOC and how is it shared?
An AOC is commonly requested by acquirers, payment brands, or partners assessing a service provider or merchant relationship, and service providers may share it with customers who rely on their services for scope purposes. Because it summarizes compliance status, treat it as sensitive and share it through channels agreed with the requesting party. Follow the distribution expectations set by your acquirer or the relevant program rather than assuming a single standard process.

Common misconceptions

An AOC proves the entity is permanently secure and free from breach.
An AOC attests to compliance status as of the assessment date against a specific version of PCI DSS. It is a point-in-time declaration and does not guarantee ongoing compliance or that a breach cannot occur; compliance and security are related but not equivalent.
The AOC and the Report on Compliance (or SAQ) are the same document.
The AOC is a summary attestation, while the ROC or SAQ contains the detailed assessment findings and evidence. The AOC references and depends on that underlying documentation and does not substitute for it.
PCI DSS AOC covers validation under all PCI standards.
An AOC pertains to PCI DSS. Other PCI standards such as PCI P2PE, PCI PIN, PCI 3DS, or the PCI Software Security Framework have their own validation and attestation processes; a PCI DSS AOC does not attest to compliance with those separate standards.

Best practices

Confirm the AOC references the current published PCI DSS version and the correct form template, since requirement numbering, wording, and form structure differ between versions.
Ensure the scope summary in the AOC accurately reflects the systems that store, process, or transmit account data, and verify it aligns with the underlying ROC or SAQ.
Retain and cross-reference the corresponding ROC or SAQ, treating the AOC as a summary that depends on that detailed supporting documentation.
Treat the AOC as a point-in-time attestation and maintain compliance activities continuously rather than relying on the signed date as evidence of ongoing security.
Verify that signatures and identification of the assessed entity and any QSA or ISA are complete and accurate before submitting the AOC to acquirers, processors, or card brands.
When compliance was achieved with a legal exception or specific conditions, ensure these are clearly documented so recipients interpret the attestation correctly.