Is There a PCI Compliance Certificate?

7 minute read
Beginner

There is no official PCI compliance certificate. What exists instead (AOC, SAQ, ROC, ASV scans), who issues each, how long it lasts, and red flags.

What proof of PCI compliance actually exists

Four documents do the work. Each has a different job, and a request for a "certificate" is almost always a request for one of them.

  • Report on Compliance (ROC). The full assessment of every applicable PCI DSS requirement, written on PCI SSC's ROC template. Required for Level 1 merchants and Level 1 service providers. Usually performed and written by a Qualified Security Assessor (QSA).
  • Self-Assessment Questionnaire (SAQ). A questionnaire covering only the requirements that apply to one way of taking cards. There are ten types, from SAQ A to SAQ D for Service Providers. The merchant or service provider completes it, sometimes with help from a consultant.
  • Attestation of Compliance (AOC). A short declaration of the assessment's result, scope and date that accompanies every ROC and SAQ. PCI DSS states that official AOCs are only available on the PCI SSC website. An executive officer of the merchant or service provider signs it, and the QSA signs it too when a QSA did the assessment.
  • ASV scan report. The results of an external vulnerability scan, with an attestation of scan compliance, showing your internet-facing systems passed. Issued by an Approved Scanning Vendor listed by PCI SSC.

The AOC is the document most people mean when they ask for a certificate. It is short, it states whether you are compliant, and it can be shared without exposing how your environment is built.

Who issues each

PCI compliance has more parties than most buyers expect, and none of them issues a certificate.

  • The PCI Security Standards Council writes PCI DSS, publishes the official ROC, SAQ and AOC forms, and trains and lists QSAs and ASVs. It does not assess merchants, and it does not decide who has to comply. That is left to the payment brands and acquirers that run compliance programs.
  • The card brands (Visa, Mastercard and others) run the compliance programs. They set merchant and service provider levels and decide which levels need a ROC and which can self-assess. Visa publishes a Global Registry of Service Providers that have validated with Visa. It is a registry, not a certificate.
  • Your acquirer, the bank that set up your merchant account, collects your AOC and SAQ or ROC, confirms your level, and decides what you submit and when.
  • Qualified Security Assessors perform ROC assessments and sign the AOC that goes with them.
  • Approved Scanning Vendors run the quarterly external scans and issue the scan reports.
  • You sign the AOC. The executive who signs it owns every answer behind it, whoever helped complete the work.

What a customer or bank asking for a "certificate" usually wants

The word "certificate" shows up in vendor questionnaires, contracts and bank letters all the time. Here is what each requester usually needs.

  • Your acquirer or payment processor wants your current AOC and the SAQ or ROC behind it, plus passing ASV scan reports if your SAQ requires them.
  • An enterprise customer reviewing you as a vendor wants a service provider AOC that covers the services you provide to them. Under Requirement 12.8 they have to check their service providers' PCI status every year, and under Requirement 12.9.2 service providers must give customers their compliance status and say which requirements they are responsible for.
  • An auditor, insurer or investor in diligence usually wants the AOC, the date of the last assessment, and evidence that open items were closed. A full ROC is rarely shared outside an NDA, because it describes your environment in detail.
  • Your own team, checking a supplier, should ask for the supplier's AOC, not a certificate or a logo, and check that the services listed on it are the ones you buy.

If a customer insists on a certificate, send the AOC with a one-line note: PCI SSC does not issue certificates, and this is the official attestation.

How long each one is valid

None of these documents carries a PCI SSC expiry date. The time limits come from the card brand programs and from PCI DSS testing frequencies.

  • Report on Compliance and its AOC: every year. Brands require annual validation, so an AOC more than 12 months old is generally treated as out of date.
  • Self-Assessment Questionnaire and its AOC: every year, and again if a change in how you take cards changes your SAQ type.
  • ASV scan report: at least once every three months, and after significant changes (Requirements 11.3.2 and 11.3.2.1).
  • Penetration test report: at least once every 12 months and after significant changes, where your SAQ or ROC requires it (Requirement 11.4). Segmentation tests run every 12 months for merchants and every six months for service providers.
  • Scope confirmation: every 12 months for merchants and every six months for service providers (Requirements 12.5.2 and 12.5.2.1).

Your acquirer sets the exact dates you file. Compliance is also continuous: an AOC describes your environment on the day of the assessment, and a change the next week can take you out of compliance even though the paper still looks current.

Red flags in "PCI certificate" offers

  • A certificate with no AOC behind it. If the seller cannot hand you a completed AOC on the official PCI SSC form, there is nothing your acquirer can accept.
  • A "PCI compliant" seal or badge for your website. A badge is not a PCI SSC validation document, and it says nothing about your scope or your controls.
  • Same-day results with no scope review. The SAQ type depends on where card data actually flows. A vendor that never asks about your payment channels, call recordings or stored card numbers is guessing.
  • An offer to complete and sign the SAQ for you. Your executive officer signs the AOC and owns the answers. Help with the work is fine. Handing over the attestation is not.
  • A guaranteed pass. An honest consultant tells you what is missing. A guarantee usually means the scope was set to fit the answer.
  • A firm that claims PCI SSC approval it does not have. Check any claimed QSA or ASV status against the lists on the PCI SSC website before you rely on it.

Related Reading

Is there an official PCI compliance certificate?

No. The PCI Security Standards Council does not issue certificates to merchants or service providers. Compliance is validated with a Report on Compliance or a Self-Assessment Questionnaire, an Attestation of Compliance and, where required, quarterly ASV scan reports.

What should I send when someone asks for my PCI certificate?

Send your current Attestation of Compliance. A service provider should send a service provider AOC that covers the services the customer buys. Add the date of your last assessment and, if asked, your passing ASV scan reports.

How long is a PCI Attestation of Compliance valid?

PCI SSC does not set an expiry date, but the card brands require annual validation, so an AOC more than 12 months old is generally treated as out of date. ASV scans are due at least every three months.

Is a PCI compliant badge on a website proof of compliance?

No. A badge is not a PCI SSC validation document and says nothing about your scope or controls. The proof is the Attestation of Compliance and the SAQ or ROC behind it.

Example: A Customer Asks for Your PCI Certificate

A common situation: a software company that takes card payments on behalf of its customers receives a vendor security questionnaire with one line, "Attach your PCI DSS certificate." There is no such document to attach. The right response is the company's current service provider AOC, the date of its last assessment, and a short note on which PCI DSS requirements the company manages for the customer and which stay with the customer (Requirement 12.9.2). If the AOC is more than a year old, or the services it lists do not match what the customer buys, the honest answer is a date for the next assessment, not a certificate from a vendor who offers one.

4

Documents that prove PCI DSS compliance: the Report on Compliance, the Self-Assessment Questionnaire, the Attestation of Compliance and the ASV scan report. The PCI Security Standards Council issues no certificate.

How Cloudskope Can Help

Cloudskope does the readiness, remediation and testing work behind a PCI DSS validation, and works alongside your QSA through fieldwork. We map where your card data actually lives, confirm which SAQ or assessment applies, fix the gaps, and build the evidence your signing officer can stand behind. See our PCI DSS compliance consulting service, or start with the PCI SAQ finder to see which questionnaire you likely need in about two minutes.