Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Audit & Certification

Qualified Security Assessor

Also known as: QSA, QSA company, PCI QSA
Simply put

A Qualified Security Assessor (QSA) is an independent security organization, and its qualified personnel, approved by the PCI Security Standards Council to check whether a business meets the Payment Card Industry Data Security Standard (PCI DSS). QSAs assess merchants and service providers that handle payment card data and often help them identify and close security gaps. The designation is granted through a qualification program run by the PCI Security Standards Council rather than by any government body.

Formal definition

A Qualified Security Assessor is a designation conferred by the PCI Security Standards Council (PCI SSC) to independent security organizations (QSA companies) and the individuals within them who have completed the Council's qualification program and meet its information security criteria. QSAs are authorized to perform assessments validating compliance of merchants and service providers against PCI DSS requirements. Note that PCI DSS is a contractually enforced industry standard imposed through payment brand and acquirer agreements rather than a statutory regulation, so QSA involvement is a scheme requirement rather than a legal mandate; the QSA validates conformance but is distinct from the entity being assessed and does not itself confer legal compliance. Qualification, program rules, and PCI DSS versions are periodically revised, so readers should verify current requirements against the official PCI SSC documentation.

Why it matters

Organizations that store, process, or transmit payment card data are generally required, through their agreements with payment brands and acquiring banks, to validate their conformance with the PCI Data Security Standard (PCI DSS). For larger merchants and service providers, that validation typically must be performed by a Qualified Security Assessor rather than through self-assessment alone. The QSA therefore acts as an independent check on whether the security controls a business claims to have in place actually meet the standard, giving payment brands and acquirers a consistent, third-party basis for accepting an entity's compliance posture.

It is important to keep the QSA's role in proportion. PCI DSS is a contractually enforced industry standard imposed through payment brand and acquirer agreements, not a statutory regulation, so engaging a QSA satisfies a scheme requirement rather than a legal mandate. A QSA validates conformance against the standard at a point in time; it does not itself confer legal compliance, nor does it assume the assessed entity's ongoing responsibility for maintaining controls between assessments. Readers should treat a QSA's finding as evidence of validated conformance within a defined scope, not as a guarantee against breaches or as a substitute for the organization's own security program.

Because the QSA designation is granted through a qualification program run by the PCI Security Standards Council, and because that program, its rules, and PCI DSS versions are periodically revised, the specific obligations tied to using a QSA change over time. Organizations should confirm current requirements—including when a QSA is required versus when self-assessment is permitted—against the official PCI SSC documentation and their own acquirer's expectations.

Who it's relevant to

Merchants handling payment card data
Businesses that store, process, or transmit cardholder data may be required, depending on their transaction volume and their acquirer's terms, to have a QSA validate their PCI DSS conformance rather than relying on self-assessment. They should confirm with their acquirer whether a QSA assessment applies to them.
Service providers
Organizations that provide services affecting the security of cardholder data on behalf of others are frequently assessed by QSAs. QSA validation gives their customers and the payment brands an independent basis for accepting the provider's compliance posture within a defined scope.
Compliance and information security teams
Internal teams responsible for maintaining PCI DSS controls work with QSAs during assessments and often engage them to help identify and close security gaps. These teams retain ongoing responsibility for controls between assessments, since a QSA validates conformance at a point in time rather than assuming that responsibility.
Security firms seeking qualification
Independent security organizations that wish to perform PCI DSS assessments must complete the PCI Security Standards Council's qualification program and meet its information security criteria to become QSA companies. Because program rules and standard versions are periodically revised, prospective QSAs should track the current official PCI SSC requirements.
Acquiring banks and payment brands
Acquirers and payment brands rely on QSA validation as a consistent, independent input when accepting a merchant's or service provider's PCI DSS compliance. Their contractual terms typically determine when a QSA assessment is required versus when other validation methods are acceptable.

Inside QSA

QSA Company
An organization approved by the PCI Security Standards Council (PCI SSC) to perform assessments of merchants and service providers against the Payment Card Industry Data Security Standard (PCI DSS). The company must meet and maintain qualification requirements defined by the Council, including business, insurance, and security-practice criteria.
QSA (Individual Employee)
A qualified individual employed by a QSA Company who has satisfied the Council's training and certification requirements and is authorized to conduct PCI DSS assessments. Both the company and the individual must hold current qualification for assessment work to be recognized.
PCI DSS Scope
PCI DSS is a contractual standard developed by the PCI SSC that applies to entities that store, process, or transmit cardholder data. It derives its force from agreements with payment brands and acquiring banks rather than from statute in most jurisdictions, so a QSA's role is tied to that contractual framework.
Report on Compliance (ROC)
The primary deliverable a QSA may produce when conducting an on-site assessment, documenting the entity's controls against PCI DSS requirements. The applicability of a full ROC versus a Self-Assessment Questionnaire generally depends on the entity's merchant or service-provider level.
Attestation of Compliance (AOC)
A declaration accompanying an assessment result that summarizes the outcome. It reflects the assessed state of the environment at the time of review rather than a permanent status.
Qualification Maintenance
Ongoing requirements—such as requalification, continuing training, and adherence to Council program rules—that a QSA Company and its assessors must satisfy to remain in good standing. Qualification can lapse, be suspended, or be revoked.

