Assessor Details
List the QSA name, organization, contact information, report identifier, and accreditation details. Clear attribution supports auditor validation and legal traceability of the attestation. Include assessor signature and date.
Completing the PCI-DSS Compliance AOC Form provides a concise, auditable statement of an environment's assessed compliance status, clarifies scope limitations and compensating controls, and helps organizations satisfy acquirer and merchant program requirements for cardholder data protection and third-party vendor due diligence.
Typical users include merchant security teams, QSAs, and acquiring banks that require formal evidence of PCI compliance during vendor assessments.
Small merchants, service providers, and managed service vendors also complete AOCs when required by payment processors or contractual obligations.
| Field | Configuration |
|---|---|
| Signature Field | Require signer name, date, and authentication code |
| Authentication | Email link or SMS code; use MFA for high risk |
| Templates | Save AOC template to ensure consistency across assessments |
| Retention | Set archival period and export signed PDF with audit trail |
Ensure the eSignature platform supports required security, audit trails, and authentication levels for PCI compliance reporting.
List the QSA name, organization, contact information, report identifier, and accreditation details. Clear attribution supports auditor validation and legal traceability of the attestation. Include assessor signature and date.
Provide a concise list of in-scope systems, network segments, locations, and cardholder data flows. Explicit scope reduces misunderstanding about assessed assets and compliance applicability in reporting.
Summarize each control tested, the testing methodology, sample sizes, and results. Include references to test artifacts so reviewers can corroborate the assessor's findings when requested.
Document any deviations from PCI requirements, compensating controls applied, and timelines for remediation. This section affects acquirer risk scoring and can require follow-up validation steps.
State the assessor's overall determination: compliant, non-compliant, or conditional. Provide a concise rationale tied to controls and note whether a follow-up assessment is recommended or required.
List attached reports, sampled logs, configuration snapshots, vulnerability scan results, and any external attestations. Clear cross-references make it easier for acquirers and auditors to verify compliance.
Sign AOC after all tests are complete
Submit to acquirer per merchant agreement
Reissue annually or when scope changes
Track timelines agreed with acquirer
Retain signed AOC with evidence per policy
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies | Varies | Varies | Varies |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |