ROC vs SAQ: Which PCI Validation Path Are You On?
The two roads through PCI DSS certification — what happens on each, who decides, and the expensive mistake of picking the wrong one.
The two paths
PCI DSS certification runs on one of two tracks. A ROC (Report on Compliance) is an independent on-site assessment by a Qualified Security Assessor — required for Level 1 merchants and Level 1–2 service providers. A SAQ (Self-Assessment Questionnaire) is your own attestation against the requirements that apply to how you handle card data — no QSA signs it. Both end with an Attestation of Compliance (AoC) going to your acquirer.
What happens on a ROC
Five phases: scoping, gap assessment, remediation, QSA fieldwork (2–12 weeks of control testing and evidence review), then the signed ROC and AoC. Planning estimates: $30K–$100K+ in QSA fees for Level 1, first-year all-in $75K–$250K+. The full journey typically runs 4–9 months the first time. Read the full process guide.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesWhat happens on a SAQ
You determine which of the eight SAQ types fits your payment setup (see our SAQ type guide), work through the applicable requirements honestly, gather your own evidence, and sign the AoC. Guided SAQ engagements run $5K–$25K in planning estimates; DIY filing costs nothing but your time. Smaller scope, but the requirements you do face are just as real.
Who decides
The card brands set merchant and service-provider levels by transaction volume, but your acquirer has the final say — and acquirers routinely require a ROC from merchants who technically qualify for a SAQ, especially after a breach or during rapid growth. Get your level confirmed in writing before you plan.
The expensive mistake
Doing a SAQ, having your acquirer reject it, then paying for a rushed ROC on a deadline. If there's any doubt, get a QSA's scoping opinion (often a short paid engagement) before committing to a path.
Keep reading
SAQ Types A Through D, Explained
Eight questionnaires, one choice that shapes your whole PCI workload. Which SAQ type fits your payment setup — and what each one demands.
What QSAs Actually Test: Inside ROC Fieldwork
Phase 4 demystified — the testing procedures, the evidence requests, and how to walk into fieldwork with everything ready.
What Happens If You Fail a PCI Assessment
Nobody passes on the first try. How findings, remediation, and re-testing actually work — and why “not yet compliant” isn't the disaster it sounds like.
Questions
Can a QSA help with our SAQ?
Yes — a QSA can guide and review your SAQ, but it remains your attestation. The QSA doesn't sign a SAQ the way they sign a ROC.
How long is a ROC valid?
One year. Then the whole cycle repeats — see our guide to ROC validity and renewals.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.