A PCI DSS Attestation of Compliance (AoC) is a formal document that records the outcome of a PCI DSS assessment. When an organization is assessed as compliant, the AoC states that it met the applicable PCI DSS requirements within the defined assessment scope.

Merchants and service providers that process, store, or transmit payment card data may be required to provide an AoC as evidence of compliance. The precise validation and submission requirements depend on the applicable payment brands, acquiring bank, contractual arrangements, transaction volumes, and assessment program.

The AoC identifies the organization being assessed, the assessment scope, the assessment method, the applicable PCI DSS version, and the compliance status. It is normally completed alongside a Self-Assessment Questionnaire (SAQ) or a Report on Compliance (RoC).

This article explains what an AoC does, who may need one, how the PCI DSS assessment process works, how to prepare for and maintain compliance, how an AoC differs from a Report on Compliance, the common issues that slow validation, and how to complete the attestation process more efficiently.

An AoC may also carry contractual or commercial significance. An organization that cannot provide requested evidence of PCI DSS compliance may face consequences under its acquiring agreement, payment-brand program, customer contracts, or insurance terms. The exact consequences depend on the applicable agreements, rules, circumstances, and law.

DSS Attestation of Compliance

A PCI DSS AoC is an industry-specific document based on templates published by the PCI Security Standards Council (PCI SSC). It has several features that distinguish it from more general attestations or certifications:

  • The PCI DSS assessment framework is maintained by a private industry standards organization rather than a governmental agency.
  • PCI DSS AoCs use standardized templates. Annual compliance validation is commonly required, although an AoC records assessment results at a particular point in time rather than serving as a certificate that guarantees compliance for a fixed 12-month period.
  • The attestation process addresses the protection of payment account data within the defined PCI DSS assessment scope.
  • PCI DSS applies to entities that store, process, or transmit payment account data, as well as entities that can affect the security of the cardholder data environment. Formal assessment and AoC submission requirements depend on the applicable payment brand, acquirer, and contractual rules.
  • Compliance programs are generally administered by payment brands and acquiring banks. Depending on applicable rules and agreements, non-compliance may result in contractual penalties, increased fees, additional validation requirements, or restrictions on card-processing privileges.

The AoC is an attestation of the assessment results and uses information from an SAQ or RoC. The SAQ or RoC contains the detailed evaluation of the organization’s security controls, while the AoC provides a standardized summary of the assessment scope, method, and outcome.

The AoC should not be described as a general PCI DSS certification or as a guarantee of continuing compliance. It records the assessment result based on the environment and evidence reviewed during the assessment period.

Who Needs a PCI Attestation to Determine Compliance?

Entities that process, store, or transmit cardholder data must comply with applicable PCI DSS requirements. Not every entity is required to submit the same validation documents.

Whether a merchant must complete an SAQ, undergo a formal assessment, prepare an RoC, or submit an AoC depends on the merchant’s payment brands, acquiring bank, transaction volumes, risk profile, contractual obligations, and any instructions from the entity receiving the compliance documentation.

Merchants with lower transaction volumes may be permitted to complete an eligible SAQ and the associated AoC. Higher-volume or higher-risk merchants may be required to complete an RoC, frequently with the involvement of a Qualified Security Assessor (QSA). The specific assessment method should be confirmed with the merchant’s acquirer or payment brands.

Service providers, including payment gateways and cloud service providers, may also be required to complete an AoC. Service providers are generally evaluated under separate payment-brand classification and validation programs rather than receiving the compliance level of the merchants they support.

Merchants that have experienced a cardholder-data compromise or have been identified as presenting additional risk may be required to follow a higher level of validation. Companies should review the specific requirements of their payment brands and acquiring banks.

Determine Compliance Level and Assessment Methodology

Merchant validation levels are established by individual payment brands and acquiring banks rather than universally defined by the PCI Security Standards Council. The thresholds and requirements can therefore differ between payment programs.

The following levels reflect the commonly cited Visa merchant-level framework and should not be treated as universal PCI SSC classifications:

Level 1

Level 1 generally covers merchants processing more than six million Visa transactions annually. A merchant may also be assigned Level 1 status following a cardholder-data compromise or when Visa or an acquiring bank determines that additional validation is appropriate.

Level 1 merchants are generally required to complete an RoC and the associated AoC. A QSA often performs the assessment, although the specific assessor and validation requirements depend on the applicable payment brand and acquirer rules.

The assessed organization’s authorized representative signs the AoC. When a QSA or other approved assessor performs the assessment, the relevant assessor representatives also complete and sign the applicable sections.

