PCI DSSBy Mehar un Nisa · 23 Jul 2026 · 7 min readShare on LinkedIn

What Happens in a PCI DSS QSA Assessment: ROC vs AoC, Timeline and Cost Drivers

A plain-language walkthrough of a QSA assessment: the six phases, what a ROC and AoC actually are, realistic first-year timelines, and the factors that genuinely drive cost.

If you have never been through a QSA assessment, the process can feel like a black box: an auditor arrives, months pass, documents fly back and forth, and eventually something called an AoC appears. Businesses regularly over-budget on fear or under-budget on optimism, and both mistakes are avoidable.

This is a plain-language walkthrough of what actually happens in a PCI DSS assessment performed by a Qualified Security Assessor: the documents that come out of it, the phases and realistic timeline, and the factors that genuinely drive cost. It reflects how we run engagements at Cianaa across New Zealand and Australia under PCI DSS v4.0.1.

First, do you even need a QSA assessment?

Validation requirements are set by the card brands and your acquirer, based mainly on transaction volume. As a rule of thumb: Level 1 merchants (over six million transactions a year on a brand, or those designated Level 1 after a breach) validate with a full onsite assessment producing a Report on Compliance. Most service providers that store, process or transmit cardholder data for others are also asked for a ROC by their customers or brands once they pass roughly 300,000 transactions, and many pursue one voluntarily because enterprise clients demand it. Everyone else typically validates with a self-assessment questionnaire, which we cover in our SAQ Selector.

Two things push organisations below the thresholds into QSA territory anyway: acquirers or major customers who insist on independent validation, and internal risk appetite after seeing what self-assessment misses. If you are unsure, ask your acquirer what they require before commissioning anything.

ROC vs AoC: the two documents, and who sees what

A completed assessment produces two artefacts, and they serve different audiences.

  • The Report on Compliance (ROC) is the full technical report: requirement by requirement, what the assessor tested, the evidence examined, and the finding. For a real environment it runs to hundreds of pages. It is confidential, typically shared with your acquirer or a card brand on request.
  • The Attestation of Compliance (AoC) is the short summary document, signed by both your organisation and the QSA, stating the result, scope and validation details. This is the document you hand to customers, partners and prospects. When an enterprise procurement team asks for “your PCI certificate”, the AoC is what they mean.

One nuance worth knowing: PCI DSS validation is not a certificate, despite the popular term. There is no such thing as an official “PCI certificate”; wallet-sized cards and badge PDFs some vendors issue have no standing. The AoC is the recognised evidence.

The six phases of an assessment

  1. Scoping (one to two weeks of effort, often earlier than you expect). You and the assessor agree what is in scope: where cardholder data flows, which systems are in the cardholder data environment, which connected systems affect its security, and what segmentation exists. Get this wrong and every later phase inherits the error, which is why we treat scoping and segmentation as its own discipline.
  2. Gap assessment / readiness review (two to four weeks). A dry run against the requirements to find what would fail. First-time environments almost always surface gaps here; that is the point. The output is a remediation plan with owners and dates.
  3. Remediation (highly variable: four weeks to six months or more). You fix what the gap assessment found. This phase, not the assessment itself, is what stretches first-year timelines. Mature environments with few gaps move through in weeks; environments needing segmentation redesign or logging platforms can take two quarters.
  4. Formal assessment (three to six weeks). The QSA tests each requirement: interviews, configuration reviews, sampling systems, observing processes, examining evidence. Under v4.0.1 expect attention on the newer requirements now in force, from targeted risk analyses to payment page script controls.
  5. Quality assurance and reporting (two to four weeks). The ROC is written and goes through the QSA company’s internal QA, which the Council mandates and audits. Good firms are strict here; it protects the credibility of the report you are paying for.
  6. Sign-off and delivery. AoC signed by both parties, documents delivered to you, and submitted to your acquirer or customers as required. Then the annual cycle begins again, and the quarterly obligations (like ASV scans, see our ASV scanning explainer) continue between assessments.

Realistic end-to-end timeline: a prepared, previously assessed environment completes the annual cycle in roughly eight to twelve weeks. A first-time assessment, including remediation, more commonly spans four to nine months. Anyone promising a first-time ROC in a month is telling you something about their testing rigour.

What actually drives cost

QSA fees vary widely, and the honest reason is that effort varies widely. These are the factors that move the number, roughly in order of impact.

  • Scope size. The number of in-scope systems, applications, and data flows is the single biggest driver. Fifty servers cost more to sample and test than five. This is why scope reduction (tokenisation, outsourcing, segmentation) usually pays for itself.
  • Segmentation quality. A flat network puts everything in scope. Well-implemented and tested segmentation shrinks the assessed environment dramatically.
  • Number of locations and environments. Data centres, offices with access to cardholder data, cloud accounts, and call centres each add sampling and testing effort. Distributed teams can be assessed remotely for many controls, but observation still takes time.
  • Evidence maturity. Organisations that maintain evidence continuously (tickets, scan reports, review records, training logs) are cheap to assess. Organisations that reconstruct a year of evidence during the assessment burn assessor hours, and their own staff time, at an alarming rate.
  • Requirement complexity in your environment. Customized Approach requirements, bespoke payment applications, and unusual architectures all add assessor design and testing work. See our guide to the Customized vs Defined Approach before assuming flexibility is free.
  • First year vs steady state. Year one carries the readiness review and remediation support. Subsequent years are leaner if you maintain compliance rather than rebuilding it every twelve months.

How to make your assessment cheaper and faster

Three behaviours separate smooth assessments from painful ones. Reduce scope before you assess, because every system you remove from scope is testing you never pay for. Keep evidence as you go, because the difference between “here is the folder” and “we will get back to you” is measured in weeks. And fix scoping disagreements early, because discovering mid-assessment that a “out of scope” system was connected to the CDE reopens work nobody budgeted.

Frequently asked questions

What is the difference between a ROC and an AoC?

The ROC is the full, confidential technical report of the assessment, often hundreds of pages. The AoC is the short attestation summarising the result, signed by you and the QSA, and it is the document you share with customers and partners as evidence of compliance.

How long does a first PCI DSS QSA assessment take?

Plan for four to nine months end to end: scoping and readiness first, then remediation (the variable that dominates), then a three-to-six-week formal assessment and two to four weeks of reporting and QA. Well-prepared environments land at the short end.

Can we fail the assessment?

A requirement found not in place does not end the engagement; you remediate and the assessor retests before the report is finalised. Assessments “fail” in practice only when remediation cannot be completed in a workable window, which a decent readiness phase makes rare.

Do we need a QSA every year?

If your validation level requires a ROC, yes, it is an annual exercise, with quarterly obligations such as ASV scans continuing in between. Many controls also carry their own periodic frequencies (reviews every six months, annual testing), which your assessor will check across the whole year, not just assessment week.

Get a realistic number for your environment

Cianaa is an independent QSA company operating across New Zealand and Australia. We will tell you your realistic scope, timeline and effort before you commit to anything, including whether you need a ROC at all. Book a scoping call or read more about our PCI DSS assessment services.

PCI DSS assurance

Talk to Cianaa Technologies

Talk to our QSA team about scoping, gap remediation, and Report on Compliance under PCI DSS 4.0.1.

Book a discovery call
Enjoyed this article?

Get the next one in your inbox

One email when we publish. Written by named auditors, never by a marketing robot. Unsubscribe anytime with one click.

Double opt-in. No spam, no list-selling, covered by our privacy policy.

Similar Posts