Insights on Crypto Payments, Infrastructure, and Operations

Attestation of Compliance (AOC)

Abbreviation: AOC

Pronunciation: at-eh-STAY-shun uhv kum-PLEYE-uns (A-O-C)

Also known as: Attestation of Compliance, AOC

Definition

An Attestation of Compliance is an official PCI form declaring the results of a merchant's or service provider's PCI DSS assessment. An Attestation of Compliance is the official PCI Security Standards Council form used to attest to the results of a PCI DSS assessment. It accompanies the relevant Self-Assessment Questionnaire or Report on Compliance for a merchant or service provider. The form identifies the assessed entity, environment, assessment method, applicable requirements, and overall result.

Overview

An Attestation of Compliance is the official PCI Security Standards Council form used to attest to the results of a PCI DSS assessment. It accompanies the relevant Self-Assessment Questionnaire or Report on Compliance for a merchant or service provider.

The form identifies the assessed entity, environment, assessment method, applicable requirements, and overall result. Completion and submission procedures depend on the payment brands, acquirer, customer contracts, and whether a qualified assessor or the entity performs the underlying assessment.

An AOC is evidence about a defined assessment scope and date, not a permanent guarantee that every system remains secure. Recipients should confirm the official template, relevant version, service coverage, exceptions, and relationship between the attestation and their own responsibilities.

An auditable record of Attestation of Compliance (AOC) should link onboarding, verification, screening, monitoring, investigation, approval, reporting, and periodic-review events to the governing policy or model version, source evidence, decision, approver, exception, action, and final outcome.

An Attestation of Compliance is an official PCI form declaring the results of a merchant’s or service provider’s PCI DSS assessment. An AOC records a PCI DSS assessment result for a defined scope and period; it is not a universal security certificate.

Implementation of Attestation of Compliance (AOC) should map an official PCI form declaring the results of a merchant’s or service provider’s PCI DSS assessment to the applicable entity, product, customer, transaction, and jurisdictional scope. Evidence for service provider’s PCI DSS assessment should preserve the governing requirement, policy version, control execution, exception decision, owner, and review date. Material changes affecting the Attestation of compliance duty and service provider’s PCI DSS assessment should trigger reassessment instead of silent reuse of an outdated conclusion.

Key Takeaway

An AOC records a PCI DSS assessment result for a defined scope and period; it is not a universal security certificate.

Sources

  1. PCI Security Standards Council Documentation: Pci Dss — PCI Security Standards Council (2026-07-30)