Preparing for Your First PCI DSS Report on Compliance (ROC) vs. SAQ D | Lorikeet Security Skip to main content
Back to Blog

Preparing for Your First PCI DSS Report on Compliance (ROC) vs. SAQ D

Lorikeet Security Technical Team September 23, 2026 10 min read Compliance & PCI DSS

When an e-commerce platform, digital marketplace, or financial software provider scales past six million annual transactions-or when enterprise payment partners mandate an on-site assessment-the compliance game changes fundamentally.

You can no longer submit a Self-Assessment Questionnaire (SAQ D). You must undergo a formal, on-site audit conducted by a licensed Qualified Security Assessor (QSA) resulting in an exhaustive Report on Compliance (ROC) and signed Attestation of Compliance (AOC).

For engineering and compliance leaders, transitioning to your first ROC can be jarring. In an SAQ, you affirm your own controls; in a ROC, an independent auditor demands tangible, forensic evidence and live sampling for every single control.

The Cost of an Unprepared ROC: If your QSA discovers unaddressed technical vulnerabilities, failed segmentation, or missing quarterly scanning logs, fieldwork halts. Remediating findings under audit pressure easily doubles project costs and risks missing your acquiring bank compliance deadline.

SAQ D vs. Report on Compliance (ROC): Key Differences

Metric SAQ D (Self-Assessment) Report on Compliance (ROC)
Applicability Level 2-4 merchants and eligible service providers. Level 1 merchants (>6M transactions) and major service providers.
Assessor Role Internal security lead signs the self-assessment. Independent QSA leads on-site testing, interviews, and writes report.
Evidence Testing Internal review of policies and system configs. Statistical sampling of user accounts, firewall rule changes, and code pull requests.
Penetration Testing Annual pentest required; internal summary often accepted. Exhaustive third-party technical report, methodology, and verified retest attestation required.

The 3 Evidence Pitfalls That Stall ROC Assessments

1. Missing Quarterly ASV Vulnerability Scans

PCI DSS mandates that all external IP addresses in the Cardholder Data Environment must be scanned at least once every 90 days by a PCI SSC Approved Scanning Vendor (ASV). Submitting only one recent scan is an automatic audit exception-QSAs require four consecutive quarters of passing ASV scans.

2. Unverified Third-Party Service Providers (TPSPs)

Every cloud provider, payment gateway, and hosting partner that touches your cardholder flow must have an active AOC on file. If any critical vendor cannot provide a current AOC, your audit stalls.

3. Lack of Independent Segmentation Pentest Evidence

Under Requirement 11.4, your penetration testing vendor must execute authenticated network segmentation testing proving that systems outside the CDE cannot reach cardholder data stores.

The ROC Pre-Audit Sprint: How to Prepare

  1. Step 1: Scoping & CDE Boundary Freeze. Finalize your network architecture and ensure all out-of-scope connections are blocked.
  2. Step 2: Collect 12 Months of Continuous Evidence. Gather quarterly ASV scans, monthly internal vulnerability scans, employee offboarding tickets, and access reviews.
  3. Step 3: Execute Comprehensive Penetration Testing. Complete independent web application, API, and network segmentation penetration testing with Lorikeet Security.
  4. Step 4: Conduct a Pre-Audit Dry Run. Review sampled evidence with our readiness team to catch documentation gaps before the QSA begins formal assessment.

Prepare for Your PCI DSS ROC Audit with Confidence

Eliminate audit surprises and achieve a clean Report on Compliance. Lorikeet Security provides pre-ROC readiness assessments, technical control validation, and certified penetration testing.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!