Report on Compliance (ROC)
Abbreviation: ROC
Pronunciation: ree-PAWRT ahn kum-PLEYE-uns (R-O-C)
Also known as: Report on Compliance, ROC
Definition
Report on Compliance (ROC) is a compliance or privacy requirement that documents a formal PCI DSS assessment, the assessed environment, evidence, testing, and conclusions using the applicable template. A Report on Compliance is the detailed record produced for a qualifying PCI DSS assessment. It describes scope, payment flows, system components, service providers, sampling, control testing, findings, compensating or customized approaches, and the assessor’s conclusions. The current ROC template must correspond to the applicable PCI DSS version and assessment program.
Overview
A Report on Compliance is the detailed record produced for a qualifying PCI DSS assessment. It describes scope, payment flows, system components, service providers, sampling, control testing, findings, compensating or customized approaches, and the assessor’s conclusions.
The current ROC template must correspond to the applicable PCI DSS version and assessment program. A ROC is not a public security guarantee, and its conclusions apply only to the defined entity, environment, period, evidence, and assessment conditions.
Organizations should ensure that scope and diagrams are accurate, evidence is complete, exceptions are not hidden, and remediation is tracked. The ROC and associated attestations contain sensitive information and require controlled distribution, retention, and version management.
The financial-crime compliance workflow for Report on Compliance (ROC) should locate where evidence enters, where a rule or judgment is applied, what state changes, and which downstream service relies on the result.
An auditable record of Report on Compliance (ROC) should link onboarding, verification, screening, monitoring, investigation, approval, reporting, and periodic-review events to the governing policy or model version, source evidence, decision, approver, exception, action, and final outcome.
Report on Compliance (ROC) is a compliance or privacy requirement that documents a formal PCI DSS assessment, the assessed environment, evidence, testing, and conclusions using the applicable template. A ROC is detailed, scoped PCI DSS assessment evidence whose value depends on accurate boundaries, current templates, complete testing, and honest findings.
Implementation of Report on Compliance (ROC) should map Report on Compliance (ROC) is a compliance or privacy requirement that documents a formal PCI DSS assessment, the assessed environment, evidence, testing, and conclusions using the applicable template to the applicable entity, product, customer, transaction, and jurisdictional scope. Evidence for assessed environment, evidence, and testing should preserve the governing requirement, policy version, control execution, exception decision, owner, and review date. Material changes affecting the Report on compliance duty and assessed environment, evidence, and testing should trigger reassessment instead of silent reuse of an outdated conclusion.
Key Takeaway
A ROC is detailed, scoped PCI DSS assessment evidence whose value depends on accurate boundaries, current templates, complete testing, and honest findings.
Sources
- PCI Security Standards Council Documentation: Pci Dss — PCI Security Standards Council (2026-07-30)