Level 2

Level 2 generally covers merchants processing between one million and six million Visa transactions annually.

Subject to payment-brand and acquirer rules, these merchants may be permitted to complete an eligible SAQ and associated AoC instead of undergoing a QSA-led RoC assessment.

Level 3

Level 3 generally covers merchants processing between 20,000 and one million Visa e-commerce transactions annually.

Subject to payment-brand and acquirer rules, these merchants may be permitted to complete an annual SAQ and associated AoC.

Level 4

Level 4 generally covers merchants processing fewer than 20,000 Visa e-commerce transactions annually or up to one million Visa transactions through other channels, such as physical stores or telephone orders.

The acquiring bank commonly determines the validation requirements for Level 4 merchants. An SAQ and associated AoC may be required or recommended depending on the applicable program.

Companies must confirm their assessment and submission requirements with their acquiring bank or payment brands rather than relying solely on transaction-volume thresholds.

Self-Assessment Path

The self-assessment path generally includes the following steps:

  • Confirming with the acquirer or payment brand that the organization is eligible to self-assess;
  • Determining the correct SAQ for the organization’s payment environment;
  • Completing the applicable testing and questionnaire;
  • Completing any required Approved Scanning Vendor scans;
  • Remediating identified compliance gaps and vulnerabilities;
  • Completing and signing the associated AoC through an authorized organizational representative; and
  • Submitting the SAQ, AoC, scan documentation, or other materials requested by the acquiring bank, payment brand, or customer.

The representative signing the AoC must have sufficient authority to bind the organization legally. The signer does not necessarily need to hold a particular job title such as “executive officer,” unless the applicable form or compliance program specifies otherwise.

QSA-Led Assessment Path

A QSA-led assessment generally requires the organization to take the following steps:

  • Engage a QSA Company listed by the PCI Security Standards Council;
  • Accurately define the cardholder data environment and assessment scope;
  • Provide the QSA with access to relevant systems, personnel, documentation, and evidence;
  • Allow the QSA to evaluate the environment and applicable security controls using on-site and, where appropriate, remote assessment techniques;
  • Support independent testing of the applicable PCI DSS controls;
  • Address any gaps identified during the assessment;
  • Complete a detailed RoC covering the applicable PCI DSS requirements;
  • Review and sign the assessed entity’s sections of the AoC;
  • Obtain the applicable QSA signatures; and
  • Submit the AoC, RoC, or other requested documentation to the acquiring bank, payment brands, customers, or other receiving entities.

The QSA does not sign the AoC solely on behalf of the merchant or service provider. The assessed organization and the assessor each complete and sign the sections applicable to their responsibilities.

How to Prepare for a Compliance Assessment

Organizations should prepare for a PCI DSS assessment by performing several activities related to their payment account data and cardholder data environment.

Map Cardholder Data Flows

Teams should map cardholder-data flows to identify the scope of the cardholder data environment, including the systems, applications, people, and processes involved in storing, processing, or transmitting cardholder data.

Systems that can connect to or affect the security of the cardholder data environment may also be in scope, even when they do not directly store cardholder data.

Teams should apply the required security controls to all systems and processes included in the assessment scope.

Consider Network Segmentation

Organizations may use network segmentation to isolate the cardholder data environment from other networks.

Segmentation is strongly recommended because properly implemented segmentation can reduce PCI DSS scope, security risk, and assessment effort. Network segmentation is not, by itself, a universal PCI DSS requirement.

Where segmentation is used to reduce scope, the organization must verify that the controls effectively isolate the cardholder data environment.

Collect Documentation and Evidence

Companies should collect PCI-relevant policies, procedures, system configurations, scan reports, testing records, access reviews, training records, and other evidence in a secure repository.

Centralizing this information can make it easier to complete an SAQ or support a QSA-led assessment.

Conduct Readiness Reviews

Businesses should conduct internal readiness reviews to identify gaps in security controls before beginning the formal validation process.

Internal audit, compliance, security, or other qualified personnel may support these reviews. An internal audit department is not universally required to complete every self-assessment.

Assessment Methodology

Whether an organization uses an SAQ or undergoes a QSA-led assessment, it must evaluate the PCI DSS requirements applicable to its environment and document the results.

When a QSA is not involved, the organization performs a self-assessment using qualified personnel and the applicable SAQ instructions. Internal audit may support the assessment, but it is not automatically the function responsible for validation.

External vulnerability scans by an Approved Scanning Vendor must be completed when required by the applicable PCI DSS requirements and validation path. Internal vulnerability scanning and penetration testing must also be performed where the applicable requirements call for them.

