How to Share Your PCI AoC (and ROC) With Customers
What to share, what to never share, and how mature companies handle the 47th ‘please send your PCI docs’ request of the quarter.
Share the AoC, guard the ROC
The Attestation of Compliance (AoC) is designed to be shared — it’s a short signed statement of your compliance status. The ROC is a detailed technical report describing your cardholder data environment, controls, and any compensating controls. Distributing the full ROC broadly hands your network architecture to anyone who asks. Standard practice: share the AoC freely (under NDA if you prefer); share ROC excerpts only for specific, justified requests.
The NDA question
Most companies share the AoC under a mutual NDA or as part of a signed customer agreement. It’s reasonable to require one — the AoC still contains scope details a competitor or attacker finds interesting. What’s not reasonable: refusing to share anything at all. Enterprise buyers will walk.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesBuild a trust center
If you field these requests regularly, build a trust center page: current AoC (gated), pen-test summary letter, security whitepaper, subprocessors list, and contact for security reviews. Every request you deflect with a link saves your team an hour.
Handling security reviews
Pair the AoC with a completed standardized questionnaire (CAIQ, SIG Lite) rather than answering 300 bespoke questions per customer. And keep the AoC current — nothing kills a deal faster than an expired attestation discovered during procurement.
Keep reading
ROC vs SAQ: Do You Actually Need a QSA On Site?
The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.
How to Choose a PCI QSA Company: 11 Questions Before You Sign
What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.
PCI DSS Assessment Cost in 2026: What the Fee Actually Covers
Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.
Questions
Can customers demand our full ROC?
They can ask. You can decline and offer the AoC plus a QSA summary letter instead — that’s standard practice and most enterprise security teams accept it.
How long is the AoC valid?
One year, tied to the assessment cycle. Date your trust-center documents so nobody has to ask.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.