ROC vs SAQ: Do You Actually Need a QSA On Site?
The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.
The one-paragraph difference
A ROC (Report on Compliance) is produced by an independent Qualified Security Assessor after an on-site assessment of your environment — the heavyweight validation, required for Level 1 merchants and Level 1–2 service providers. A SAQ (Self-Assessment Questionnaire) is your own attestation that you meet the applicable PCI DSS requirements; no QSA signs it, though a QSA can guide you through it. Both are submitted with an Attestation of Compliance (AoC).
Side-by-side
| ROC | SAQ | |
|---|---|---|
| Performed by | QSA employed by an accredited QSA company | You (self-attestation) |
| Who needs it | Level 1 merchants; Level 1–2 service providers | Level 2–4 merchants; Level 2 service providers (varies) |
| Planning estimate | $30K–$100K+ assessment fee | $5K–$25K guided; DIY filing is free |
| Fieldwork | 2–12 weeks on-site/remote | Days to weeks of internal work |
| Credibility | Highest — independent attestation | Lower — your own word |
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesWho decides
The card brands set the levels, but your acquirer has the final say. Acquirers routinely require a QSA-led ROC from merchants who technically qualify for a SAQ — especially after a breach, during rapid growth, or in high-risk categories. Ask your acquirer in writing before you plan around a SAQ.
The expensive middle
The priciest outcome isn’t the ROC — it’s doing a SAQ, having your acquirer reject it, and then paying for a rushed ROC on a deadline. If there’s any doubt about which path applies, get the QSA’s scoping opinion (often a short paid engagement) before committing.
The common mistake
Treating the SAQ as a paperwork exercise. QSAs and acquirers can spot a copy-paste SAQ instantly, and signing an AoC you can’t defend is worse than not filing at all. If you self-assess, do it honestly — or pay a QSA to guide it.
Keep reading
How to Choose a PCI QSA Company: 11 Questions Before You Sign
What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.
PCI DSS Assessment Cost in 2026: What the Fee Actually Covers
Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.
PCI DSS 4.0: What Changed and What It Means for Your Next Assessment
v3.2.1 is retired. Here’s what’s actually different in v4.0.1, which changes bite first-timers hardest, and how to plan the transition.
Questions
Can a QSA sign my SAQ?
A QSA can guide and review your SAQ, but the SAQ remains your attestation — the QSA doesn’t sign it the way they sign a ROC.
How many SAQ types are there?
Eight: A, A-EP, B, B-IP, C-VT, C, P2PE, and D. SAQ D is the full set of requirements for merchants that don’t fit the narrower SAQs.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.