# PCI attestation of compliance (AOC): components, steps, samples, and starter kit

## In this article:

- [Summary of each element in a PCI AOC document](https://www.strikegraph.com/blog/pci-attestation-of-compliance-aoc#Summary-of-each-element-in-a-PCI-AOC-document-jumplink)
- [Benefits of PCI compliance](https://www.strikegraph.com/blog/pci-attestation-of-compliance-aoc#Benefits-of-PCI-compliance-jumplink)
- [Steps to obtain and complete a PCI DSS attestation of compliance](https://www.strikegraph.com/blog/pci-attestation-of-compliance-aoc#Steps-to-obtain-and-complete-a-PCI-DSS-attestation-of-compliance-jumplink)
- [Challenges and common errors when filling out an AOC](https://www.strikegraph.com/blog/pci-attestation-of-compliance-aoc#Challenges-and-common-errors-when-filling-out-an-AOC-jumplink)
- [PCI DSS Compliance starter kit with AOC templates](https://www.strikegraph.com/blog/pci-attestation-of-compliance-aoc#PCI-DSS-Compliance-starter-kit-with-AOC-templates-jumplink)

A PCI attestation of compliance (AOC) is a signed, formal document summarizing the results of an organization’s PCI DSS audit. It attests to whether the organization meets the required security standards for handling payment card data. Organizations can provide it to others to promote trust.

The AOC is concise summary of other key documents that detail the security measures used to meet each PCI DSS requirement. These can include a report on compliance (ROC) or a self-assessment questionnaire (SAQ), depending on your PCI DSS level.

### Key Takeaways:

- A PCI attestation of compliance (AOC) formally attests that a company meets its PCI audit requirements.
- An AOC sends a strong message to credit card companies and business partners about the organization's commitment to security.
- The PCI Security Standards Council (SSC) provides an AOC for each type of reporting documentation, including both the report on compliance (ROC) and the self-assessment questionnaires (SAQs).

### Who needs a PCI AOC?

Any business or service provider that processes, stores, or transmits credit card data needs a PCI AOC. It’s necessary regardless of their size or transaction volume.

### What is the difference between attestation of compliance and certification of compliance?

When people describe a 'certification of compliance,' they usually mean an attestation of compliance (AOC). The term "certification of compliance" is incorrect; the PCI Security Standards Council doesn’t offer certification.

### Steps to fill out a PCI DSS attestation of compliance

1. **Educate**: Understand your PCI DSS level and draft a PCI security policy.
2. **Audit**: Conduct an internal audit or hire an external QSA.
3. **Assess and report**: Complete an SAQ or ROC.
4. **Remediate**: Fix any compliance issues identified during the audit.
5. **Submit AOC**: Complete the AOC form to certify your results.

### Benefits of PCI attestation

- Confirms credit card data protection according to PCI DSS standards.
- Boosts business reputation and trustworthiness among partners.
- Helps avoid potential fines and penalties for non-compliance.

### Challenges and common errors when filling out a PCI AOC

- Misinterpreting the scope of the assessment.
- Failing to record compensatory controls.
- Completing the incorrect self-assessment questionnaire (SAQ).

### PCI DSS compliance starter kit with AOC templates

Strike Graph’s PCI DSS Compliance Starter Kit includes AOC templates and essential PCI documentation tools. [Download the PCI DSS Compliance Starter Kit](https://www.strikegraph.com/hubfs/Downloadable%20Assets/Strike%20Graph_PCI%20DSS%20Starter%20Kit.pdf) for comprehensive guidance.