Common questions

Answers to the questions practitioners most commonly ask about QSA.

Is a Qualified Security Assessor a government-appointed or legally mandated role?
No. A QSA is a company (and its associated individuals) qualified by the PCI Security Standards Council, a private-sector body, to perform assessments against the Payment Card Industry Data Security Standard (PCI DSS). PCI DSS is a contractual and industry standard rather than a statute, and the QSA designation carries no governmental authority. Obligations to engage a QSA generally arise from contractual arrangements with payment brands, acquirers, or merchant agreements rather than from law directly. That said, related legal requirements may exist in some jurisdictions or sectors, so readers should verify how contractual and any applicable legal obligations interact in their specific circumstances.
Does a QSA assessment resulting in a compliant report guarantee an organization is secure or free from liability?
No. A QSA assessment evaluates whether an entity meets the applicable PCI DSS requirements at the point in time and for the scope assessed; it is an assessment of conformity to a standard, not a guarantee of security. Compliance and security are distinct concepts: an environment can be assessed as compliant yet still be vulnerable to threats not addressed by, or emerging after, the assessment. A validated assessment also does not by itself confer legal immunity. Application of these outcomes to a particular situation requires professional judgment and, where relevant, legal advice.
How does the role of a QSA differ from that of an internal auditor or an ISA?
A QSA is an external party qualified by the PCI Security Standards Council to conduct independent PCI DSS assessments and, where applicable, produce the associated validation documentation. An Internal Security Assessor (ISA) is an individual employed by an organization who has completed PCI SSC training to perform certain internal PCI DSS functions, but this is a distinct designation with different scope. A general internal auditor performs assessment activities defined by the organization's own program and is not, on that basis alone, qualified to sign PCI DSS validation documents. Readers should confirm current eligibility rules and the specific documents each role may produce against the latest PCI SSC materials.
What should an organization consider when selecting and engaging a QSA?
Organizations generally consider whether the QSA company holds current qualification with the PCI Security Standards Council, the individual assessors' qualification status, relevant sector and technical experience, and independence from the environment being assessed. Because qualification status and program requirements change over time, the QSA's current standing should be verified against the PCI SSC's published listings. Scope, timelines, and deliverables are typically defined in the engagement agreement, and any interaction with an organization's acquirer or payment brand requirements should be clarified in advance.
How is the scope of a QSA assessment typically determined?
Scope is generally defined by the cardholder data environment and the systems, processes, and people that store, process, or transmit account data, as well as connected or security-impacting components. Accurate scoping is a foundational step, and under-scoping can undermine the validity of the assessment. Scoping decisions often depend on network segmentation, data flows, and organizational context, so they are fact-specific. Organizations should confirm scoping expectations against the current PCI DSS text and any acquirer or payment brand instructions rather than relying on generalizations.
How often is a QSA assessment relevant, and does one assessment remain valid indefinitely?
A QSA assessment reflects a point-in-time evaluation against the applicable requirements and for the defined scope; it does not remain valid indefinitely. Reassessment cadence and ongoing validation expectations are generally driven by contractual arrangements with payment brands or acquirers and by the applicable version of the standard. Because PCI DSS is periodically revised and superseded, and validation expectations may differ by entity type and transaction volume, organizations should verify the current requirements and timing obligations against the latest authoritative PCI SSC and payment brand sources.

Common misconceptions

A QSA enforces a law, so PCI DSS is a legal regulation like the GDPR.
PCI DSS is a contractual security standard maintained by the PCI SSC and enforced through agreements with payment brands and acquirers, not a statute in most jurisdictions. A QSA assesses conformance to that standard; obligations generally arise from contract rather than legislation, though local law may reference it in specific cases.
A QSA-issued assessment certifies an organization as permanently compliant.
An assessment reflects the state of the environment at a point in time and does not guarantee ongoing compliance. Compliance must be maintained continuously, and a favorable Report on Compliance or Attestation does not carry forward automatically as controls, scope, or the standard itself change.
Any information security auditor can perform a PCI DSS assessment and produce a valid ROC.
Only individuals and companies holding current QSA qualification from the PCI SSC are recognized to perform certain PCI DSS assessments. A general security audit or assessment is distinct from a QSA-conducted PCI DSS assessment, and qualification status should be verified.

Best practices

Verify a QSA Company's and individual assessor's current qualification status through the PCI SSC's official listings before engaging them, since qualification can lapse or be revoked.
Confirm at the outset which deliverable applies to your situation—for example a full Report on Compliance versus a Self-Assessment Questionnaire—based on your merchant or service-provider level and the requirements set by your acquirer or payment brand.
Treat any assessment result as a point-in-time snapshot and maintain controls continuously rather than relying on a past favorable outcome.
Keep PCI DSS assessment activity distinct from other audits and assessments in your compliance program, and do not assume a general security review satisfies QSA-scope requirements.
Check the current version of PCI DSS and the applicable Council program rules against the official source, as the standard and its qualification schemes are periodically updated or superseded.
Engage qualified professionals to determine how these requirements apply to your specific environment, as scope and deliverable applicability are fact-specific.
Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."