Attestation of Compliance (AOC)

An Attestation of Compliance (AOC) is a formal document that confirms an organization has been assessed against the PCI DSS standard and meets its applicable requirements. 

What is Attestation of Compliance (AOC) 

If your organization processes payment card data, demonstrating PCI DSS compliance is essential for building trust with customers and meeting payment industry requirements. The Attestation of Compliance (AOC) serves as the official record of a successful PCI DSS assessment, providing customers, payment processors, acquiring banks, and business partners with evidence that your organization has validated its compliance.

Because the AOC follows a standardized format defined by the PCI Security Standards Council (PCI SSC), stakeholders can quickly understand the scope of the assessment, the validation method used, and the overall assessment outcome. Organizations commonly share the AOC during customer security reviews, vendor onboarding, and other due diligence processes to demonstrate their payment security posture.

Unlike a Report on Compliance (ROC), the AOC does not include detailed technical findings, testing procedures, or control-level evidence. Instead, it provides a concise summary of the assessment, making it the primary document organizations share when demonstrating PCI DSS compliance to external parties.

Requirements for an Attestation of Compliance (AOC) 

To receive an Attestation of Compliance (AOC), an organization must first complete the appropriate PCI DSS assessment. The assessment evaluates the organization’s security controls, payment environment, policies, procedures, and supporting evidence against the PCI DSS 4.0 requirements. 

Once any identified gaps have been addressed, the organization can complete its PCI DSS validation and receive an AOC confirming its compliance status. Because PCI DSS compliance must be validated annually, the AOC must also be renewed each year.

SAQ vs. ROC 

The path to obtaining an AOC depends on your organization’s PCI DSS validation requirements, which are determined by factors such as merchant level, transaction volume, and role in the payment ecosystem. Smaller merchants and eligible service providers typically validate compliance using a Self-Assessment Questionnaire (SAQ), while larger organizations generally require a Report on Compliance (ROC) completed by a Qualified Security Assessor (QSA). Although the assessment process differs, both validation paths result in an AOC. 

Validation pathSAQ + AOCROC + AOC
Who it’s forLower-level merchants and eligible service providersLarge merchants and service providers requiring a full assessment
Assessment methodSelf-Assessment Questionnaire (SAQ)On-site assessment by a Qualified Security Assessor (QSA)
Level of detailSelf-validated questionnaireComprehensive Report on Compliance (ROC)
OutcomeAttestation of Compliance (AOC)Attestation of Compliance (AOC)
SAQ vs. ROC

Creating an AOC Document and Report

Obtaining an Attestation of Compliance (AOC) begins with completing the appropriate PCI DSS assessment. The process typically involves the following steps:

  • A Qualified Security Assessor (QSA), or the organization through a Self-Assessment Questionnaire (SAQ), evaluates the organization’s security controls, policies, procedures, and cardholder data environment against PCI DSS requirements.
  • The assessment identifies any compliance gaps or areas that require remediation before the organization’s PCI DSS compliance program can be successfully validated.
  • Once all applicable PCI DSS requirements have been met, an AOC is completed to formally confirm the organization’s compliance status.

What’s Included in the AOC Document 

While the exact format varies depending on the organization and assessment type, most AOC documents contain the same core information. Together, these sections summarize the PCI DSS assessment, document the organization’s compliance status, and provide evidence of the security controls that support continuous compliance. A typical AOC includes: 

Merchant or service provider information

Basic details about the organization, including its name, business type, contact information, and PCI DSS validation method.

Executive summary

A high-level overview of the PCI DSS assessment, including the scope of the review and the organization’s overall compliance status.

QSA or ISA findings

A summary of the Qualified Security Assessor’s (QSA) or Internal Security Assessor’s (ISA) evaluation, confirming whether the organization meets the applicable PCI DSS requirements.

Attestation and signatures

The formal declaration of compliance, signed by the assessor and, where required, an authorized representative of the organization, verifying the accuracy of the assessment and compliance status.

AI-native GRC for how teams work today.

Scytale G2 badge

Role of AOC in PCI DSS Compliance

An AOC serves several important functions beyond validating PCI DSS compliance. Here are the key roles it plays for organizations and their stakeholders: 

1. Supports security reviews 

Customers, payment processors, acquiring banks, and business partners often request an AOC during security reviews or before establishing a business relationship. Providing a current AOC helps speed up the review process and demonstrates adherence to recognized PCI DSS requirements

2. Simplifies compliance verification

Rather than completing lengthy security questionnaires for every request, organizations can use an AOC as standardized evidence that they have successfully validated their PCI DSS compliance.

3. Builds trust

A current AOC gives stakeholders confidence that the organization has implemented appropriate safeguards to protect cardholder data, helping strengthen customer trust and support long-term business relationships.

Simplify PCI DSS Compliance with Scytale

Scytale’s AI-powered GRC platform helps organizations streamline PCI DSS compliance by automating evidence collection, centralizing documentation, and continuously monitoring security controls. Whether you’re preparing for an initial assessment or renewing your AOC, Scytale keeps your compliance program organized, audit-ready, and aligned with PCI DSS requirements.

Combined with dedicated GRC expert guidance, Scytale simplifies every stage of the PCI DSS journey, from gap assessments and remediation to audit preparation and ongoing compliance. The result is less manual work, greater visibility into your security posture, and a faster path to maintaining PCI DSS year after year.