ℹ️
Reference Content: This is a copy of content from the PCI Security Standards Council FAQ database, preserved for tracking changes over time.
View Original →
FAQ #1375 Published

Can an Attestation of Compliance (AOC) be provided to an assessed entity before the Report on Compliance (ROC) is finalized?

No, an Attestation of Compliance (AOC) cannot be provided to an assessed entity before the Report on Compliance (ROC) is finalized. The AOC must be completed as a declaration of the results of the assessment with the Payment Card Industry Data Security Standard Requirements and Security Assessment Procedures (PCI DSS).  Within "Section 2: Report on Compliance" of the AOC, it is stated that the AOC "reflects the results of an onsite assessment, which is documented in an accompanying Report on Compliance (ROC)" and there the assessor must provide the date of the assessment documented in the attestation and in the ROC, which again enforces the intent that the ROC is finalized prior to the execution of the AOC.  

Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.