What supports a PCI DSS compliance claim?
A PCI DSS compliance statement needs supporting documents and a defined scope. Document type, assessment responsibility and independent assessor involvement are separate questions; they cannot be reduced to a simple certified-or-not comparison.
Self-Assessment Questionnaire vs. Qualified Security Assessor review
An eligible organisation can complete the applicable Self-Assessment Questionnaire (SAQ), with or without assistance from a QSA. The organisation remains responsible for accurate responses and eligibility. Its payment brand, acquirer or other compliance-accepting entity determines the required validation route. PCI SSC FAQ 1215: SAQ eligibility
A Qualified Security Assessor (QSA) is qualified through the PCI Security Standards Council programme and works for a qualified QSA company. Where a Report on Compliance is required, the assessment records testing and findings. QSA assistance can also be used with an SAQ; the document type and the assessor’s involvement are separate questions.
The required validation path depends on applicable payment-brand or acquirer requirements and the organisation’s eligibility. It is not determined by a buyer’s risk appetite alone. Ask the entity accepting the compliance submission which assessment and documentation are required.
What to ask before you accept the claim
Ask which assessment path supports the compliance claim: the applicable SAQ or Report on Compliance, and who performed or assisted with the assessment.
Request the appropriate Attestation of Compliance (AOC), alongside a clear description of the assessed services. Confirm which assessment it accompanies and whether the relevant service, legal entity and assessment period match your purchase.
Ask what is in scope. PCI DSS compliance can be scoped narrowly to a specific system or environment; a vendor can be genuinely compliant for the systems in scope while other parts of their environment are outside it entirely.
Match the evidence to the service you rely on
When the claim is about your own organisation, you control the scope and the evidence. When it is about a partner or vendor handling card data on your behalf, you are relying on their attestation being both accurate and current — which is exactly why asking the assessment-path question up front is worth the friction it creates in a vendor conversation.
Read the four terms without confusing them
Use this comparison during procurement. An assessor credential is not a certificate for every service delivered by the assessor’s client.
- SAQ: a validation questionnaire for an eligible environment. Ask which SAQ was used and why its eligibility conditions fit the actual payment architecture. Outsourcing payment processing does not by itself establish eligibility for a particular SAQ.
- ROC: a Report on Compliance documenting an assessment. Request the appropriate shareable evidence and identify the entity accepting it. Do not demand an entire restricted report where an AOC and a scoped clarification will answer the buying decision.
- AOC: the attestation associated with the applicable assessment. Match the entity, services and assessment date to your contract. A dated attestation is evidence about its stated scope, not an assurance that every subsequent change has been assessed.
- QSA: a qualified assessor working through a qualified assessor company. Check current qualification in the PCI SSC directory where relevant. QSA participation does not remove the assessed organisation’s responsibility for ongoing compliance.
- Record the customer/provider responsibility split: logging, access control, vulnerability handling and incident communication may be divided. Ask who performs each task and what evidence you receive, rather than assuming the provider handles everything.
A useful procurement decision identifies what the evidence covers, what it excludes and which unresolved question affects the proposed integration. If the architecture or service has changed since assessment, ask how that change was evaluated. Resolve the required validation path with the compliance-accepting entity before purchasing an assessment.

