ROC Validity and Renewals: Keeping PCI Certification Alive
The ROC lasts one year. What the annual renewal cycle looks like, why renewals get cheaper, and how companies accidentally let certification lapse.
One year, then repeat
A Report on Compliance is a point-in-time assessment valid for one year from the assessment date — not the calendar year. Miss the renewal and your AoC expires, which your acquirer, your enterprise customers, and your contracts will notice. PCI certification is a cycle, not a project.
What changes at renewal
The standard is the same, but the engagement is different: scoping is a delta review (what changed this year?), evidence collection reuses last year's package as a baseline, and fieldwork focuses on changes plus the full control set. Expect the QSA to re-test everything — renewals aren't rubber stamps — but the discovery phase shrinks dramatically.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesWhy renewals get cheaper
First-year costs include gap assessment, remediation, and building the evidence pipeline from scratch. Renewals skip most of that: planning estimates typically run 40–70% of the first-year assessment fee once the program matures. The lever is continuous evidence collection — teams that gather evidence year-round turn fieldwork into verification instead of archaeology.
How lapses happen
- Starting the renewal cycle too late. Engage the QSA 3–4 months before expiry.
- Scope changed silently. A new product, a new region, a new processor — all can invalidate last year's scoping.
- Key people left. The person who knew where the evidence lived is gone, and nobody documented it.
- The QSA is booked. Peak renewal season strains QSA calendars; late bookers wait.
The renewal playbook
- 90 days out: confirm scope changes and re-engage the QSA.
- 60 days out: refresh the evidence package; close known gaps.
- 30 days out: fieldwork window.
- On signing: distribute the new AoC to your acquirer and customer trust center immediately.
- Year-round: collect evidence continuously so next renewal is boring.
Keep reading
ROC vs SAQ: Which PCI Validation Path Are You On?
The two roads through PCI DSS certification — what happens on each, who decides, and the expensive mistake of picking the wrong one.
SAQ Types A Through D, Explained
Eight questionnaires, one choice that shapes your whole PCI workload. Which SAQ type fits your payment setup — and what each one demands.
What QSAs Actually Test: Inside ROC Fieldwork
Phase 4 demystified — the testing procedures, the evidence requests, and how to walk into fieldwork with everything ready.
Questions
Can we switch QSA companies at renewal?
Yes — renewals are the natural switching point. See our switching playbook for the clean handoff.
Does the ROC date or the AoC date matter?
Both come from the same assessment; the AoC is what you distribute. Track the assessment date — that's when the one-year clock starts.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.