TL;DR: PCI DSS Report on Compliance preparation for Level 1 merchants
- Level 1 merchants treat the RoC as a signed piece of paper. QSAs treat it as 400 pages of evidence. The gap between those two beliefs is where the engagement adds three months and a six-figure line item.
- A RoC covers all 12 PCI DSS requirements, is signed by a QSA, and typically runs $50,000 to $250,000 in fees alone. First-time engagements take three to six months, and QSAs report 6.4.3 and 11.6.1 as the two requirements clients underestimate most heavily going in.
- If you are a Level 1 merchant or a service provider heading into a RoC, get the seven artifacts, especially the 6.4.3 script inventory and 11.6.1 header monitoring, in place before the QSA arrives. If the QSA is already on-site, cside can produce the missing client-side evidence continuously so the assessment writes controls rather than reconstructs them.
A PCI DSS Report on Compliance (RoC) is the formal audit document a Qualified Security Assessor produces after evaluating an entity against every applicable PCI DSS requirement. It replaces the merchant's self-attestation with third-party validation. Level 1 merchants and all service providers file a RoC annually. Smaller merchants file a Self-Assessment Questionnaire instead.
Who has to file a RoC
The card brands split merchants into levels based on transaction volume:
| Level | Trigger | Compliance validation |
|---|---|---|
| 1 | Over 6M transactions/year (Visa/Mastercard) or any merchant designated Level 1 after a breach | Annual RoC signed by QSA + quarterly network scans by ASV |
| 2 | 1M-6M transactions/year | Annual SAQ (D preferred) + quarterly ASV scans |
| 3 | 20K-1M e-commerce transactions/year | Annual SAQ + quarterly ASV scans |
| 4 | Fewer than 20K e-commerce or 1M total | Annual SAQ, ASV scans as required |
| Service Provider (any) | Any entity that stores, processes, or transmits cardholder data on behalf of others | Annual RoC signed by QSA |
If you are a Level 1 merchant or any service provider, a QSA is going to sit in your environment for weeks. Preparing before they arrive determines whether that engagement produces a signed RoC or a list of findings.
What a RoC actually contains
The RoC follows a strict template published by the PCI Security Standards Council. The current version for PCI DSS 4.0.1 is roughly 400 pages when completed and covers:
- Scope of the assessment (which systems store, process, or transmit cardholder data)
- Description of the cardholder data environment
- Network diagrams and data-flow diagrams
- Evidence for every applicable requirement and sub-requirement
- Compensating controls where a requirement cannot be met directly
- Findings summary and executive attestation
The QSA does not accept "we do this" as evidence. Every control needs artifacts: configuration exports, screenshots, log samples, policy documents, code review evidence, and interview notes.
Where most RoCs get stuck: client-side controls
PCI DSS 4.0.1 formalized requirements 6.4.3 and 11.6.1, which govern client-side script inventory and payment page monitoring. Both require evidence that would not have existed at all before 2025 in most environments: a complete inventory of every script on every payment page, business justification for each, integrity verification, and detection of unauthorized change.
Most QSAs report that 6.4.3 and 11.6.1 are the two requirements clients underestimate most heavily going into a RoC engagement. See our practical guide to complying with PCI 6.4.3 and 11.6.1 and the QSA guide for what auditors specifically look for.
Preparation checklist
Before the QSA arrives, get these seven artifacts in order:
- Scope document: every system in the cardholder data environment, every network segment, every third-party connection
- Network and data-flow diagrams: current, accurate, dated
- Script inventory for payment pages: the 6.4.3 artifact
- Change-monitoring evidence for payment pages: the 11.6.1 artifact
- HTTP header monitoring evidence: required by 11.6.1
- Policy set: information security, access control, incident response, vendor management, change management
- Prior year's assessment or SAQ: QSAs read the prior findings first
If any of the first four are missing or manual, the QSA engagement will spend billable weeks reconstructing them.
Where cside fits
cside produces the 6.4.3 and 11.6.1 evidence a QSA needs to sign off on those requirements: a continuous inventory of every script on every payment page, business justification tags, integrity monitoring, and change detection with alert history. The PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 compliance guide walks through what the dashboard produces and how a QSA reads it.
The VikingCloud approval validated the platform against 4.0.1 with a top-tier QSA firm, which is the fastest path to satisfying that section of the RoC.
The one thing that shortens a RoC
Continuous compliance beats point-in-time remediation. A QSA who arrives to find scripts already inventoried, change history already logged, and integrity monitoring already in place spends the engagement writing up controls rather than helping the merchant build them. That difference is often measured in months.