Vulnerability scans and penetration tests are not automatically required for every AoC or SAQ. Their applicability depends on the organization’s environment, assessment scope, SAQ eligibility, and relevant PCI DSS requirements.

During an assessment, the assessor may interview subject-matter experts responsible for maintaining the payment environment. These interviews help the assessor understand the implemented controls and resolve discrepancies between documentation, observed practices, and technical evidence.

What the AoC Document Contains

The precise structure varies between merchant and service-provider forms, but an AoC commonly includes the following sections:

Assessment Information

This section identifies the entity being assessed, the organization performing the assessment, the applicable PCI DSS version, relevant dates, and the type and scope of the assessment.

Supporting assessment information may come from either a self-assessment or an independent assessor-led review.

Executive Summary

The executive summary describes the organization’s payment environment and how it stores, processes, or transmits account data.

It may identify:

  • The assessment methodology;
  • The cardholder data environment;
  • Relevant business locations;
  • Payment channels;
  • Service providers;
  • Network segmentation;
  • Technologies used in the environment; and
  • Requirements determined not to be applicable, together with the supporting explanation.

Validation and Attestation Details

This section records the assessment result and confirms the accuracy of the information provided.

The assessed entity’s authorized representative signs the applicable attestation. When a QSA, Internal Security Assessor, or another approved assessor participates, the relevant assessor signatures are also included where required.

Action Plan for Non-Compliant Requirements

An action plan may be included when requirements are marked non-compliant, and the receiving entity requests one.

The action plan may identify:

  • The non-compliant requirements;
  • A description of the identified gaps;
  • Planned remediation activities; and
  • Target remediation dates.

The action-plan section is not necessarily completed for every compliant assessment.

Companies may also be required to provide supporting documentation, including an SAQ, RoC, Approved Scanning Vendor reports, or other evidence requested by an acquiring bank, a payment brand, a customer, or a business partner.

PCI AoC vs. RoC

AoCs and RoCs are both PCI DSS compliance documents, but they differ significantly in purpose and scope.

An AoC is a standardized attestation summarizing the scope, assessment method, and outcome of the compliance assessment. Depending on the form and circumstances, the recorded status may include:

  • Compliant;
  • Non-Compliant;
  • Compliant with a Legal Exception;
  • Full assessment; or
  • Partial assessment.

For this reason, an AoC should not always be described as delivering only a simple pass-or-fail judgment.

The assessed entity completes and signs the applicable portions of the AoC. When a QSA or other approved assessor performs the assessment, that assessor also completes and signs the applicable sections.

An RoC is a detailed technical report describing the environment, assessment procedures, evidence reviewed, testing performed, and conclusions for the applicable PCI DSS requirements.

RoCs are commonly required for higher-volume merchants and certain service providers. The precise circumstances in which an RoC is mandatory—and who is permitted to perform the assessment—depend on the applicable payment brand, acquiring bank, and validation program rules.

A merchant that has experienced a cardholder data compromise may be required to complete an RoC or follow a higher validation level, but this is not an automatic, universal rule across all payment programs.

How Long Is an Attestation Valid?

PCI DSS compliance is not established once and then guaranteed for a fixed 12-month period.

An AoC records the result of an assessment conducted for a specified scope and assessment period. Payment brands, acquirers, and contractual programs commonly require organizations to revalidate compliance annually.

Organizations must maintain the applicable PCI DSS controls continuously between assessments. An AoC does not guarantee that the environment will remain compliant after the assessment is completed.

A change to the cardholder data environment or a cardholder data compromise may require additional testing, a scope review, or reassessment, depending on the applicable PCI DSS requirements and on instructions from the organization’s acquirer or payment brands.

Organizations should plan their annual reassessments to meet the submission deadlines set by the entity that receives their compliance documentation.

How to Complete the Attestation of Compliance Form

Businesses must select the correct AoC template for their assessment type and applicable PCI DSS version.

All organizational, assessment, and scope information must be accurately entered in the form.

An authorized representative of the assessed organization must review and sign the applicable portions of the document and accept responsibility for the accuracy of the information. When an assessor is involved, the assessor completes and signs the sections assigned to the assessor.

The organization should submit the AoC and any supporting documents to the parties that require them, such as an acquiring bank, a payment brand, a customer, or a business partner.

Maintaining Compliance After Attestation

Organizations must maintain PCI DSS compliance after completing an AoC. Compliance is an ongoing responsibility for businesses that accept or process payment cards.

Continuously Monitor the Environment

Teams should continuously monitor the cardholder data environment to ensure required security controls remain in place and operate effectively.

