If your organization stores, processes, or transmits payment card data, PCI DSS compliance is more than completing a questionnaire and receiving a certificate.
A PCI DSS compliance program can involve scope definition, gap assessment, remediation, QSA assessment, penetration testing, ASV scans, a Report on Compliance (ROC), and an Attestation of Compliance (AOC), depending on the organization, validation method, and requirements imposed by the relevant acquirer or payment brand.
There is also an important terminology point: PCI SSC does not issue a PCI DSS “certificate.” For formal validation, PCI SSC recognizes documents such as the ROC, AOC, SAQ, and applicable ASV documentation.
So when businesses search for PCI DSS certification services, they are generally looking for a qualified provider that can help them determine the applicable validation path, assess their controls, complete required testing, address gaps, and produce the documentation needed to demonstrate compliance.
This guide explains what PCI DSS certification and compliance services actually include, when you need a QSA, what the ROC and AOC mean, where ASV scans and penetration testing fit, and how to choose the right PCI DSS compliance partner.
What Are PCI DSS Certification Services?
PCI DSS certification services are professional services that help merchants, service providers, and other organizations subject to PCI DSS requirements assess and validate the security of their cardholder data environment. Depending on the organization’s validation requirements, services may include:
- PCI DSS scoping and readiness assessment
- PCI DSS gap assessment
- QSA-led PCI DSS assessment
- Report on Compliance (ROC)
- Attestation of Compliance (AOC)
- Self-Assessment Questionnaire (SAQ) support
- PCI Approved Scanning Vendor (ASV) scans
- Internal and external vulnerability scanning
- PCI DSS penetration testing
- Segmentation testing
- Remediation advisory
- Pre-audit assessment
- Compliance documentation
- Ongoing PCI DSS compliance support
PCI DSS applies to entities that store, process, or transmit cardholder data or sensitive authentication data, as well as entities that can impact the security of the cardholder data environment. This includes merchants, processors, acquirers, issuers, and service providers.
The exact services an organization needs depend on its PCI DSS scope, payment environment, validation requirements, and applicable SAQ or ROC path.
Is PCI DSS Actually a Certification?
Not in the traditional certification sense.
PCI SSC explicitly states that it does not authorize or recognize generic “PCI DSS certificates” as validation documentation. The official documents used to demonstrate PCI DSS compliance include the Report on Compliance (ROC), Attestation of Compliance (AOC), Self-Assessment Questionnaire (SAQ), and applicable ASV documentation.
However, “PCI DSS certification” remains a widely used search term because organizations commonly refer to completing their PCI DSS validation as getting “PCI certified.”
For businesses evaluating PCI DSS certification services, the more useful question is:
What validation does my organization need, who is qualified to perform it, and what documentation must I submit?
That distinction can prevent organizations from purchasing a generic “certificate” that does not satisfy their acquirer, payment brand, or other compliance-accepting entity.
What Does a PCI DSS QSA Assessment Include?
A Qualified Security Assessor (QSA) is an organization qualified by PCI SSC to perform PCI DSS assessments. QSAs evaluate whether an entity’s applicable controls meet PCI DSS requirements and can perform formal PCI DSS assessments resulting in a ROC and associated AOC when that validation path applies. A QSA-led assessment typically involves several stages.
- PCI DSS scoping
The assessment starts by determining what is actually within scope. This can include:
- Cardholder data flows
- Cardholder data environment (CDE)
- Systems that store, process, or transmit cardholder data
- Connected systems
- Network components
- Applications
- Cloud infrastructure
- Security controls
- Third-party service providers
Poor scoping can create two problems: an organization may assess systems that do not need to be included, while simultaneously overlooking systems that actually affect the security of cardholder data.
- Control assessment
The QSA evaluates the applicable PCI DSS requirements and the evidence demonstrating that controls are implemented and operating as required. Depending on the environment, evidence can include:
- Policies and procedures
- Network diagrams
- Data-flow diagrams
- System configurations
- Access-control records
- Vulnerability scans
- Penetration testing reports
- Logging and monitoring evidence
- Security awareness records
- Incident response documentation
- Technical configurations
- Change-management records
- Gap identification
The QSA identifies requirements where the organization does not meet the applicable PCI DSS expectations or where evidence is insufficient. The organization then addresses those gaps before final validation.
- Final assessment and documentation
Once the applicable requirements have been assessed and outstanding issues addressed, the QSA completes the relevant reporting and attestation documentation. For organizations requiring a formal assessment, this generally means a ROC and AOC.
What Is a PCI DSS Report on Compliance (ROC)?
A Report on Compliance (ROC) is the formal assessment report used to document the results of a PCI DSS assessment. It provides detailed information about how the organization’s applicable PCI DSS requirements were assessed and whether they were found to be in place.
A ROC is therefore substantially different from a simple compliance letter. It provides evidence of the assessment performed and documents the organization’s compliance status against the applicable requirements.
A QSA may also perform a partial PCI DSS assessment in certain circumstances, with the relevant subset documented in a ROC. PCI SSC confirms that partial assessments can be documented this way when appropriate to the organization’s validation needs.
What Is a PCI DSS Attestation of Compliance (AOC)?
The Attestation of Compliance (AOC) is the formal attestation associated with the applicable PCI DSS validation.
Think of it this way:
ROC = detailed assessment report
AOC = formal attestation of the assessment/compliance result
The AOC is often the document that customers, acquirers, payment brands, or business partners request as evidence that an organization has completed the applicable PCI DSS validation.
The exact documentation required depends on the organization’s compliance program and the entity requesting validation. PCI SSC advises organizations to consult their acquirer, payment brands, or other compliance-accepting entity regarding specific reporting requirements.
What Are PCI ASV Scans?
A PCI Approved Scanning Vendor (ASV) performs external vulnerability scanning required under applicable PCI DSS requirements.
PCI SSC defines an ASV as an organization with an approved scanning solution used to conduct external vulnerability scanning services for PCI DSS Requirement 11.3.2. ASVs must maintain their qualification through the PCI SSC program.
Under PCI DSS v4.x, applicable external vulnerability scans must generally be performed at least once every three months, with passing scan results maintained as evidence.
The purpose is to identify vulnerabilities in internet-facing systems that could potentially expose the payment environment.
What does an ASV scan test?
Depending on the applicable scope, an ASV scan can identify issues such as:
- Vulnerable services
- Missing security patches
- Insecure configurations
- Exposed services
- Network vulnerabilities
- Web-facing vulnerabilities
- Other weaknesses detectable through the approved scanning methodology
Accorian is a PCI SSC Approved Scanning Vendor and provides external vulnerability scanning, vulnerability validation, risk prioritization, remediation guidance, and rescanning.
Does an ASV Scan Mean You Are PCI DSS Compliant?
No.
This is one of the most important distinctions in PCI DSS. An ASV scan addresses the applicable external vulnerability scanning requirement. It does not evaluate every PCI DSS requirement. PCI SSC explicitly states that an ASV scan report is not an indication that other PCI DSS requirements have been reviewed or implemented.
In simple terms:
ASV scan ≠ PCI DSS compliance
An organization may pass its ASV scan and still have significant gaps in access control, policies, authentication, logging, secure development, vulnerability management, or other applicable PCI DSS requirements.
How Is PCI DSS Penetration Testing Different From an ASV Scan?
An ASV scan and penetration test are not substitutes for one another. An ASV scan is designed to identify external vulnerabilities through the PCI SSC-approved scanning process.
A penetration test goes further by using controlled attack techniques to determine whether vulnerabilities can actually be exploited and what an attacker could accomplish.
PCI DSS penetration testing may involve:
- External network penetration testing
- Internal network penetration testing
- Web application penetration testing
- API penetration testing
- Segmentation testing
- Exploitation of identified vulnerabilities
- Validation of security controls
- Attack-path analysis
The exact testing requirements depend on the organization’s applicable PCI DSS requirements and validation method.
