Get Ready for the Future! Download the State of Checkout 2025 White Paper Today
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Use Cases

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Solutions

Get the 2025 State of Checkout Report

View the Demo
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Parter Integrations

Partners & Integrations

Integrations Ecosystem
Our Partners

Latest Partner News

Webinars

Paysafe Unveils Strategic Partnership with Spreedly

Featured Partner

PayPal
Product & Solutions

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Pricing
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Developers

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Partners & Integrations

Partners & Integrations

Integrations Ecosystem
Our Partners

Latest Partner News

Webinars

Paysafe Unveils Strategic Partnership with Spreedly

Featured Partner

PayPal
Company

Company

About
Leadership
Careers
Contact Us
News
Company
Log In
See a Demo
Log In
See a Demo
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Use Cases
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Blog
Platform

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Use Cases
Resources

The Open Payments Library

Take a look at all of our resources and get the information you need to grow your business

View all Resources

Featured resources

The Payments Guide to Expansion into LATAM
Accelerate Your Growth by Expanding into Brazil
Security, Compliance, and AI: Inside Spreedly’s 2025 Foundation:

Spreedly Makes Agentic Commerce a Live Channel for Merchants

Read More
Company

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Blog
Log In
See Demo

Product & Solutions

Learn more about the only open payments platform built for global commerce

How it Works

Solutions

Open Payments Connectivity
Payment Data Security & Compliance
Intelligent Payment Optimization
Fraud Prevention & Authentication
Operational Agility & Simplicity
Centralized Management & Reporting

Platform Pillars

Connect

The unified orchestration layer for wallets and alternative payments

Vault

The secure repository for all your payment methods

Optimize

Workflow-driven payments intelligence for smarter routing and higher auth rates

Protect

A flexible fraud and authentication layer. Instantly add advanced fraud tools and 3DS

Resolve

Reduce siloes, advanced security and billing control

View How Spreedly

Connects to your favorite payment methods
Optimizes your revenue
Protects your data
Reduces fraud
View the Demo
Back to Blog
Back to News

Payment Security

July 9, 2024

What is PCI Attestation of Compliance?

Your guide to obtaining PCI compliance through Attestation of Compliance documentation

Written by

Rachel Fine

In this article

Share

Related products

No items found.

Lorem Ipsum Dolor Sit

Vel sed vitae enim nec suspendisse ut viverra tincidunt quis

Learn More

The PCI Data Security Standard (DSS) dictates how businesses can securely process and manage payments. As cybercrime persists as a significant challenge to payment security, this security standard helps protect you against substantial financial loss and frustration. 

According to IBM’s 2023 Cost of a Data Breach Report, the total average cost of a breach has risen to $4.45 million, more than a 15% increase compared to three years prior. 

Securing your payment system according to the latest regulatory standards takes exceptional effort and resources. The last thing you want to do is reach the finish line and discover you don’t know how to prove the strength of your data security.

When in need of such proof, an attestation of compliance is a good place to start.

Completing an Attestation of Compliance: Why It Matters

An attestation of compliance form proves a payment system meets the 12 high-level PCI requirements. Merchants and service providers use this form to present the results of their compliance assessment, completed by either a qualified security assessor or an internal security assessor. 

As part of this assessment, you must complete a self-assessment questionnaire or a report on compliance. The type of assessment you complete depends on your merchant level. Take a look at the purpose of these two assessments and their requirements:

  • SAQ: An SAQ helps merchants categorized in Levels 2 to 4 self-assess their compliance based on the specific business processes and the methods they use to handle payment card data. Different types of this questionnaire exist to serve different businesses and their unique payment processing systems. 
  • ROC: A ROC is a more formal document prepared by a Qualified Security Assessor (QSA) or an Internal Security Assessor (ISA). This type of documentation is often only expected of Level 1 merchants and must be completed as an independent evaluation conducted by one of the qualified third parties listed before. A ROC includes detailed information about your systems, processes, and controls related to the protection of cardholder data.

Following the completion of either the SAQ or ROC assessment, your business can receive an AOC, serving as tangible evidence that your organization operates securely.

However, completing an AOC is not a one-time achievement. You must annually complete a compliance assessment and attestation form to prove your system meets the current standards. Failure to comply can have severe consequences, including fines and reputational damage. 

