Definition
ROC
A ROC, or Report on Compliance, is the formal document a Qualified Security Assessor produces after auditing a large merchant or service provider against PCI DSS. It records how each requirement was tested, what evidence supported the conclusion, and whether every control was in place. High-volume organizations, typically Level 1 merchants, need a ROC rather than a self-assessment because the stakes and transaction counts are far higher. The report feeds an Attestation of Compliance that the company shares with its acquiring bank and card brands. A ROC is thorough by design, so preparation usually spans months of evidence gathering and remediation.
Related services
Keep exploring
← Back to the full glossary