The key distinction is:
Vulnerability scanning asks, “What weaknesses are visible?”
Penetration testing asks, “Can those weaknesses be exploited, and what impact could exploitation have?”
Accorian provides PCI ASV scanning alongside external and internal network penetration testing, application and API penetration testing, and other security testing services.
Do All Organizations Need a QSA, ROC, AOC, ASV Scan and Pen Test?
No.
This is where many PCI DSS programs become unnecessarily complicated. The validation method depends on the organization’s circumstances, scope, payment-processing model, and requirements imposed by the relevant compliance-accepting entities.
Some organizations may validate using an SAQ, while others may require a QSA-led assessment and ROC. Similarly, applicable ASV scanning and penetration testing requirements depend on the organization’s PCI DSS scope and validation requirements.
For example, PCI SSC states that SAQ A under PCI DSS v4.x includes applicable external vulnerability scanning requirements for certain e-commerce merchants, even when payment processing is outsourced to a PCI DSS-compliant third-party service provider.
This is why organizations should determine their validation path before purchasing individual PCI DSS services.
What Does a Complete PCI DSS Compliance Service Include?
For organizations that need a comprehensive PCI DSS program, the engagement may look like this:
Step 1: Scope the environment
Map:
Payment flows → Cardholder data → CDE → Connected systems → Third parties
Step 2: Perform a readiness or gap assessment
Evaluate the current environment against the applicable PCI DSS requirements.
Step 3: Remediate identified gaps
Address technical, administrative, and operational deficiencies.
Step 4: Perform required security testing
Depending on scope, this can include:
- ASV scans
- Internal vulnerability scans
- External vulnerability assessments
- Penetration testing
- Segmentation testing
- Application/API testing
Step 5: Conduct the formal QSA assessment
The QSA validates the applicable controls and supporting evidence.
Step 6: Complete the ROC and AOC
The applicable compliance documentation is finalized.
Step 7: Maintain ongoing compliance
PCI DSS compliance is not a one-time activity. Organizations may need recurring scans, testing, monitoring, evidence collection, remediation, and reassessment depending on their applicable requirements.
How Long Does PCI DSS Compliance Take?
There is no universal PCI DSS certification timeline. The timeline depends on:
- Size of the cardholder data environment
- Number of systems in scope
- Payment architecture
- Cloud infrastructure
- Third-party dependencies
- Existing security controls
- Number of compliance gaps
- Remediation effort
- Penetration testing requirements
- QSA availability
- Required documentation
An organization with a well-defined CDE and mature security controls may move through assessment considerably faster than an organization attempting PCI DSS validation for the first time with a broad or poorly defined scope. The fastest route is not necessarily to start with the audit.
Accurate scoping and readiness assessment first can reduce unnecessary remediation and assessment delays later.
How Much Do PCI DSS Certification Services Cost?
PCI DSS compliance costs vary significantly because the scope of the engagement varies. Pricing can depend on:
- Number of systems in scope
- Number of applications
- CDE complexity
- Transaction environment
- Cloud infrastructure
- Number of locations
- Third-party integrations
- Penetration testing requirements
- ASV scanning requirements
- QSA assessment scope
- Remediation requirements
- Ongoing compliance support
Organizations should therefore be cautious about providers advertising a single fixed “PCI certification price” without first understanding the environment.
A meaningful quote should explain what is included in the assessment, what testing is required, what documentation will be produced, and what ongoing services are included.
How Should You Choose a PCI DSS Compliance Provider?
Before selecting a PCI DSS certification or compliance services provider, ask:
Is the organization actually PCI SSC qualified for the service I need?
For QSA services, verify the QSA company’s status through PCI SSC. For ASV services, verify that the provider appears on PCI SSC’s current ASV list. PCI SSC recommends checking the current status because ASV listings can change.
