Frequently Asked Question

What is an Attestation of Compliance?
The Attestation of Compliance is the document used to indicate that the appropriate Report on Compliance or Self-assessment Questionnaire has been performed, and to attest to your organization’s compliance status with PCI DSS.
July 2012
Article Number: 1132
Related
-
Is the PCI DSS Attestation of Compliance intended to be shared?
-
Can sensitive information be redacted from the PCI DSS Attestation of Compliance before it is shared with other entities?
-
Can the “Compliant but with Legal exception” option in the AOC be used to identify where a testing procedure could not be performed due to a legal constraint?
Featured FAQ Articles
Most Recently Updated
-
Is the expectation that any PFI investigation initiated must result in a PFI Final Report?
-
Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for assessments documented in a Report on Compliance?
-
Do PCI DSS requirements for keyed cryptographic hashing apply to previously hashed PANs?