Guide

PCI DSS Validation: SAQ vs. ROC, and Which One Applies to You

Two very different validation paths exist under PCI DSS — and knowing which one your organization is on shouldn't be a surprise delivered by your acquiring bank.

Talk to a CISO

The business problem

Every organization that accepts, processes, transmits, or stores payment card data is required to validate its compliance with PCI DSS. Depending on transaction volume, processing method, and card brand requirements, an organization will either complete a Self-Assessment Questionnaire (SAQ) or undergo a Report on Compliance (ROC) conducted by a Qualified Security Assessor.

Many organizations don't know which path applies until their acquiring bank tells them — often with a deadline attached.

Why it matters

An SAQ is typically completed internally, on a schedule the organization largely controls. A ROC requires engaging an independent assessor and working through a formal audit cycle. Organizations that assume they qualify for the simpler path and then learn otherwise often discover this mid-renewal, at the worst possible time.

“PCI DSS validation isn't a checkbox — it's a determination made about your business, by your payment partners, based on facts you should already know.”

Signs the organization should pay attention now

  • Transaction volume has grown meaningfully since the last validation cycle, or growth is planned
  • The organization has added new payment channels
  • No one on the leadership team can say with confidence whether the current path is SAQ or ROC, or why
  • A payment processor or acquiring bank has changed without a corresponding compliance review
  • Cardholder data handling has changed — new systems, vendors, or integrations touch payment data

What good looks like

Organizations that manage this well treat PCI DSS validation as a known, owned, and monitored obligation. Leadership can answer, without hesitation, which validation path currently applies and why, and the relationship with the acquiring bank is proactive rather than reactive.

Want ongoing executive ownership of this program?

Explore Compliance & Program Leadership

Practical guidance

Confirm in writing which validation path currently applies, and get the rationale from the acquiring bank — don't assume it stays the same year over year. Build validation timing into the annual compliance calendar. Assign clear ownership so institutional knowledge doesn't leave with one employee. Revisit the determination whenever transaction volume or payment channels change materially.

My CISO Partner's perspective

We regularly see organizations compliant on paper but unclear on the mechanics of how their own validation status is determined. Our role is to make this legible: what validation path applies today, what would change it, and what the organization needs to have in place either way.

Where to go from here

If your organization can't clearly answer which PCI DSS validation path applies today, that's worth a conversation now, not after your acquiring bank raises it.

FAQ

Questions, answered directly.

An SAQ is a self-attested review completed internally, typically for lower transaction volumes. A ROC is a formal assessment performed by a Qualified Security Assessor, generally required for higher-volume merchants.

Your acquiring bank or payment processor determines which validation path applies, based on transaction volume and card brand requirements.

At minimum annually, but also any time transaction volume grows significantly or the organization changes payment channels or processors.

No. SAQ eligibility is based on transaction volume and processing method, not the strength of an organization’s security program.

Talk to a CISO about your situation.

30 minutes. No obligation. No sales pitch.

Talk to a CISO