Skip to contentSkip to content

PCI DSS Audit Process Guide

From initial scoping to final Attestation of Compliance — a complete walkthrough of every phase in the PCI DSS v4.0.1 audit lifecycle.

Run Audit Effort Benchmark →← Back to PCI DSS Guide

6-Phase Audit Lifecycle

1

Scoping

2–4 weeks
  • Define cardholder data environment (CDE)
  • Inventory all in-scope systems
  • Network segmentation review
  • Document data flows
2

Gap Assessment

3–6 weeks
  • Review all 285 controls
  • Identify gaps vs current state
  • Prioritise remediation backlog
  • Estimate remediation effort
3

Remediation

4–16 weeks
  • Close critical findings first
  • Implement compensating controls where needed
  • Document all changes
  • Retest remediated items
4

Evidence Collection

4–8 weeks
  • Gather policy documents
  • Run scans (ASV, internal)
  • Collect system config screenshots
  • Export log samples and reports
5

QSA Assessment

2–6 weeks
  • Submit evidence package
  • QSA interviews and walkthroughs
  • On-site visits (if required)
  • Clarification requests
6

Report & Attestation

2–4 weeks
  • QSA drafts ROC
  • Review and respond to findings
  • Sign Attestation of Compliance (AOC)
  • Submit to acquiring bank

FAQ

What is a ROC?

A Report on Compliance (ROC) is the formal PCI DSS assessment report produced by a Qualified Security Assessor (QSA) for Level 1 merchants and service providers. It documents all 285 test procedures and their outcomes.

What is the difference between ROC and SAQ?

A ROC (Report on Compliance) requires an external QSA and is mandated for Level 1 merchants. A Self-Assessment Questionnaire (SAQ) allows merchants to self-certify at lower transaction volumes, with fewer requirements depending on SAQ type.

How long does a PCI DSS audit take?

SAQ completion: 2–8 weeks. Level 1 ROC: 3–9 months depending on scope size, evidence maturity, and number of findings requiring remediation.

What happens if you fail a PCI audit?

A failed PCI audit results in compensating controls documentation, remediation of findings, and a follow-up assessment. Persistent non-compliance can result in fines from card brands ranging from $5,000–$100,000 per month.

How long will your audit take?

Get a personalised audit effort estimate based on your organisation profile.

Run Free Benchmark →