When an e-commerce platform, digital marketplace, or financial software provider scales past six million annual transactions-or when enterprise payment partners mandate an on-site assessment-the compliance game changes fundamentally.
You can no longer submit a Self-Assessment Questionnaire (SAQ D). You must undergo a formal, on-site audit conducted by a licensed Qualified Security Assessor (QSA) resulting in an exhaustive Report on Compliance (ROC) and signed Attestation of Compliance (AOC).
For engineering and compliance leaders, transitioning to your first ROC can be jarring. In an SAQ, you affirm your own controls; in a ROC, an independent auditor demands tangible, forensic evidence and live sampling for every single control.
The Cost of an Unprepared ROC: If your QSA discovers unaddressed technical vulnerabilities, failed segmentation, or missing quarterly scanning logs, fieldwork halts. Remediating findings under audit pressure easily doubles project costs and risks missing your acquiring bank compliance deadline.
SAQ D vs. Report on Compliance (ROC): Key Differences
| Metric | SAQ D (Self-Assessment) | Report on Compliance (ROC) |
|---|---|---|
| Applicability | Level 2-4 merchants and eligible service providers. | Level 1 merchants (>6M transactions) and major service providers. |
| Assessor Role | Internal security lead signs the self-assessment. | Independent QSA leads on-site testing, interviews, and writes report. |
| Evidence Testing | Internal review of policies and system configs. | Statistical sampling of user accounts, firewall rule changes, and code pull requests. |
| Penetration Testing | Annual pentest required; internal summary often accepted. | Exhaustive third-party technical report, methodology, and verified retest attestation required. |
The 3 Evidence Pitfalls That Stall ROC Assessments
1. Missing Quarterly ASV Vulnerability Scans
PCI DSS mandates that all external IP addresses in the Cardholder Data Environment must be scanned at least once every 90 days by a PCI SSC Approved Scanning Vendor (ASV). Submitting only one recent scan is an automatic audit exception-QSAs require four consecutive quarters of passing ASV scans.
2. Unverified Third-Party Service Providers (TPSPs)
Every cloud provider, payment gateway, and hosting partner that touches your cardholder flow must have an active AOC on file. If any critical vendor cannot provide a current AOC, your audit stalls.
3. Lack of Independent Segmentation Pentest Evidence
Under Requirement 11.4, your penetration testing vendor must execute authenticated network segmentation testing proving that systems outside the CDE cannot reach cardholder data stores.
The ROC Pre-Audit Sprint: How to Prepare
- Step 1: Scoping & CDE Boundary Freeze. Finalize your network architecture and ensure all out-of-scope connections are blocked.
- Step 2: Collect 12 Months of Continuous Evidence. Gather quarterly ASV scans, monthly internal vulnerability scans, employee offboarding tickets, and access reviews.
- Step 3: Execute Comprehensive Penetration Testing. Complete independent web application, API, and network segmentation penetration testing with Lorikeet Security.
- Step 4: Conduct a Pre-Audit Dry Run. Review sampled evidence with our readiness team to catch documentation gaps before the QSA begins formal assessment.
Prepare for Your PCI DSS ROC Audit with Confidence
Eliminate audit surprises and achieve a clean Report on Compliance. Lorikeet Security provides pre-ROC readiness assessments, technical control validation, and certified penetration testing.