Fundamentals

ROC vs SAQ: Do You Actually Need a QSA On Site?

The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.

The one-paragraph difference

A ROC (Report on Compliance) is produced by an independent Qualified Security Assessor after an on-site assessment of your environment — the heavyweight validation, required for Level 1 merchants and Level 1–2 service providers. A SAQ (Self-Assessment Questionnaire) is your own attestation that you meet the applicable PCI DSS requirements; no QSA signs it, though a QSA can guide you through it. Both are submitted with an Attestation of Compliance (AoC).

Side-by-side

ROCSAQ
Performed byQSA employed by an accredited QSA companyYou (self-attestation)
Who needs itLevel 1 merchants; Level 1–2 service providersLevel 2–4 merchants; Level 2 service providers (varies)
Planning estimate$30K–$100K+ assessment fee$5K–$25K guided; DIY filing is free
Fieldwork2–12 weeks on-site/remoteDays to weeks of internal work
CredibilityHighest — independent attestationLower — your own word

Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.

Request quotes

Who decides

The card brands set the levels, but your acquirer has the final say. Acquirers routinely require a QSA-led ROC from merchants who technically qualify for a SAQ — especially after a breach, during rapid growth, or in high-risk categories. Ask your acquirer in writing before you plan around a SAQ.

The expensive middle

The priciest outcome isn’t the ROC — it’s doing a SAQ, having your acquirer reject it, and then paying for a rushed ROC on a deadline. If there’s any doubt about which path applies, get the QSA’s scoping opinion (often a short paid engagement) before committing.

The common mistake

Treating the SAQ as a paperwork exercise. QSAs and acquirers can spot a copy-paste SAQ instantly, and signing an AoC you can’t defend is worse than not filing at all. If you self-assess, do it honestly — or pay a QSA to guide it.

Keep reading

How to Choose a PCI QSA Company: 11 Questions Before You Sign

What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.

PCI DSS Assessment Cost in 2026: What the Fee Actually Covers

Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.

PCI DSS 4.0: What Changed and What It Means for Your Next Assessment

v3.2.1 is retired. Here’s what’s actually different in v4.0.1, which changes bite first-timers hardest, and how to plan the transition.

Questions

Can a QSA sign my SAQ?

A QSA can guide and review your SAQ, but the SAQ remains your attestation — the QSA doesn’t sign it the way they sign a ROC.

How many SAQ types are there?

Eight: A, A-EP, B, B-IP, C-VT, C, P2PE, and D. SAQ D is the full set of requirements for merchants that don’t fit the narrower SAQs.

Turn reading into quotes

Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.

Get a free quote