Report on Compliance
A Report on Compliance (ROC) is a formal document that records the results of a detailed PCI DSS assessment of an organization, describing how well it meets the standard's security requirements. It is typically produced during an onsite assessment and is used as part of the process for demonstrating, or validating, PCI DSS compliance. It can apply to merchants and service providers, and is often prepared with the involvement of an external assessor.
The Report on Compliance (ROC) is the documented output of a PCI DSS assessment, produced during onsite assessments as part of an entity's validation process, using the ROC Reporting Template published by the PCI Security Standards Council for the applicable PCI DSS version. It records detailed findings on the entity's adherence to PCI DSS requirements, including scope, tested controls, and the assessor's conclusions for each requirement. According to the evidence, it may be performed for both merchants and service providers and is described as being conducted by an external Qualified Security Assessor; assessment frequency, eligibility, and whether a ROC versus a Self-Assessment Questionnaire applies are governed by acquirer and payment brand program rules and are not determined by PCI DSS alone. Note that ROC template structure, requirement numbering, and reporting instructions differ between PCI DSS versions, so practitioners should confirm details against the current published reporting template rather than assuming a fixed format. The ROC is a validation and reporting artifact and is distinct from the underlying PCI DSS control requirements themselves and from other PCI standards such as PA-DSS, the PCI Software Security Framework, PCI PIN, PCI P2PE, and PCI 3DS.
Why it matters
The Report on Compliance is the primary artifact through which an organization demonstrates, in detail, that its handling of payment card data was assessed against PCI DSS requirements. Unlike a simple attestation, the ROC records scope, the controls that were tested, and the assessor's conclusions for each requirement, giving acquirers and payment brands a documented basis for evaluating an entity's validation. For merchants and service providers whose programs call for an onsite assessment, the ROC is often the difference between a compliance claim that can be independently reviewed and one that cannot.
Because the ROC captures scope and per-requirement findings, it also functions as a working record of where an entity's cardholder data environment begins and ends and how its controls were evaluated at a point in time. That makes it relevant well beyond the assessment itself: it informs remediation planning, supports discussions with acquirers, and provides a reference for the next assessment cycle. It is important to remember, however, that a ROC is a validation and reporting document, not a guarantee of security; it reflects the state of controls as assessed and does not by itself eliminate risk or fraud.
Whether a given entity needs a ROC at all, and how often, is governed by acquirer and payment brand program rules rather than by PCI DSS alone. Some entities validate through a Self-Assessment Questionnaire instead. Practitioners should also note that the ROC Reporting Template, requirement numbering, and reporting instructions differ between PCI DSS versions, so the exact structure and expectations should be confirmed against the current published template rather than assumed from a prior engagement.
Who it's relevant to
Inside ROC
Common questions
Answers to the questions practitioners most commonly ask about ROC.