A retail merchant processes approximately 2 million credit card transactions annually. According to the Payment Card Industry Data Security Standard (PCI DSS), which of the following is the primary requirement for this merchant to validate their compliance?
-
A
Completing an annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA).
-
B
Submitting to quarterly network scans by an Approved Scanning Vendor (ASV) only.
-
C
Completing an annual Self-Assessment Questionnaire (SAQ).
-
D
Undergoing a mandatory on-site audit by the major card brands.