Skip to main content
Blog
Blog

PCI DSS Report on Compliance (RoC): What It Is and When You Need One

A PCI DSS Report on Compliance is required for Level 1 merchants and service providers. Learn what a RoC covers, who signs it, and how to prepare.

Aug 18, 2026 5 min read
PCI DSS Report on Compliance (RoC): What It Is and When You Need One

TL;DR: PCI DSS Report on Compliance preparation for Level 1 merchants

  • Level 1 merchants treat the RoC as a signed piece of paper. QSAs treat it as 400 pages of evidence. The gap between those two beliefs is where the engagement adds three months and a six-figure line item.
  • A RoC covers all 12 PCI DSS requirements, is signed by a QSA, and typically runs $50,000 to $250,000 in fees alone. First-time engagements take three to six months, and QSAs report 6.4.3 and 11.6.1 as the two requirements clients underestimate most heavily going in.
  • If you are a Level 1 merchant or a service provider heading into a RoC, get the seven artifacts, especially the 6.4.3 script inventory and 11.6.1 header monitoring, in place before the QSA arrives. If the QSA is already on-site, cside can produce the missing client-side evidence continuously so the assessment writes controls rather than reconstructs them.

A PCI DSS Report on Compliance (RoC) is the formal audit document a Qualified Security Assessor produces after evaluating an entity against every applicable PCI DSS requirement. It replaces the merchant's self-attestation with third-party validation. Level 1 merchants and all service providers file a RoC annually. Smaller merchants file a Self-Assessment Questionnaire instead.

Who has to file a RoC

The card brands split merchants into levels based on transaction volume:

LevelTriggerCompliance validation
1Over 6M transactions/year (Visa/Mastercard) or any merchant designated Level 1 after a breachAnnual RoC signed by QSA + quarterly network scans by ASV
21M-6M transactions/yearAnnual SAQ (D preferred) + quarterly ASV scans
320K-1M e-commerce transactions/yearAnnual SAQ + quarterly ASV scans
4Fewer than 20K e-commerce or 1M totalAnnual SAQ, ASV scans as required
Service Provider (any)Any entity that stores, processes, or transmits cardholder data on behalf of othersAnnual RoC signed by QSA

If you are a Level 1 merchant or any service provider, a QSA is going to sit in your environment for weeks. Preparing before they arrive determines whether that engagement produces a signed RoC or a list of findings.

What a RoC actually contains

The RoC follows a strict template published by the PCI Security Standards Council. The current version for PCI DSS 4.0.1 is roughly 400 pages when completed and covers:

  • Scope of the assessment (which systems store, process, or transmit cardholder data)
  • Description of the cardholder data environment
  • Network diagrams and data-flow diagrams
  • Evidence for every applicable requirement and sub-requirement
  • Compensating controls where a requirement cannot be met directly
  • Findings summary and executive attestation

The QSA does not accept "we do this" as evidence. Every control needs artifacts: configuration exports, screenshots, log samples, policy documents, code review evidence, and interview notes.

Where most RoCs get stuck: client-side controls

PCI DSS 4.0.1 formalized requirements 6.4.3 and 11.6.1, which govern client-side script inventory and payment page monitoring. Both require evidence that would not have existed at all before 2025 in most environments: a complete inventory of every script on every payment page, business justification for each, integrity verification, and detection of unauthorized change.

Most QSAs report that 6.4.3 and 11.6.1 are the two requirements clients underestimate most heavily going into a RoC engagement. See our practical guide to complying with PCI 6.4.3 and 11.6.1 and the QSA guide for what auditors specifically look for.

Preparation checklist

Before the QSA arrives, get these seven artifacts in order:

  1. Scope document: every system in the cardholder data environment, every network segment, every third-party connection
  2. Network and data-flow diagrams: current, accurate, dated
  3. Script inventory for payment pages: the 6.4.3 artifact
  4. Change-monitoring evidence for payment pages: the 11.6.1 artifact
  5. HTTP header monitoring evidence: required by 11.6.1
  6. Policy set: information security, access control, incident response, vendor management, change management
  7. Prior year's assessment or SAQ: QSAs read the prior findings first

If any of the first four are missing or manual, the QSA engagement will spend billable weeks reconstructing them.

Where cside fits

cside produces the 6.4.3 and 11.6.1 evidence a QSA needs to sign off on those requirements: a continuous inventory of every script on every payment page, business justification tags, integrity monitoring, and change detection with alert history. The PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 compliance guide walks through what the dashboard produces and how a QSA reads it.

The VikingCloud approval validated the platform against 4.0.1 with a top-tier QSA firm, which is the fastest path to satisfying that section of the RoC.

The one thing that shortens a RoC

Continuous compliance beats point-in-time remediation. A QSA who arrives to find scripts already inventoried, change history already logged, and integrity monitoring already in place spends the engagement writing up controls rather than helping the merchant build them. That difference is often measured in months.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

FAQ

Frequently Asked Questions

A Report on Compliance is the formal documentation a Qualified Security Assessor (QSA) produces after auditing an entity against all 12 PCI DSS requirements. It replaces the merchant's or service provider's self-attestation with a third-party validation. The RoC is required for Level 1 merchants (over 6 million transactions per year) and for all service providers regardless of size. It runs to hundreds of pages and covers evidence for every applicable requirement and sub-requirement.

Level 1 merchants (over 6 million transactions per year, or any merchant Visa or Mastercard designates Level 1) must submit a RoC annually, signed by a QSA. All service providers must submit a RoC annually. Level 2, 3, and 4 merchants typically complete a Self-Assessment Questionnaire instead, though card brands can require a RoC in response to a breach or elevated risk. If you are unsure of your level, ask your acquirer; they set it based on transaction volume.

A first-time RoC engagement typically runs three to six months from scoping to signed report. Ongoing annual assessments are shorter, usually six to ten weeks, once the QSA is familiar with the environment and controls are stable. Remediation work discovered during the assessment can extend the timeline significantly, particularly for client-side controls under requirements 6.4.3 and 11.6.1, which are newer to most environments.

QSA fees for a full RoC assessment typically range from $50,000 to $250,000 depending on scope, environment complexity, number of locations, and whether remediation is included. Larger service providers and merchants with complex payment stacks fall at the top of that range. Add internal engineering time for remediation, tooling costs for continuous compliance monitoring, and legal review. The total cost of a compliance program is usually two to five times the QSA fee alone.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo