Definition

ROC

A ROC, or Report on Compliance, is the formal document a Qualified Security Assessor produces after auditing a large merchant or service provider against PCI DSS. It records how each requirement was tested, what evidence supported the conclusion, and whether every control was in place. High-volume organizations, typically Level 1 merchants, need a ROC rather than a self-assessment because the stakes and transaction counts are far higher. The report feeds an Attestation of Compliance that the company shares with its acquiring bank and card brands. A ROC is thorough by design, so preparation usually spans months of evidence gathering and remediation.

FINAUDIT CPA · ASSURANCE · VERIFIED · INDEPENDENT ·

Ready when you are

Ready to make trust your competitive advantage?

One licensed CPA firm for your SOC, ISO, HIPAA, and VAPT programs — and the financial audits behind them. Talk to a senior auditor, not a sales rep.

Call Book a Consultation