Skip to main content
Category: PCI DSS Compliance

Qualified Security Assessor

Also known as: QSA, QSA company, Qualified Security Assessor company
Simply put

A Qualified Security Assessor (QSA) is an independent security organization that the PCI Security Standards Council has qualified to check whether a business meets PCI DSS requirements. QSAs review a company's payment security practices, identify gaps, and help validate compliance. The term also refers to the individuals trained and qualified to perform these assessments on behalf of a QSA company.

Formal definition

A Qualified Security Assessor (QSA) is an independent security organization qualified by the PCI Security Standards Council (PCI SSC) to validate an entity's compliance with the PCI Data Security Standard (PCI DSS). QSA companies employ individuals who complete the PCI SSC's QSA qualification program and are authorized to perform PCI DSS assessments of merchants and service providers, documenting results in accordance with PCI SSC program requirements. The QSA designation is governed by the PCI SSC's assessor program and is distinct from other PCI SSC assessor qualifications and from separate standards such as PA-DSS, PCI PIN, PCI P2PE, or PCI 3DS; the specific scope of a QSA engagement depends on the assessment being performed and should be confirmed against the current PCI SSC program documentation.

Why it matters

PCI DSS applies to any entity that stores, processes, or transmits cardholder data, but the standard itself does not validate an organization's compliance. QSAs fill that role: as independent organizations qualified by the PCI Security Standards Council (PCI SSC), they provide the third-party assessment that acquirers, payment processors, and card brands often rely on to confirm a merchant or service provider actually meets PCI DSS requirements rather than merely asserting it. This independence matters because self-attestation alone can miss gaps that an experienced assessor is trained to identify.

For many larger merchants and service providers, a QSA-led assessment and the resulting Report on Compliance is the mechanism through which PCI DSS validation is documented and accepted within the payment ecosystem. Beyond producing a compliance artifact, QSAs review payment security practices, identify gaps, and help organizations understand where their controls fall short. This can help reduce the likelihood that weaknesses in the handling of cardholder data go undetected, though it is important to note that a point-in-time assessment reflects the state of controls at the time of review and does not guarantee ongoing security between assessments.

Because the QSA designation is granted and governed by the PCI SSC's assessor program, it carries a defined and verifiable qualification rather than a generic security credential. Organizations should confirm a QSA company's current listing and the specific scope of an engagement against current PCI SSC program documentation, since the QSA qualification is distinct from other PCI SSC assessor roles and from separate standards such as PA-DSS, PCI PIN, PCI P2PE, and PCI 3DS.

Who it's relevant to

Merchants and service providers
Organizations that store, process, or transmit cardholder data may be required or may choose to engage a QSA to validate PCI DSS compliance. A QSA can help identify gaps in payment security practices and document validation, though the assessed entity remains responsible for maintaining controls between assessments.
Acquirers and payment processors
Acquirers and processors often rely on QSA-produced assessment results as part of how they confirm that a merchant or service provider meets PCI DSS requirements. They may direct entities to engage a QSA depending on the validation approach expected for a given tier or environment.
Compliance officers and security engineers
Those responsible for a PCI DSS program work directly with QSA personnel to define scope, evidence controls, and remediate identified gaps. Confirming the QSA company's current PCI SSC listing and the agreed scope against current program documentation helps ensure the engagement aligns with the applicable standard version.
Security companies pursuing assessor status
Security organizations seeking to perform PCI DSS assessments must complete the PCI SSC's QSA company qualification program, and their staff must complete the PCI SSC's QSA training and qualification requirements. This designation is distinct from other PCI SSC assessor qualifications, so companies should confirm which program matches the assessments they intend to perform.

Inside QSA

QSA Company Qualification
A firm qualified by the PCI Security Standards Council (PCI SSC) to perform PCI DSS assessments. The company must meet business, insurance, and program requirements defined by the PCI SSC and appear on the Council's published list of qualified companies.
QSA Employee Qualification
Individual assessors employed by a QSA company who have completed the PCI SSC training and requalification requirements. The individual qualification is distinct from the company qualification, and both are needed for an assessment to be recognized.
Scope of Work
QSAs are qualified to assess compliance against PCI DSS. Assessments against other PCI SSC standards (such as PCI P2PE, PCI 3DS, or the Software Security Framework) require separate, distinct qualifications and are not covered by a PCI DSS QSA credential alone.
Report on Compliance (ROC)
The formal deliverable a QSA produces documenting the assessment, testing performed, and findings for each applicable PCI DSS requirement. Requirement numbering and wording vary between PCI DSS versions, so the ROC should be completed against the version in force at the time of assessment.
Attestation of Compliance (AOC)
A summary document attesting to the results of the assessment, signed by the assessed entity and the QSA. It reflects the outcome documented in the ROC.
Scope Validation
Part of a QSA engagement involves reviewing and validating the defined cardholder data environment (CDE), including where cardholder data such as PAN is stored, processed, or transmitted, and confirming that sensitive authentication data is not retained after authorization.

