What a QSA does, what a QSA may not assess, and how to verify one
A QSA's qualification is granted per company, per region, per person and per version of the standard. Here is what that covers, what it bars, and how to check it.
A Qualified Security Assessor is a company qualified by the PCI Security Standards Council “to validate an entity’s adherence to PCI DSS requirements”, working through individually qualified staff called QSA Employees. The qualification is narrower than the market usually assumes. It is granted per company, per geographic region, per individual and per version of the standard, and every part of it lapses annually unless renewed.
That structure decides everything that follows: what a QSA can be engaged to do, the short list of things a QSA is barred from assessing, and how you check that the firm quoting you holds the qualification for the work you are actually buying.
What the qualification covers, and what bounds it
| Bound by | The rule |
|---|---|
| The company | PCI SSC adds the qualified company to the QSA List and its qualified staff to the Assessor-Employee search tool. “Only those QSA Companies and Assessor-Employees on the QSA List or in such search tool (as applicable) are recognized by PCI SSC to perform or support PCI DSS Assessments.” |
| Region | Qualification fees are paid per region or country. “Under no circumstances may QSA Companies perform PCI DSS Assessments—or any QSA Services—outside of the qualified region(s) or country(ies).” An entity headquartered in one region with in-scope sites in another needs a firm qualified in both. |
| The individual | A QSA Employee needs at least a year each in application security, information systems security and network security, plus a year each in IT security auditing and information security risk assessment or management — and at least one certification from an information-security list (CISSP, CISM, accredited ISO 27001 Lead Implementer) and one from an audit list (CISA, GSNA, accredited ISO 27001 Lead or Internal Auditor, IRCA ISMS Auditor, CIA). |
| Version | “QSA Employees are only authorized to perform PCI DSS Assessments using versions of the PCI DSS for which they have successfully completed training.” |
| The year | The company requalifies regionally every year; each assessor requalifies annually on proof of two current certifications, completed training and fees. Negative feedback from clients, PCI SSC or the payment brands may affect eligibility. |
Subcontracting is the bound most often missed. Engaging anyone who is not a direct employee to perform any part of the work “requires prior written consent by PCI SSC in each instance” — and that holds even where the subcontractor is itself a QSA Company. Approved subcontractors may not put another company’s logo or name into the Report on Compliance or the attestation documents.
What a QSA produces
PCI DSS v4.0.1 sets out the assessment in six steps: confirm scope, perform the assessment, complete the applicable report, complete the Attestation of Compliance in full, submit it to whoever asked for it, and remediate and re-report anything not in place. Requirements “are not considered to be in place if controls are not yet implemented or are scheduled to be completed at a future date”, and the assessor reassesses after remediation rather than taking a plan on trust.
The output is a Report on Compliance on the current ROC Template with an AOC attached, signed by a duly authorised officer of the QSA Company as well as by the assessed entity. Where an entity validates by self-assessment instead, a QSA is optional and the form records exactly what they did: SAQ D Part 3c asks whether the “QSA performed testing procedures” or “QSA provided other assistance”, and if the latter, to “describe all role(s) performed”. Part 3d asks the same of an Internal Security Assessor. Which artefact you owe, and who signs which block, is covered in what “PCI DSS certification” actually means.
What a QSA may not assess
- Anything it has a stake in. A QSA Company “will not undertake to perform any PCI SSC Assessment of any entity that it controls, is controlled by, is under common control with, or in which it holds any investment.” That is a flat bar with no disclosure route out of it.
- A customised control it helped build. Appendix D of v4.0.1 is explicit: “if a QSA is involved in designing or implementing a customized control, that QSA does not also derive testing procedures for, assess, or assist with the assessment of that customized control.”
- Its own products — undeclared. Outside the customised approach the rule is disclosure rather than prohibition. “The QSA Company must fully disclose in the Report on Compliance if it assesses any customer that uses any security-related device or security-related application developed or manufactured by the QSA Company, or to which the QSA Company owns the rights, or that the QSA Company has configured or manages” — the named categories run from firewalls and IDS/IPS through encryption, audit-log and file-integrity solutions to vulnerability scanning services. Backing it up are a conflict-of-interest policy, documented separation of duties, and a disclosure form each assessor signs at hire and annually.
- A sample your team picked. “The assessor must select the sample from the complete population without influence from the assessed entity.” Sampling applies to populations, never to the standard: “it is not acceptable for an assessor to review only a sample of PCI DSS requirements for compliance.”
