If your organization stores, processes, or transmits cardholder data, PCI DSS compliance is required by Visa, Mastercard, and the other major card brands, regardless of size or transaction volume. PCI DSS v4.0.1 became fully mandatory in March 2025, and every requirement is now in effect. Depending on your transaction volume, that means either a full Report on Compliance (ROC) from a Qualified Security Assessor (QSA), or a Self-Assessment Questionnaire (SAQ), and either way, an Attestation of Compliance (AOC), the document you actually hand to your bank or partners.
This applies to service providers as much as merchants
PCI DSS draws a real distinction between two entity types. A merchant accepts payment cards directly from consumers, an e-commerce company, a retail chain. A service provider provides payment-related services to merchants or other service providers: a payment processor, a payment gateway, a cloud host storing cardholder data. In practice, the majority of PCI engagements involve service providers, not merchants, because compliance flows through the payment ecosystem; a merchant using a compliant service provider can inherit that provider’s compliance for the requirements it controls. That makes a service provider’s own AOC something its customers directly depend on to reduce their scope, which is exactly why a service provider SAQ without a credible QSA signature carries limited weight in the market.
Why the assessor matters as much as the assessment
Not every PCI DSS engagement looks the same, even when the paperwork does. Some are led by a current, active QSA testing controls directly. Others involve an Associate QSA or subcontracted work, or an assessor splitting time across several frameworks rather than working PCI DSS exclusively. That difference tends to show up exactly when it matters least, at renewal, or after something goes wrong. Insight Assurance assessors work PCI DSS exclusively, and every engagement is led by a current, active QSA.
ROC, SAQ, and AOC: what each one is
- ROC (Report on Compliance): required for Level 1 merchants (over 6 million transactions/year) and higher-volume service providers. A full assessment documenting compliance in depth, evidence, interviews, and detailed narrative for every requirement.
- SAQ (Self-Assessment Questionnaire): for organizations below the ROC threshold. The applicable SAQ type is determined by your acquiring bank or payment processor based on how you handle card data, not something you choose yourself.
- AOC (Attestation of Compliance): the short, standardized document issued alongside either the ROC or the SAQ. This is the one your bank, partners, and customers actually want to see, the ROC and SAQ themselves stay internal.
What drives complexity (it isn’t company size)
The biggest misconception in PCI DSS scoping is that a bigger company means a bigger assessment. In practice, what drives scope and cost is the number and type of cardholder data flows a business has: website payments, in-store terminals, call center, gift cards, chargebacks, and how much of that runs through compliant service providers versus infrastructure the company runs itself. A large company routing everything through compliant third parties can have a simpler assessment than a smaller company running its own payment infrastructure across multiple locations.
Where most assessments succeed or struggle: scoping
The single biggest driver of how heavy a PCI DSS assessment feels, year after year, is the size of the Cardholder Data Environment (CDE). A CDE that’s grown wider than it needs to be carries that cost into every future assessment. Scoping and planning, mapping every cardholder data flow and looking for a legitimate reduction strategy, is where a rigorous assessment starts, not an afterthought once testing is underway.
What the engagement looks like
Fieldwork happens on-site or remote, with findings shared as the assessment progresses rather than saved for a surprise at the end. From there, the engagement produces a defensible ROC or SAQ, plus the AOC you’ll actually use, delivered on schedule. PCI DSS compliance is annual, there’s no multi-year certificate, so this repeats every cycle.
A note on independence
A PCI DSS assessment is an independent evaluation of your environment against the current standard. Its findings come from testing, not opinion. Remediation, if anything is identified, is managed by your team, an assessor’s role is to evaluate, not to advise or fix.
FAQ
What is PCI DSS compliance?
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements, maintained by the major card brands, for any organization that stores, processes, or transmits cardholder data. Compliance means passing an assessment against the current standard, either a Report on Compliance from a QSA or a Self-Assessment Questionnaire, depending on volume, and it’s required annually, not a one-time certification.
How much does a PCI DSS assessment cost?
It depends on your Cardholder Data Environment, not a flat rate. The number and type of cardholder data flows you have, and how much of your infrastructure runs through compliant service providers versus your own systems, drive the scope of work far more than company size does. A scoping call is the fastest way to get a real answer for your environment rather than a number that won’t hold once the details are in.
Does PCI DSS apply if our transaction volume is small?
Yes. PCI DSS is required by the card brands regardless of size or transaction volume; the assessment type (ROC or SAQ) is what scales with volume, not whether compliance applies.
We’re a service provider, not a merchant. Does this still apply to us?
Yes, and often with more at stake. Service providers make up the majority of PCI engagements, since merchants depend on a service provider’s AOC to reduce their own scope.
How is SAQ type determined?
By your acquiring bank or payment processor, based on how card data is processed across your specific flows, not something an organization selects on its own.
What’s the difference between an AOC and a ROC or SAQ?
The AOC is the short, external-facing document you share with banks and partners. The ROC or SAQ is the underlying, detailed assessment, it stays internal.
What’s the difference between a QSA and an Associate QSA?
A QSA is currently certified and active. Associate QSA work, or subcontracted work, is a different arrangement, worth asking about directly when evaluating an assessor.
Why does CDE scoping matter so much?
Because the size of your Cardholder Data Environment determines the scope, and therefore the cost in time and effort, of every future assessment, not just the current one.
Insight Assurance is a Qualified Security Assessor company working PCI DSS exclusively. If your next assessment cycle is coming up, schedule a scoping call to talk through your cardholder data flows, entity type, and what the engagement would involve.