Logs, alerts, access reviews, configuration records, and other evidence should be retained according to applicable PCI DSS requirements and organizational policies.

Complete Required Security Testing

Companies should schedule external vulnerability scans with an Approved Scanning Vendor when required by their PCI DSS scope and validation path.

Internal vulnerability scanning, penetration testing, and other security testing should be performed at the frequencies and under the circumstances required by the applicable PCI DSS requirements.

Monitor Third-Party Service Providers

Businesses should obtain appropriate evidence that third-party service providers responsible for storing, processing, transmitting, or securing account data are meeting their PCI DSS responsibilities.

An AoC is one form of evidence that may be reviewed. The organization should also confirm:

  • The services and locations covered by the provider’s assessment;
  • The date and scope of the assessment;
  • Any excluded services;
  • The PCI DSS responsibilities assigned to the provider; and
  • The responsibilities retained by the customer.

Not every provider is required to make its AoC publicly available. Organizations should obtain appropriate evidence of compliance through contracts, due diligence processes, or direct requests.

Update the Assessment Scope

The organization should review and update its PCI DSS scope when systems, networks, applications, processes, locations, payment channels, or vendors change.

New components that store, process, transmit, or can affect the security of account data must be evaluated to determine whether they belong within the PCI DSS assessment scope.

Common Challenges in PCI Attestation and Compliance Assessment

Organizations should be aware of common issues that can delay an assessment or make it difficult to demonstrate PCI DSS compliance.

Scope Misidentification

Incorrectly defining the PCI DSS scope can create substantial compliance and security risks.

Scope errors may result from:

  • Underestimating connected systems that do not directly store cardholder data but can connect to or affect the cardholder data environment;
  • Relying on ineffective network segmentation;
  • Excluding legacy systems without sufficient evidence;
  • Allowing shadow IT solutions to bypass required security controls; or
  • Missing cardholder-data flows involving third parties.

Time Pressure

Companies may face time pressure when asked to collect evidence demonstrating PCI DSS compliance.

Organizations with extensive infrastructure or decentralized documentation may find it difficult to gather the policies, configurations, logs, test results, and other records needed to support an assessment.

Maintaining evidence throughout the year can reduce the burden during annual validation.

Control Drift After Initial Attestation

An AoC records the outcome of an assessment based on the environment and evidence reviewed during the assessment period. It does not ensure that controls will continue to operate effectively after the assessment.

Control drift may occur when:

  • Teams temporarily disable firewall rules or security controls;
  • Security patches are delayed;
  • The business introduces new systems or applications without applying PCI DSS controls;
  • Employees with critical security knowledge leave the organization;
  • Documentation is not updated;
  • Access privileges are not regularly reviewed; or
  • Required monitoring and testing activities are not maintained.

Organizations must continue to operate and monitor their controls after the assessment is complete.

Practical Tips to Obtain PCI Attestation Faster

Companies can take several steps to reduce the time and effort required to complete PCI DSS validation.

  • Use properly implemented network segmentation where appropriate to reduce the scope of the cardholder data environment.
  • Use automation to support evidence collection, control monitoring, vulnerability management, and recurring compliance activities.
  • Maintain PCI DSS documentation and evidence in a centralized, access-controlled repository.
  • Conduct internal readiness reviews to identify areas requiring remediation before beginning the formal assessment.
  • Engage a qualified Internal Security Assessor (QSA) or other appropriate specialist when additional expertise is needed.
  • Strengthen access controls to prevent unauthorized access to the cardholder data environment.
  • Schedule required QSA assessments early enough to allow identified issues to be remediated before submission deadlines.
  • Confirm the required validation path with the acquiring bank or payment brand before beginning the assessment.

Resources, Templates, and Next Steps

Organizations should contact their acquiring bank, payment brand, QSA, or another qualified PCI DSS specialist when they are uncertain about their validation obligations or the correct SAQ for their environment.

PCI SSC publishes separate AoC documents and reporting templates for:

  • Merchants; and
  • Service providers.

Organizations should use the current templates published in the PCI SSC document library and confirm that they are assessing against the currently supported PCI DSS version.

Companies may also review publicly available AoCs to understand how completed forms are structured. For example, Akamai Technologies has publicly posted a PCI DSS v4.0.1 AoC dated June 30, 2026.

Atlantic.Net states that its PCI-focused hosting services include security controls and that its provider AoC can be made available to customers. Using a compliant hosting provider may support an organization’s compliance activities, but it does not automatically make the customer PCI DSS compliant. Each customer remains responsible for its own systems, configurations, applications, processes, assessment scope, and shared-responsibility obligations.