- Your scope, on your behalf. Requirement 12.5.2 makes annual scope confirmation the entity’s job, and the standard adds that it “is not the same, nor is it intended to be replaced by, the scoping confirmation performed by the entity’s assessor during the assessment”. Two exercises, both required.
So the familiar line that a QSA “cannot assess anything it implemented” is right in spirit and wrong in detail. For a customised control it is a prohibition; for everything else PCI SSC requires the relationship to be disclosed in the ROC and managed by documented separation of duties. The useful procurement question is therefore not whether a relationship exists, but whether it will appear in the report.
What a QSA is not required for
Requirements 11.4.2, 11.4.3 and 11.4.5 each call for a qualified internal resource or qualified external third party with organisational independence, and each carries the same parenthesis: “(not required to be a QSA or ASV)”. Requirement 11.3.2 runs the other way — the quarterly external vulnerability scan must be “By a PCI SSC Approved Scanning Vendor (ASV)”, and it is the one requirement in Requirement 11 for which “this requirement is not eligible for the customized approach”. Buying penetration testing from your assessor is a choice; buying the quarterly external scan from anyone but an ASV is not an option. What an ASV does covers that side.
How to verify one
| Check | What good looks like |
|---|---|
| The company is listed | It appears on the QSA List on the PCI SSC website. A certificate image, a logo on a slide, or a partner’s qualification is not the record. |
| Listed for your region | The listing names the region or country your in-scope sites are in — all of them. |
| Standing on the listing | The listing carries status, not just presence: good standing, remediation or revocation. Under the QSA Program Guide v3.0, a company in Remediation has its listing “updated to ‘red’ to notify merchants/service providers”, returning to “In Good Standing” in black text on completion. Firms in remediation may keep assessing unless PCI SSC says otherwise, and PCI SSC directs outside queries about status back to the firm — so ask the firm. |
| The named individual | The Lead QSA who will sign appears in the Assessor-Employee search tool and has completed training on the version you are being assessed against. |
| Associate involvement | The firm “must inform the applicable Customer when an Associate QSA Employee has been assigned” and say which parts they will work on. One of PCI SSC’s own audit criteria is evidence that “the Lead QSA—and not just the Associate QSA Employee—went on-site”. |
| Subcontracting | Anyone on the engagement who is not their employee has PCI SSC’s written consent, obtained per instance. |
| Conflict disclosure | Ask which products in your environment they sell, own rights to, configure or manage — and confirm those will be disclosed in the ROC. |
Two closing details worth knowing. A qualified firm may advertise its listing “only during such times as QSA actually appears in such QSA List”, so a claim outliving the listing is itself a breach. And every assessment comes with a QSA Feedback Form that you, your acquirer or a payment brand may submit to PCI SSC.
Three things a QSA cannot say
- “We will issue your PCI DSS certificate.” There is no certificate to issue. Validation is a ROC or an SAQ, plus an AOC.
- “We guarantee a compliant ROC.” QSA Companies and their staff “must not enter into any contract with a Customer that guarantees a compliant ROC”.
- “PCI DSS requires our product.” A QSA must not misrepresent any requirement of the standard or “state or imply that the PCI DSS or any other PCI SSC Standard requires usage of the QSA Company’s products or services”, and where it recommends its own product as remediation it must also recommend other market options.
Listings change without notice — PCI SSC reserves the right to remove a company or an assessor immediately for any unmet requirement, payment included. Check the list when you appoint, and check it again at renewal against the individual who will sign.
About the author
Chintan J
CISO & Director — Security Advisory
Oversees Security Brigade's cybersecurity advisory practice, helping regulated enterprises meet RBI, SEBI, CERT-In, and IRDAI compliance mandates. Previously held senior security leadership roles across BFSI.
Continue reading
All articles →What is and is not PCI DSS: SSF, P2PE, 3DS, PIN — and where PA-DSS went
PCI DSS assesses your organisation. SSF, P2PE, PTS, 3DS and PIN Security assess products and other parties. Where PA-DSS went, and what a listing changes.
Which PCI SSC document says what, and which PCI DSS version it is written against
PCI DSS v4.0.1 is the only active version: v4.0 retired 31 December 2024, v3.2.1 on 31 March 2024. Which PCI SSC document answers which question, and what version each carries.
PCI DSS renewal is a re-scope, not a repeat
Nothing renews on the anniversary. Requirement 12.5.2 asks the entity to re-confirm scope every twelve months, and a test scoped to last year's CDE is the first mismatch an assessor sees.