Do You Need a QSA? How to Choose the Right Assessor for Your Firm
If your business stores, processes, or transmits cardholder data, you have almost certainly come across the term QSA. But whether you actually need to hire one, and how to pick a good one if you do, is not always clear. This guide breaks down what a Qualified Security Assessor does, when your organization is required to use one, and what to look for when you start evaluating firms.
What Is a QSA?
A QSA is an individual certified by the PCI Security Standards Council to assess compliance with the PCI DSS. QSAs work for QSA companies, which are also independently certified by the Council. To earn and keep the credential, a QSA has to complete initial training, pass an exam, and requalify every year, so the certification reflects an active, current understanding of the standard rather than a one time achievement.
A QSA's job is to evaluate your environment against the requirements of PCI DSS, document their findings, and, where applicable, produce a formal Report on Compliance. They are independent of your organization, which is the whole point. A QSA has no stake in whether you pass or fail, only in whether the assessment accurately reflects your security posture.
It is worth distinguishing a QSA from other roles you may encounter in the compliance space. A QSA is specifically authorized to assess against PCI DSS. Other certifications, such as those for SOC 2 auditors or general security consultants, cover different frameworks and carry different credentialing requirements. If your organization needs to demonstrate PCI compliance formally, the assessment has to come from someone holding the QSA credential specifically, not simply someone with a general security background.
QSA vs. Internal Security Assessor
Larger organizations sometimes have the option of using an Internal Security Assessor, or ISA, instead of an outside QSA for certain assessments. An ISA is an employee who has gone through PCI SSC training and certification to perform assessments internally. This path can reduce costs and keep institutional knowledge in-house, but it is only available to organizations that meet specific eligibility criteria set by their acquirer and card brands, and it is not accepted for every type of assessment.
Even organizations with a qualified ISA program often bring in an outside QSA periodically for an independent check, since an internal assessor, however well trained, is still reviewing their own employer's environment. Not all acquirers accept an ISA-led Report on Compliance, even when an organization is otherwise eligible for the program, so it is worth asking your acquiring bank directly whether it is accepted for your merchant level before you invest in the training.
Do You Actually Need a QSA?
Not every merchant is required to use a QSA. Whether you need one depends primarily on your merchant level, which is determined by your card brand based on annual transaction volume.
-
Level 1 merchants, generally those processing more than six million transactions a year, are required to complete an annual Report on Compliance performed by a QSA (or in some cases an internal assessor with equivalent qualifications).
-
Level 2, 3, and 4 merchants are typically permitted to complete a Self-Assessment Questionnaire instead, though this varies by acquiring bank and card brand.
-
Some acquirers or partners require a QSA-led assessment regardless of level, particularly after a breach or if your environment is considered higher risk.
The six million transaction threshold is accurate for Visa and Mastercard, but exact merchant level definitions vary by card brand, and your acquirer has the final say on which level applies to you. Confirm your specific level and reporting requirements directly with your acquiring bank rather than assuming based on transaction volume alone.
Even when a QSA is not strictly required, many organizations choose to bring one in anyway. A self-assessment asks you to grade your own homework, and it is easy to misjudge scope, miss a requirement, or interpret a control more generously than an outside party would. A QSA brings a level of scrutiny and experience that is hard to replicate internally, especially for a first-time assessment.
What a QSA Actually Does
A QSA engagement typically starts with scoping, determining exactly which systems, networks, and processes touch cardholder data and therefore fall under PCI DSS. Scoping mistakes are one of the most common and costly errors in PCI compliance, since underscoping leaves real risk unassessed and overscoping wastes time and budget on systems that do not need it. A QSA can also point out practical ways to reduce your PCI DSS scope before the assessment even begins, which can shrink both the timeline and the cost.
From there, the QSA reviews evidence against each applicable requirement: policies, configurations, network diagrams, interviews with staff, and often hands-on testing. They will flag gaps, work with your team on remediation where needed, and ultimately issue the Report on Compliance or an Attestation of Compliance once the environment meets the standard.
