QSA-Led ROC & AOC

Powered by ValueMentor

Get from PCI gaps to your ROC and AOC with a clear, fixed-price program.

Preparing for a PCI DSS Level 1 assessment can involve hundreds of requirements, technical controls, policies, evidence requests and remediation activities. Secusy simplifies the journey. Every program starts with a ValueMentor-led PCI DSS assessment — you then choose how much help you want from us.
Fixed prices from $12,500.

Assessment planFrom $12,500
Guided plan$17,500
DeliveryRemote, delivered globally
Delivered byValueMentor

The definition

What is PCI DSS Level 1?

Payment brands and acquirers establish compliance-validation programs and determine the reporting method organizations must provide. Secusy's PCI DSS Level 1 service is designed for startups that have been asked to complete a QSA-led PCI DSS assessment resulting in a Report on Compliance (ROC). Every program starts with a ValueMentor-led PCI DSS assessment that identifies non-compliances and builds a remediation tracker, then proceeds through the formal QSA assessment and completion of the applicable ROC and Attestation of Compliance (AOC). If you are unsure whether you need a ROC, confirm the requirement with your acquirer, payment brand or other compliance-accepting entity before purchasing.
  • Assessment plan

    From $12,500

  • Guided plan

    $17,500

  • Delivery

    Remote, delivered globally

  • Delivered by

    ValueMentor

Three ways to get PCI DSS ready

Every program starts with a ValueMentor-led PCI DSS assessment, a non-compliance report and a remediation tracker. You then choose how much help you want from us.

Assessment

PCI-ready startups with a capable security or compliance team

$12,500one-time

Package scope
  • Remediation ownershipCustomer
  • PCI advisoryAssessment clarification
  • Evidence preparationRequirements provided

Timeline depends on your readiness, scope complexity and team availability.

Complete

Startups that want ValueMentor working alongside them throughout

$25,000one-time

Everything in Guided, plus
  • Remediation ownershipCustomer, with ValueMentor handholding
  • PCI advisoryWeekly working sessions
  • Policy supportUp to 15 customized policies/procedures
  • Evidence preparationHands-on support

Timeline depends on your readiness, scope complexity and team availability.

Compare the PCI DSS programs

FeatureAssessmentGuidedComplete
Remediation ownershipCustomerCustomer with VM guidanceCustomer with VM handholding
PCI advisoryAssessment clarificationBiweeklyWeekly
Policy support—TemplatesUp to 15 customized policies/procedures
Implementation guidance—GuidedHands-on support
Evidence preparation guidanceRequirements providedGuidedHands-on support
Evidence readiness reviewDuring assessmentContinuous
Compliance program management——
Scope confirmation
Initial PCI DSS assessment
Non-compliance report
Remediation tracker
Secusy compliance workspace
Cywareness subscription
Formal QSA assessment
ROC
AOC

If your team already understands PCI DSS and is largely compliant, choose Assessment. If your technical team can implement the controls but needs PCI expertise, choose Guided. If you want a PCI team actively working alongside you throughout the program, choose Complete.

There are no separate assessment fees added at the end of the program for the agreed fixed scope. PCI SSC recognizes official reporting documents such as the ROC, AOC and applicable SAQs as PCI DSS validation documents rather than separate PCI DSS “certificates.”

How it works

Every program starts with an assessment

You do not have to know exactly what is missing before you start. Our process begins by establishing your PCI DSS scope and assessing your current environment against the applicable requirements.

  1. Step 1

    Kick-off & scope confirmation

    We understand your payment environment, cardholder-data flows, cloud architecture, applications, third-party dependencies and existing security controls, then confirm the environment included in the fixed-price program.

  2. Step 2

    Initial PCI DSS assessment

    ValueMentor assesses your environment against the applicable PCI DSS requirements — documentation reviews, technical configuration reviews, interviews, process reviews, evidence examination and system/architecture reviews.

  3. Step 3

    Non-compliance report

    We document identified gaps and explain the areas that must be addressed before successful completion of the assessment.

  4. Step 4

    Remediation tracker

    Every identified non-compliance is added to a structured tracker covering the requirement, finding, required action, responsible owner, evidence required, status and target date — the working compliance plan for the engagement.

  5. Step 5

    Remediation

    Assessment customers remediate independently. Guided customers get periodic ValueMentor advisory support. Complete customers get hands-on support throughout the remediation program.

  6. Step 6

    Formal assessment

    Once remediation is complete and sufficient evidence is available, the formal QSA assessment is completed.

  7. Step 7

    ROC & AOC

    Following successful completion of the assessment, the applicable PCI DSS Report on Compliance and Attestation of Compliance are finalized.

Add PCI security testing

PCI DSS compliance is not only a documentation exercise. Your environment also needs recurring vulnerability management and security testing. Add the PCI Security Testing Bundle to any Assessment, Guided or Complete program.

