The Payment Card Industry Security Standards Council (PCI SSC) has released an  updated Report on Compliance (ROC) Template for PCI DSS v4.0.1, marking a  significant milestone in the evolution of payment security reporting. This update aims to align with the latest standard while addressing stakeholder feedback. 

In this article, we’ll explain what a RoC is, who needs to complete one, and unpack the changes made to the RoC template as a result of PCI DSS v4.0.1

What is a RoC?

A Report on Compliance (RoC) is a report prepared by a Qualified Security Assessor (QSA), outlining an organisation’s security practices against Payment Card Industry Data Security Standards (PCI DSS) compliance requirements. Following a thorough, onsite assessment, the RoC outlines an organisation’s compliance status for each PCI DSS security requirement. The result is a comprehensive document that ensures an organisation has taken the necessary measures to safeguard its cardholder data, therefore demonstrating PCI DSS Compliance. Having completed the ROC, the Assessor prepares an Attestation of Compliance (AoC) that is jointly signed by the QSA and an Executive Officer at the organisation. 

The latest RoC template is available to view and download at the PCI Council Website.

Who Needs to Complete a RoC? 

Not every organisation needs to complete a RoC. In most cases, it depends on your PCI DSS compliance level. As the most stringent and comprehensive PCI DSS compliance assessment, it applies to organisations with the highest risk profiles.

For level 1 merchants (organisations that process over 6 million card transactions per year), a RoC is required to demonstrate PCI DSS Compliance.  

A RoC is not required for level 2-4 merchants. However, your payment brand or acquiring bank may require your organisation to complete one. 

If your organisation does not need to complete a RoC, it will instead need to complete a Self-Assessment Questionnaire (SAQ) and a corresponding Attestation of Compliance (AoC) to demonstrate PCI DSS compliance.

How Often Do You Need to Complete a RoC? 

Organisations required to complete a RoC must do so every twelve months to maintain PCI DSS Compliance. 

RoC PCI DSS v4.0.1: Why was the RoC updated? 

The PCI DSS RoC template continuously improves to reflect up-to-date security best practices and address evolving security threats. 

With this in mind, the PCI DSS v4.0.1 RoC Template (the latest RoC version), was developed in collaboration with a number of industry experts (coordinated by the PCI Council) including: 

  • Global Executive Assessor Roundtable (GEAR) 
  • Board of Advisors (BOA) 
  • Technology Advisory Board (TAB) 
  • Technology Guidance Group (TGG) 

Following this review, stakeholders highlighted several key concerns with the previous template. Notably, they found that RoCs required excessive time to complete. In a valiant effort to cover all bases, RoCs contained redundant information, unnecessarily increasing the time and effort required to complete. Stakeholders also identified performance issues (and some inconsistencies) with the final report. 

Key Changes to the RoC template for PCI DSS v4.0.1

The update to the RoC template for PCI DSS v4.0.1 does not introduce new requirements. Instead, it provides clarification and improves usability. Some significant updates in the new RoC template include:

  • Renaming of the “Approach Reporting Options” section to “Method(s) Used”:  This is the terminology used to refer to the methods an assessor uses to verify PCI Compliance. The change in terminology to more natural language is in line with the PCI SSC’s goal of making language clearer and more consistent across reporting documentation. 
  • Refinement of the report structure: A number of changes clarify and consolidate key steps in the compliance assessment, removing redundant steps. 

Other key changes include: 

  • Scope exclusion clarifications.
  • Self-Assessment Questionnaire (SAQ) eligibility requirements.
  • Updated guidance on Sensitive Authentication Data (SAD) storage.
  • Improved management documentation.

PCI DSS RoC Accompanying Documentation

The PCI SSC has published several related documents: 

If your organisation is required to complete a RoC, we recommend you review these documents, so you have a complete understanding of what is required. As always, it’s best to have them explained – in the context of your organisation’s unique environment – by a QSA

Using the new RoC template 

PCI DSS v4.0 was retired as the current standard on December 31, 2024. Since then, PCI DSS v4.0.1 became the active standard security requirements for PCI DSS-mandated organisations. 

To meet these updated standards, your organisation should: 

  • Review the new ROC Template thoroughly (with your QSA).
  • Understand the structural and content changes.
  • Update internal compliance documentation. 
  • Train your cyber security and security assessment teams on the new template. 

The PCI DSS v4.0.1 ROC Template represents a collaborative effort to streamline compliance reporting, reduce administrative burden, and maintain robust security standards. Organisations should view this update as an opportunity to refine their compliance processes and documentation. 

By focusing on usability and addressing stakeholder concerns, the PCI SSC continues to evolve its approach to payment security, ensuring that compliance remains both comprehensive and manageable.

If you’d like some guidance around your organisation’s PCI compliance requirements, including advice on your RoC, our team is happy to help. Contact us for a complimentary security review.

Book a Security Review