Common questions

Answers to the questions practitioners most commonly ask about QSA.

Does hiring a QSA guarantee that our environment is secure or that we will pass our assessment?
No. A QSA is an individual qualified by the PCI Security Standards Council to perform PCI DSS assessments on behalf of a QSA company. The engagement is intended to independently assess and validate whether controls meet the applicable PCI DSS requirements at the time of the assessment; it is not a guarantee of ongoing security. A QSA cannot guarantee a passing outcome, and an assessment reflects a point in time rather than continuous compliance. Security posture depends on how controls are implemented, maintained, and operated after the assessment concludes.
Can a QSA validate compliance with any PCI standard, such as PA-DSS, PCI PIN, PCI P2PE, or PCI 3DS?
Not automatically. The QSA qualification specifically concerns PCI DSS assessments. Other PCI standards are governed by separate programs with their own assessor qualifications, for example the PCI Software Security Framework and its predecessor PA-DSS, PCI PIN, PCI P2PE, and PCI 3DS each have distinct assessor roles and program requirements. An assessor must hold the relevant qualification for the specific standard being assessed. Confirm an assessor's current qualifications against the PCI SSC's published listings rather than assuming a single QSA credential covers all programs.
How do we confirm that a QSA or QSA company is currently qualified?
Verify the QSA company and, where relevant, the individual assessor against the PCI SSC's published lists of qualified assessors, and confirm the qualification is current and applicable to your region and the standard in scope. Qualification status can change over time, so check at the point of engagement rather than relying on prior verification.
What should we prepare before a QSA begins an assessment?
Define and document your cardholder data environment and its scope, including where cardholder data is stored, processed, or transmitted, and identify connected systems. Have supporting evidence available, such as network diagrams, data-flow diagrams, policies, procedures, configuration records, and evidence of control operation. Because scope drives the assessment, be prepared to justify any scope reduction achieved through segmentation, tokenization, truncation, or other techniques, since their effect on scope depends on implementation and validation rather than the label alone.
Which PCI DSS version and requirements will the QSA assess against?
A QSA assesses against the version of PCI DSS in effect for your assessment. Requirement numbering, wording, and validation expectations differ between versions, so confirm the applicable version and its requirements against the current published standard rather than assuming a fixed requirement number. Discuss with your QSA which version applies given any transition timelines, and confirm details against the PCI SSC's current documentation.
What is the difference between a QSA-led assessment and a self-assessment?
A QSA-led assessment involves an independent qualified assessor evaluating and validating controls, typically resulting in a Report on Compliance where required. A self-assessment is performed by the entity itself using the applicable Self-Assessment Questionnaire. Which validation method applies depends on factors such as the entity's role, transaction channels, and the requirements imposed by acquirers or card brands. Confirm the required validation approach with the relevant acquirer or card brand, as their program rules govern what is accepted and can vary by region.

Common misconceptions

A QSA can certify or assess an organization against any PCI standard.
A PCI DSS QSA qualification applies to PCI DSS assessments. Other PCI SSC programs such as PCI P2PE, PCI 3DS, and the Software Security Framework have their own separate assessor qualifications; being a QSA does not automatically confer these.
Engaging a QSA guarantees an organization is secure or free from breaches.
A QSA assessment is intended to validate compliance against PCI DSS requirements at a point in time and helps demonstrate that controls were in place, but it does not guarantee security or prevent breaches. Compliance status can change between assessments.
A company listed as a QSA means every individual on staff is a qualified assessor.
Company qualification and individual employee qualification are separate. Only individuals who have met the PCI SSC training and requalification requirements are qualified to conduct assessments on the company's behalf.

Best practices

Confirm both the QSA company and the specific individual assessor appear on the PCI SSC's current published lists and hold qualifications relevant to the standard being assessed.
Verify the QSA is qualified for the specific standard you need assessed, and engage a separately qualified assessor when the scope involves other programs such as PCI P2PE, PCI 3DS, or the Software Security Framework.
Ensure the assessment is conducted against the PCI DSS version currently in force, and confirm requirement references in the ROC match that version rather than assuming fixed requirement numbers.
Work with the QSA early to define and validate the cardholder data environment scope, including where PAN and other cardholder data reside and confirmation that sensitive authentication data is not stored after authorization.
Retain the completed Report on Compliance and signed Attestation of Compliance, and treat compliance as a point-in-time result that requires ongoing maintenance between assessments.
Request that the QSA document testing procedures and evidence for each applicable requirement so findings can be independently understood and reviewed.