Establishing secure connection…Loading editor…Preparing document…

PCI-DSS Compliance AOC Form

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

PCI-DSS Compliance AOC Form

This Attestation of Compliance ("AOC") is executed by Merchant Name: , Merchant Address: and Qualified Security Assessor Firm Name: , Assessor Address: . Effective Date of Attestation: .

RECITALS

WHEREAS, Merchant engages in payment card acceptance and has systems, people, and processes that store, process or transmit cardholder data within the environment described in this document; and

WHEREAS, Assessor has conducted an assessment of Merchant's environment against the Payment Card Industry Data Security Standard (PCI DSS) using the assessment scope, methodology, and evidence described below; and

WHEREAS, the parties intend for this AOC to record the results of that assessment and the parties' respective attestations regarding compliance status as of the Effective Date.

NOW, THEREFORE, in consideration of the mutual covenants set forth below, the parties agree as follows:

1. Definitions

For purposes of this AOC, the following terms have the meanings given: "PCI DSS" means the Payment Card Industry Data Security Standard as adopted by the card brands; "Assessment" means the activities performed by Assessor to evaluate Merchant's compliance; "Scope" means the systems, people, processes and locations included in the Assessment as described in Section 2.

2. Scope of Assessment

Assessment Scope Description:

Assessment Period From: To:

PCI DSS Version Assessed: . Assessment Type:

3. Assessment Methodology and Evidence

Assessor states that the Assessment was conducted using recognized testing techniques including documentation review, personnel interviews, configuration inspection, and sampling of compensating controls where applicable. Evidence collected and relied upon is retained by Assessor as part of the assessment record and is available to card brands or acquirers upon lawful request consistent with contractual obligations.

Systems and Components in Scope

4. Attestation of Compliance

Based on the Assessment performed and to the best of Assessor's professional knowledge, the signatory Assessor hereby attests that, as of the Effective Date, the portion of Merchant's environment identified in Section 2:

Compliance Status:

Summary of Findings and Non-Compliance Items:

If remediation is required, attach a remediation plan and expected completion dates. Remediation Plan Attached:

5. Representations and Warranties

Merchant represents and warrants that it has provided Assessor with full access to the in-scope environment, relevant personnel, documentation and evidence necessary to conduct the Assessment. Assessor represents and warrants that it conducted the Assessment in a professional manner and in accordance with applicable industry standards for security assessments.

6. Confidentiality

The parties acknowledge that Assessment reports and underlying evidence may include confidential information. Each party will protect such information using at least the same degree of care it uses to protect its own confidential information, and will not disclose confidential information except as required by law, card brand or acquirer contractual obligations, or as expressly permitted in writing by the other party.

7. Indemnification

Merchant agrees to indemnify, defend and hold harmless Assessor from claims, liabilities, losses or expenses arising from Merchant's negligence or willful misconduct that materially affects the Assessment or any representations made herein. Assessor agrees to indemnify Merchant for claims arising from Assessor's negligent or willfully wrongful conduct in performing the Assessment.

8. Limitation of Liability

Except to the extent prohibited by applicable law, neither party will be liable for indirect, incidental, consequential, special or punitive damages arising from this AOC or the Assessment. Each party's aggregate liability under this AOC will be limited to direct damages up to the amount paid for assessment services, except for liabilities arising from willful misconduct or gross negligence.

9. Notices

10. Amendments; Waiver

Any amendment or modification of this AOC must be in writing and signed by authorized representatives of both parties. Failure to require strict performance of any provision will not waive that provision or any other rights.

11. Governing Law; Venue

This AOC will be governed by and construed in accordance with the laws of the jurisdiction specified by Merchant's principal place of business. Any disputes arising under or in connection with this AOC will be resolved in the courts of that jurisdiction unless the parties agree otherwise in writing.

12. Entire Agreement; Severability; Counterparts

This AOC, together with any attachments and the Assessment report referenced herein, constitutes the entire agreement between the parties concerning the subject matter and supersedes all prior agreements and understandings. If any provision is held invalid, the remainder will remain in full force. This AOC may be executed in counterparts and by electronic signature, each of which will be deemed an original.

13. Administrative Details

Acknowledgment

The undersigned representatives certify that they are authorized to execute this AOC on behalf of the named party and that, to the best of their knowledge, the information contained in this AOC and any accompanying Assessment report is true, accurate and complete as of the Effective Date.

Merchant:

By:

Date:

Assessor:

By:

Date:

Enter text✕

What the PCI-DSS Compliance AOC Form Is

The PCI-DSS Compliance AOC Form is an Attestation of Compliance completed by a Qualified Security Assessor (QSA) or authorized entity to document that a scoped environment meets Payment Card Industry Data Security Standard requirements. The form summarizes assessment scope, controls tested, exceptions, and the assessor's compliance conclusion, and it is used together with a ROC or SAQ to provide acquirers and partners evidence of cardholder data protections during vendor and audit reviews.

Why an AOC Matters for Cardholder Data Risk

Completing the PCI-DSS Compliance AOC Form provides a concise, auditable statement of an environment's assessed compliance status, clarifies scope limitations and compensating controls, and helps organizations satisfy acquirer and merchant program requirements for cardholder data protection and third-party vendor due diligence.

Why an AOC Matters for Cardholder Data Risk

Which Teams and Organizations Use This Form

Typical users include merchant security teams, QSAs, and acquiring banks that require formal evidence of PCI compliance during vendor assessments.