Can the provider handle both compliance and technical security?
PCI DSS is not only documentation.
Your provider should understand:
Compliance + Network Security + Application Security + Vulnerability Management + Penetration Testing + Remediation
Can they help with remediation?
A useful compliance partner should help your team understand what needs to change and how to address identified gaps.
Can they support your environment?
Ask whether the provider has experience with:
- Cloud environments
- SaaS
- eCommerce
- Financial services
- Payment processors
- APIs
- Hybrid infrastructure
- Third-party payment providers
Can they support recurring compliance?
PCI DSS requires ongoing security activities. A provider that can support recurring ASV scans, penetration testing, assessments, evidence, and remediation can reduce the need to coordinate multiple vendors.
Why Choose Accorian for PCI DSS Compliance Services?
Accorian provides an end-to-end PCI DSS compliance approach covering readiness, gap assessment, remediation advisory, penetration testing, ASV scanning, and QSA-led assessment and audit support.
Its PCI DSS approach begins with scoping the cardholder data environment and identifying relevant systems, processes, and controls.
The process then moves through:
Scoping → Gap Assessment → Remediation Advisory → Pre-Audit → QSA Assessment → Attestation
Accorian also operates as a PCI Approved Scanning Vendor, providing external vulnerability scanning, validation, remediation guidance, and rescanning. Its broader penetration testing capabilities include:
- External Network Penetration Testing
- Internal Network Penetration Testing
- Application & API Penetration Testing
- PCI ASV Scanning
- Vulnerability Scanning
- Secure Code Review
- Cloud Security Assessment
- Product Suite Security
- Red Teaming
- DevSecOps
- Phishing/Vishing/Social Engineering
Accorian also combines its compliance and security services with GORICO, its AI-enabled GRC platform, which centralizes control documentation, evidence collection, and compliance workflows to help reduce manual effort across the PCI DSS process.
This gives organizations a way to bring multiple PCI DSS activities into a more coordinated program rather than managing QSA assessment, penetration testing, ASV scans, remediation, and compliance evidence as completely separate processes.
What Should You Ask a PCI DSS Provider Before Signing?
Before engaging a PCI DSS compliance services provider, ask these questions:
- Are you a current PCI SSC Qualified Security Assessor Company?
- Are you an Approved Scanning Vendor if ASV scans are part of the engagement?
- What PCI DSS validation path applies to my organization?
- What systems and data will be considered in scope?
- Will you help us define the cardholder data environment?
- Which penetration tests are required for our environment?
- Will you help us remediate findings before the formal assessment?
- What documentation will we receive?
- Will the engagement include the ROC and AOC where applicable?
- What recurring activities will we need after the assessment?
These questions can help prevent one of the most common PCI DSS mistakes: purchasing an individual service without understanding how it fits into the organization’s complete validation strategy.
PCI DSS Compliance Is More Than Passing an Audit
A successful PCI DSS program should not end with a signed document. The objective is to establish a payment environment where cardholder data is properly scoped and protected, vulnerabilities are identified and remediated, security controls are tested, and evidence is maintained for ongoing compliance.
The pieces work together:
Scope → Assess → Remediate → Test → Validate → Attest → Maintain
A QSA assessment validates applicable controls.
A ROC documents the assessment.
An AOC provides the formal attestation.
An ASV scan validates applicable external vulnerability scanning requirements.
Penetration testing evaluates whether security weaknesses can be exploited.
And ongoing security activities help maintain the environment between assessments.
Need Help With PCI DSS Compliance?
If your organization is preparing for PCI DSS compliance, transitioning to PCI DSS v4.0.1, or evaluating a new QSA or ASV provider, Accorian can help you determine the right assessment and testing scope.
Accorian combines PCI DSS assessment, QSA expertise, ASV scanning, penetration testing, remediation advisory, and compliance support to help organizations move from readiness to validation.
Don’t start with a checklist. Start with your payment environment.


