Operations

How to Share Your PCI AoC (and ROC) With Customers

What to share, what to never share, and how mature companies handle the 47th ‘please send your PCI docs’ request of the quarter.

Share the AoC, guard the ROC

The Attestation of Compliance (AoC) is designed to be shared — it’s a short signed statement of your compliance status. The ROC is a detailed technical report describing your cardholder data environment, controls, and any compensating controls. Distributing the full ROC broadly hands your network architecture to anyone who asks. Standard practice: share the AoC freely (under NDA if you prefer); share ROC excerpts only for specific, justified requests.

The NDA question

Most companies share the AoC under a mutual NDA or as part of a signed customer agreement. It’s reasonable to require one — the AoC still contains scope details a competitor or attacker finds interesting. What’s not reasonable: refusing to share anything at all. Enterprise buyers will walk.

Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.

Request quotes

Build a trust center

If you field these requests regularly, build a trust center page: current AoC (gated), pen-test summary letter, security whitepaper, subprocessors list, and contact for security reviews. Every request you deflect with a link saves your team an hour.

Handling security reviews

Pair the AoC with a completed standardized questionnaire (CAIQ, SIG Lite) rather than answering 300 bespoke questions per customer. And keep the AoC current — nothing kills a deal faster than an expired attestation discovered during procurement.

Keep reading

ROC vs SAQ: Do You Actually Need a QSA On Site?

The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.

How to Choose a PCI QSA Company: 11 Questions Before You Sign

What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.

PCI DSS Assessment Cost in 2026: What the Fee Actually Covers

Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.

Questions

Can customers demand our full ROC?

They can ask. You can decline and offer the AoC plus a QSA summary letter instead — that’s standard practice and most enterprise security teams accept it.

How long is the AoC valid?

One year, tied to the assessment cycle. Date your trust-center documents so nobody has to ask.

Turn reading into quotes

Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.

Get a free quote