Internal Security Assessor
An Internal Security Assessor (ISA) is an employee of a qualifying organization who has been trained and certified by the PCI Security Standards Council to perform PCI DSS assessments for their own company. ISAs learn how to evaluate their organization's compliance with PCI DSS and recommend fixes for issues they identify.
An Internal Security Assessor is an individual from an eligible, qualifying organization who has completed the PCI SSC's ISA training and certification program, enabling them to perform internal PCI DSS assessments for their own organization and recommend remediation for identified gaps. The ISA credential is administered by the PCI Security Standards Council and is distinct from an external Qualified Security Assessor (QSA); it applies to PCI DSS assessment activity and is separate from other PCI SSC programs and standards. Program eligibility, training requirements, and the precise scope of activities an ISA may perform are defined by the PCI SSC and should be confirmed against current PCI SSC program documentation.
Why it matters
The Internal Security Assessor role gives qualifying organizations an internal, PCI SSC–trained resource who understands PCI DSS assessment methodology from the inside. Rather than relying solely on external assessors for every compliance activity, an organization can build in-house expertise that helps it identify gaps earlier, interpret requirements consistently, and prepare more effectively for formal assessments. This can improve the day-to-day maturity of a security and compliance program, because someone within the organization holds a recognized credential and shared vocabulary with external assessors.
Because the ISA credential is administered by the PCI Security Standards Council and is distinct from the external Qualified Security Assessor (QSA) credential, it is important not to conflate the two. An ISA performs internal PCI DSS assessment activity for their own organization; the specific scope of what an ISA may formally validate, and whether an external QSA is still required for a given deliverable, is defined by PCI SSC program rules and by applicable card brand and acquirer requirements. Those rules can change, so organizations should confirm the current scope of ISA activity against current PCI SSC program documentation rather than assuming a fixed set of permissions.
The ISA credential applies to PCI DSS assessment work and is separate from other PCI SSC programs and standards, such as those governing payment software, PIN, point-to-point encryption, or 3-D Secure. An ISA credential is intended to strengthen internal capability and remediation planning; it does not by itself certify an organization as compliant, and the value it delivers depends on how the individual and organization apply the training in practice.
Who it's relevant to
Inside ISA
Common questions
Answers to the questions practitioners most commonly ask about ISA.