Operations
Sharing your AoC and ROC with customers
The short version: share the AoC, guard the ROC, build a trust center, and never let an attestation expire mid-deal.
The distribution rules
- Share the AoC — it’s designed for distribution, under NDA or a customer agreement.
- Guard the ROC — it describes your cardholder data environment in detail. Share excerpts only for specific, justified requests.
- Offer a QSA summary letter for customers who want more than the AoC but don’t need the full ROC.
- Date everything. An expired AoC discovered during procurement kills deals — keep trust-center documents current.
Build the trust center
Current AoC (gated), pen-test summary letter, security whitepaper, subprocessors list, and a security-review contact. Every request deflected with a link saves your team an hour — and enterprise buyers expect it.
Pair it with a standard questionnaire
Answer CAIQ or SIG Lite once, properly, instead of 300 bespoke questions per customer. Attach the AoC and let the questionnaire do the talking.
Need the ROC first?
Get competing QSA quotes and get assessed — free, two minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.