  • Quarterly ASV Scanning

    • 4 quarterly ASV scans
    • Up to 10 external IP addresses
    • Required rescanning within the registered scope
  • Quarterly Internal Vulnerability Assessments

    • 4 internal vulnerability-assessment cycles
    • Up to 50 in-scope systems/assets
  • Annual External Network Penetration Test

    • Up to 10 external IP addresses
  • Annual Internal Network Penetration Test

    • Up to 50 in-scope systems/assets
  • Annual Web Application & API Penetration Test

    • 1 web application/platform
    • Up to 50 dynamic screens/pages
    • Up to 50 API endpoints
    • Up to 3 user roles
  • Segmentation Testing

    • Included where network segmentation is relied upon to reduce PCI DSS scope
    • One segmentation architecture
  • Retesting

    • Up to 2 remediation retest cycles for identified penetration-testing findings

PCI Security Testing Bundle

$7,500/year

Additional security testing required because of significant infrastructure, application or architectural changes is outside the bundle and can be purchased separately. PCI DSS requires vulnerability scanning at least once every three months, and external scans under the applicable requirement are performed by an Approved Scanning Vendor.

Is your startup eligible for fixed pricing?

Our fixed-price PCI DSS Level 1 programs are designed for relatively straightforward, cloud-native startup environments. To qualify, your PCI environment must generally fit within the following boundaries.

  • Organization

    • One legal entity
    • Startup or scale-up
    • One PCI DSS assessment scope
    • One primary product or platform
  • Cardholder data environment

    • One primary production CDE
    • No multiple independent CDEs
    • No customer-owned data centre
    • No ATM environment
    • No physical POS estate
    • No PIN-processing environment
    • No card manufacturing or personalization environment
  • Cloud

    • One primary cloud provider — AWS, Microsoft Azure or Google Cloud
    • Up to 3 cloud accounts, subscriptions or projects
    • Cloud-native or predominantly cloud-hosted architecture
  • Third parties

    • Up to 10 PCI-relevant third-party service providers
    • Review of their relationship, responsibilities and relevant evidence is included
  • Delivery

    • Remote assessment and advisory
    • Customer provides reasonable access to required personnel, systems, documents and evidence
    • Customer completes remediation within the agreed program period

The third-party providers' own environments are not included in the ValueMentor assessment scope. If a third-party provider itself requires assessment, this is treated as a separate engagement. Environments involving multiple CDEs, multiple cloud providers, complex payment infrastructure, large physical estates, PIN environments or significantly larger technical scope require a custom PCI DSS engagement.

Included

What you get

Regardless of the plan selected, the objective is clear: give your startup a structured route from its current PCI posture to successful assessment.

Your program includes

  • Defined PCI DSS scope
  • Initial PCI DSS assessment
  • Documented non-compliances
  • Remediation tracker
  • Secusy compliance workspace
  • Cywareness security awareness access
  • Assessment evidence requirements
  • QSA-led formal assessment
  • Report on Compliance
  • Attestation of Compliance

There are no separate assessment fees added at the end of the program for the agreed fixed scope.

Security awareness included

PCI DSS requires organizations to maintain a security awareness program. Every Secusy PCI DSS Level 1 package therefore includes 12 months of Cywareness security awareness training for up to 100 users. Additional users can be added separately.

  • Deliver security-awareness training
  • Track training completion
  • Maintain awareness records
  • Support PCI DSS evidence requirements
  • Build security awareness beyond the assessment itself

Why Secusy + ValueMentor?

One journey from assessment to ROC and AOC. Many startups pursuing PCI DSS Level 1 coordinate QSA assessment, remediation support and compliance tooling separately — Secusy and ValueMentor bring the program together in one fixed-price engagement.

One journey instead of multiple vendors

Your compliance program, remediation tracking, security awareness, optional vulnerability scanning, penetration testing and QSA assessment can be coordinated through one engagement.

Fixed pricing for eligible startups

Know the cost of your PCI DSS program before you begin — no open-ended consulting engagement for environments that remain within the agreed scope.

Start with evidence, not guesswork

We first assess your current environment. You receive documented findings and a structured remediation tracker before deciding how much implementation support your team requires.

Choose the support you actually need

Already PCI-ready? Choose Assessment. Have a capable internal team but need expertise? Choose Guided. Need someone working closely alongside you? Choose Complete.

Digital compliance management

Use Secusy to organize findings, responsibilities, remediation and evidence rather than managing the entire PCI program through spreadsheets and email.

Powered by ValueMentor

Secusy is the digital sales and service-delivery platform for ValueMentor cybersecurity services. ValueMentor is a member of the PCI Security Standards Council's 2026–2028 Global Executive Assessor Roundtable.

Questions

Frequently asked questions

Ready to start your PCI DSS Level 1 program?

Start with a defined scope, clear pricing and an assessment-led approach. PCI DSS compliance delivered through Secusy, powered by ValueMentor.

Assessment

$12,500one-time

Complete

$25,000one-time

Optional PCI Security Testing Bundle — $7,500/year, addable to any plan above.