PCI DSS 4.0: Proving Your Compliance with the Latest Regulatory Update 

PCI DSS 4.0, the newest iteration of the security standard, came into effect in March 2024 and aims to achieve the following goals:

  • Continuing to meet the security needs of the payment industry
  • Promoting security as a continuous process
  • Adding flexibility for different methodologies
  • Enhancing validation methods

While the new standard is officially in effect, several new requirements are future-dated, with compliance not expected until March 2025. As of March 2024, the 4.0 versions of the AOC form for merchants and service providers are available and ready for use on the PCI Document Library. 

How to Complete an Attestation of Compliance

While PCI DSS compliance is not federally mandated, failing to complete a required AOC can result in the card issuing companies you work with imposing significant fines or even revoking your account access until you remediate your non-compliance issues. 

To complete an AOC, the first step is determining your merchant level, which is based on your number of annual transactions. As we have discussed, not all businesses must submit an AOC. Merchants Levels 1 to 3 are required to complete an AOC. 

Once you are certain of your merchant level, you can determine which assessments you need to complete. A SAQ can be completed internally, while a ROC requires the assistance of a third-party assessor. Your finished SAQ or ROC serves as the crucial component for obtaining an AOC. 

Regardless of the type of assessment required, taking the time to optimize your compliance strategy before performing this assessment is key. Merchants who rely on external service providers for their payment infrastructure should make sure to choose providers with Level 1 PCI compliance. 

With Spreedly, You Can Reduce Your Compliance Burden

PCI compliance can be a painful process, especially for growing businesses with enough to worry about. Spreedly’s Advanced Vault offers Level 1 compliance, the highest level for merchants. 

Our vaulting solution helps you establish a modern, evergreen approach to payment data security, all while ensuring you grow your revenue along the way. 

With Spreedly, you gain a fully-optimized payment environment ready to handle your biggest transactions, helping you to reduce the technological burden of compliance. 

Plus, we help you improve recurring payments and drive customer loyalty with features like Network Tokenization and Account Updater. By keeping your stored payment data up-to-date, Spreedly enables you to meet compliance requirements while also improving the customer payment experience. 

Chat with Spreedly today to learn how our payment orchestration solution can benefit your business. 

Download the PCI Compliance eBook Below

Support Portal

Spreedly Support
Trust Center
Platform Status

Developer Portal

Developer Guides
Documentation
Read more
Written By
No items found.

Navigating AI Risk

Building Resilience for Global Scale

Download Free
Get My Report
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

140+ Payment Integrations

Managed Payment Vault

Learn More
Download Free
Get My Report
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Written by

Rachel Fine

Rachel Fine is Senior Compliance Manager at Spreedly, where she leads the company’s PCI-DSS and SOC 2 compliance programs and oversees governance frameworks that support secure, scalable payment infrastructure. Her work focuses on translating regulatory requirements into practical, risk-based processes that enable the business to move confidently while maintaining strong security and audit readiness.

Rachel brings a structured, program-driven approach to compliance, balancing strategic oversight with operational detail. She has guided initiatives spanning PCI DSS 4.0 readiness, data classification, SOC 2 certification, and customer advisory on regulatory obligations, helping organizations navigate evolving standards without slowing innovation.

Rachel writes about payment compliance, PCI DSS, SOC 2, and regulatory strategy, with a focus on helping organizations understand the real cost of compliance, reduce development burden, and build resilient governance programs that support long-term growth.

Lorem Ipsum Dolor Sit

Vel sed vitae enim nec suspendisse ut viverra tincidunt quis

Learn More

Related Articles

Addressing New PCI DSS 4.0 Security Concerns With Payments Orchestration

Payment Security

Rachel Fine

November 22, 2023

Arc’teryx and the 2019 PSD2 Mandate

Payment Security

Lorra Gosselin

June 23, 2020

Benefits of Performing Security Risk Assessments

Payment Security

Aaron Finley

June 15, 2022

Back to Blog

Get Regular Updates From Payments Experts

Subscribe to our newsletter and we’ll send you a monthly update of all of our new content so you don’t miss out on new data, new insights, and news from the world of payments. 

Insights and updates you actually care about

By subscribing, you agree to our Privacy Policy and Terms.

Find Us On

Company
  • Pricing
  • About
  • Careers
  • Contact Us
  • Partners
Resources
  • Support
  • Guides
  • FAQ
  • News
  • Webinars
  • Trust Center
Developers
  • Developer Guides
  • Documentation
  • See Demo
  • Status

Find Us On

Privacy SettingsTermsPrivacyStatus
© 2026 Spreedly, Inc. All rights reserved.