Deck Is Now PCI DSS Level 1 ROC Certified

Deck PCI DSS v4.0.1 Compliant 2026, assessed by Insight Assurance
August 31, 2026

Deck has achieved PCI DSS Level 1 compliance through a Report on Compliance (ROC) — the highest level of certification under the PCI Security Standards Council, and the version that requires a Qualified Security Assessor (QSA) to independently test every applicable control and attach their name to the result.

If you sell into fintechs or enterprises, that last part matters more than it sounds like it should.

SAQ vs. ROC: A Real Distinction, Not a Technicality

Most vendors who claim “PCI compliant” have completed a Self-Assessment Questionnaire (SAQ) — a checklist the company fills out about its own controls. No external party verifies the answers. It’s a reasonable bar for a lower-risk merchant. It is not the bar most enterprise procurement and security teams will accept from a service provider that touches cardholder data.

A Level 1 ROC is different. A QSA audits the environment directly: control by control, requirement by requirement, with evidence. The resulting report carries the assessor’s attestation, not just the vendor’s. For a procurement team evaluating a data infrastructure provider that will have contact with primary account numbers (PAN), an SAQ is a claim. A ROC is a verified one.

That distinction shows up concretely in vendor security reviews. A lot of enterprise and fintech procurement teams have a hard rule: they won’t accept an SAQ from a service provider that touches PAN, full stop. A ROC is often the difference between clearing security review in weeks versus not clearing it at all.

Why This Matters for Deck Specifically

Deck runs agent-driven workflows across web portals on behalf of fintechs and enterprises — including portals where payment data is part of the workflow. That means Deck’s infrastructure, not just a customer’s own systems, is in scope for how that data is handled, stored, and transmitted.

Level 1 is the tier PCI DSS reserves for the organizations with the largest volume and the most stringent audit requirements. Reaching it as a ROC — rather than stopping at a self-attested SAQ — means:

For teams running Deck workflows near payment portals, this is the artifact you hand to your own security and compliance reviewers — the kind of documentation that closes a vendor review instead of stalling it.

What This Adds to Deck’s Compliance Posture

PCI DSS Level 1 ROC joins Deck’s existing security and compliance program, which includes SOC 2, HIPAA, GDPR, CCPA, and PIPEDA. Together, they’re built for the same underlying requirement: any platform authenticating into portals, moving data on a schedule, and handling credentials at scale has to prove its controls, not just describe them.

Full detail on Deck’s security architecture, credential vault, and now-current certifications is available on the security page.

If you’re evaluating Deck for a workflow that touches payment data, or your security team needs the ROC for a vendor review, reach out and we’ll get it into their hands.

Need the ROC for a vendor review?

Talk to the Deck team and we’ll get the Report on Compliance into your security reviewers’ hands.

Talk to Sales →

Related reading