The PCI SSC (Payment Cards Industry Security Standards Council) allows for some organizations that handle payment card data (merchants and their service providers) to complete a Self Assessment Questionnaire (SAQ) and associated Attestation of Compliance (AOC) to the PCI Data Security Standard (DSS) rather than get a full onsite assessment and Report on Compliance (ROC) from a Qualified Security Assessor (QSA). A QSA can still be engaged to assist with the details of completing the appropriate SAQ; however, unlike in a full ROC, the organization is attesting to its own compliance rather than seeking the independent opinion of a QSA.