  • Merchants processing card payments seeking acquirer verification of PCI scope and controls.
  • Qualified Security Assessors documenting test procedures, results, and compliance conclusions.
  • Service providers and third-party vendors demonstrating cardholder data environment protections to customers.

Small merchants, service providers, and managed service vendors also complete AOCs when required by payment processors or contractual obligations.

Step-by-Step: Complete the AOC Accurately

Follow this sequential checklist to complete the PCI-DSS Compliance AOC Form accurately and maintain a reproducible audit trail.

  • 01
    Prepare: Gather ROC/SAQ, scope diagrams, and test evidence.
  • 02
    Complete Fields: Fill assessor, scope, status, and control test results.
  • 03
    Review: Confirm accuracy, check dates, and resolve discrepancies.
  • 04
    Sign: Signer signs, dates, and records contact details.

Digital Configuration When Using an eSignature Workflow

When preparing an electronic AOC, configure fields, authentication, and document retention to match legal and acquirer requirements.

Field Configuration
Signature Field Require signer name, date, and authentication code
Authentication Email link or SMS code; use MFA for high risk
Templates Save AOC template to ensure consistency across assessments
Retention Set archival period and export signed PDF with audit trail

Typical Routing and Verification Flow

This flow shows typical routing and verification steps when submitting an electronic AOC to stakeholders.

  • Upload: Upload signed ROC or completed SAQ with evidence files
  • Assign: Assign reviewers at acquiring bank or merchant
  • Authenticate: Signer identity verified via email or stronger method
  • Distribute: Provide final AOC and audit trail to relevant parties

Platform Requirements for Secure eSubmission

Ensure the eSignature platform supports required security, audit trails, and authentication levels for PCI compliance reporting.

  • Encryption: TLS in transit; AES-256 at rest
  • Audit Trail: Timestamped actions, IP address, and event log
  • Integrations: CRM and storage integrations for secure routing

Core Sections Every Professional AOC Should Include

A professional PCI-DSS Compliance AOC Form includes assessor details, scope definition, control test summaries, exceptions, signature blocks, and references to supporting ROC or SAQ evidence.

Assessor Details

List the QSA name, organization, contact information, report identifier, and accreditation details. Clear attribution supports auditor validation and legal traceability of the attestation. Include assessor signature and date.

Scope Summary

Provide a concise list of in-scope systems, network segments, locations, and cardholder data flows. Explicit scope reduces misunderstanding about assessed assets and compliance applicability in reporting.

Controls Tested

Summarize each control tested, the testing methodology, sample sizes, and results. Include references to test artifacts so reviewers can corroborate the assessor's findings when requested.

Exceptions & Compensations

Document any deviations from PCI requirements, compensating controls applied, and timelines for remediation. This section affects acquirer risk scoring and can require follow-up validation steps.

Conclusion

State the assessor's overall determination: compliant, non-compliant, or conditional. Provide a concise rationale tied to controls and note whether a follow-up assessment is recommended or required.

Supporting Evidence

List attached reports, sampled logs, configuration snapshots, vulnerability scan results, and any external attestations. Clear cross-references make it easier for acquirers and auditors to verify compliance.

Security-Related Data Elements to Include

Encryption: TLS 1.2/1.3 in transit; AES-256 at rest
Access Logs: Timestamped events with IP and actor
Scope Definition: Explicit systems, networks, and data flows
Test Evidence: Vulnerability scans, logs, and control tests
PII Exclusion: Do not include unnecessary personal data
Retention Policy: Signed AOC and ROC stored with audit trail

Penalties and Risks from Incorrect or Missing AOCs

Filing Penalties: IRC §6721 applies to incorrect returns
Acquirer Fines: Fines or increased reserve requirements
Remediation Costs: Costly remediation and retesting
Contract Exposure: Breach of contract or indemnity claims
Reputation Risk: Loss of customer trust and business
Operational Impact: Service disruptions and compliance holdbacks

Common Preparation Challenges to Watch For

  • Unclear scope definitions can cause mismatched evidence and incomplete attestations, leading acquirers to require additional testing or reject the AOC.
  • Incomplete or inconsistent control testing documentation often triggers follow-up audits and increases remediation timelines and costs.
  • Using unsigned forms, missing dates, or mismatched signer identities undermines legal attribution and may invalidate the attestation.
  • Failure to retain evidence and AOC PDFs with audit trails can hamper investigations or regulatory responses.

Key Timing Considerations for Issuing and Retaining the AOC

Key timing considerations for producing, signing, and submitting an AOC to acquirers and auditors are shown below.

Assessment Completion:

Sign AOC after all tests are complete

Acquirer Submission:

Submit to acquirer per merchant agreement

Annual Renewal:

Reissue annually or when scope changes

Remediation Deadlines:

Track timelines agreed with acquirer

Record Retention:

Retain signed AOC with evidence per policy

eSignature Plan Comparison Relevant to AOC Delivery

Compare common eSignature plans and features relevant for delivering signed PCI-DSS Compliance AOC Forms to acquirers and auditors.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

FAQs and Troubleshooting for the PCI-DSS Compliance AOC Form

Frequently asked questions and solutions for common issues when preparing, signing, or submitting a PCI-DSS Compliance AOC Form are provided below.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users