Fundamentals

ROC vs SAQ: Which PCI Validation Path Are You On?

The two roads through PCI DSS certification — what happens on each, who decides, and the expensive mistake of picking the wrong one.

The two paths

PCI DSS certification runs on one of two tracks. A ROC (Report on Compliance) is an independent on-site assessment by a Qualified Security Assessor — required for Level 1 merchants and Level 1–2 service providers. A SAQ (Self-Assessment Questionnaire) is your own attestation against the requirements that apply to how you handle card data — no QSA signs it. Both end with an Attestation of Compliance (AoC) going to your acquirer.

What happens on a ROC

Five phases: scoping, gap assessment, remediation, QSA fieldwork (2–12 weeks of control testing and evidence review), then the signed ROC and AoC. Planning estimates: $30K–$100K+ in QSA fees for Level 1, first-year all-in $75K–$250K+. The full journey typically runs 4–9 months the first time. Read the full process guide.

Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.

Request quotes

What happens on a SAQ

You determine which of the eight SAQ types fits your payment setup (see our SAQ type guide), work through the applicable requirements honestly, gather your own evidence, and sign the AoC. Guided SAQ engagements run $5K–$25K in planning estimates; DIY filing costs nothing but your time. Smaller scope, but the requirements you do face are just as real.

Who decides

The card brands set merchant and service-provider levels by transaction volume, but your acquirer has the final say — and acquirers routinely require a ROC from merchants who technically qualify for a SAQ, especially after a breach or during rapid growth. Get your level confirmed in writing before you plan.

The expensive mistake

Doing a SAQ, having your acquirer reject it, then paying for a rushed ROC on a deadline. If there's any doubt, get a QSA's scoping opinion (often a short paid engagement) before committing to a path.

Keep reading

SAQ Types A Through D, Explained

Eight questionnaires, one choice that shapes your whole PCI workload. Which SAQ type fits your payment setup — and what each one demands.

What QSAs Actually Test: Inside ROC Fieldwork

Phase 4 demystified — the testing procedures, the evidence requests, and how to walk into fieldwork with everything ready.

What Happens If You Fail a PCI Assessment

Nobody passes on the first try. How findings, remediation, and re-testing actually work — and why “not yet compliant” isn't the disaster it sounds like.

Questions

Can a QSA help with our SAQ?

Yes — a QSA can guide and review your SAQ, but it remains your attestation. The QSA doesn't sign a SAQ the way they sign a ROC.

How long is a ROC valid?

One year. Then the whole cycle repeats — see our guide to ROC validity and renewals.

Turn reading into quotes

Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.

Get a free quote