A good QSA does more than check boxes. They should be able to explain why a requirement exists, help you think through compensating controls when a literal requirement does not fit your architecture, and give you a realistic picture of how much work remediation will take before you commit to a timeline with your acquirer.
How to Choose the Right QSA
Not all QSA companies operate the same way, and the right fit depends on your industry, your environment, and how your team likes to work. A few things are worth evaluating closely before you sign an engagement letter.
Relevant industry experience
A QSA who has assessed dozens of e-commerce platforms will ask sharper questions about your environment than one whose background is mostly point-of-sale retail. Ask prospective firms about their experience with businesses similar in size, industry, and technical architecture to yours.
Clear, Collaborative Methodology
Ask how the assessment is structured, how long it typically takes, and what is expected from your team at each stage. A QSA who cannot walk you through their process clearly at the sales stage is unlikely to be much clearer once the engagement starts.
Transparent Pricing
PCI assessments can vary widely in cost depending on scope, environment complexity, and the QSA firm's approach. Get a detailed scope of work and pricing structure in writing before you commit, including what happens if remediation takes longer than expected.
Support Beyond the Report
The best QSAs treat the assessment as part of an ongoing relationship rather than a once-a-year transaction. Ask whether they offer guidance between assessments, help with scoping changes when your environment evolves, or support if you experience a security incident.
References and Reputation
Ask for references from clients in a similar position to yours, and do not be shy about asking pointed questions: Did the assessment stay on schedule? Was the QSA responsive? Did anything come up during the assessment that felt like a surprise it shouldn't have been?
Tools and Reporting Quality
Some QSA firms rely on modern platforms for evidence collection and tracking remediation items, which can make the process considerably less painful for your team than a folder full of spreadsheets and email threads. Ask to see a sample of what the final report and supporting documentation actually look like. A clear, well-organized Report on Compliance is easier to hand to your acquirer and easier to reference the following year when scoping the next assessment.
How Long Does a QSA Assessment Take?
Timelines vary considerably based on the size and complexity of your environment, how prepared your documentation is going in, and how many gaps turn up along the way. A straightforward environment with good documentation and few findings might move from kickoff to final report in six to eight weeks. A more complex environment, or one going through its first assessment with significant remediation needed, can take several months.
A QSA who gives you a firm timeline before understanding your environment is not doing you any favors. Be wary of anyone quoting a fixed number of weeks before scoping is complete, since that number is only as good as the assumptions behind it.
Red Flags to Watch For
-
A QSA who promises a fast pass without understanding your environment first.
-
Vague or shifting pricing once the engagement is underway.
-
Limited availability for questions or support outside the formal assessment window.
-
An unwillingness to explain the reasoning behind a finding or a compensating control decision.
PCI compliance is not a one-time event. Your environment changes, the standard itself evolves, and the QSA you choose should be someone you are comfortable working with year after year, not just for a single report.
Getting Started
If you are approaching your first QSA engagement, start by gathering basic information about your environment: where cardholder data lives, which systems touch it, and what your current network diagram looks like, even a rough one. Having this ready before your first conversation with a prospective QSA will make scoping faster and give you a more accurate sense of cost and timeline from the start.
Choosing a QSA is ultimately about finding a partner who understands your business well enough to give you a fair, accurate assessment, and who communicates clearly enough that PCI compliance stops feeling like a once-a-year fire drill and starts feeling like a manageable, ongoing part of how you operate.
Compass IT Compliance's team of experienced QSAs helps organizations scope their environment accurately, prepare for assessment, and maintain PCI DSS compliance year over year. If you are weighing whether you need a QSA or evaluating firms to work with, feel free to reach out to us to talk through your specific environment and requirements.
Contact Us
Share this
You May Also Like
These Related Stories
.jpg)
When to Hire a PCI Compliance Consultant (and What They Actually Do)
%20Under%20PCI%20DSS.jpg)
How to Define Your Cardholder Data Environment (CDE) Under PCI DSS

.webp?width=2169&height=526&name=Compass%20white%20blue%20transparent%202%20website%20(1).webp)
-1.webp?width=2169&height=620&name=Compass%20regular%20transparent%20website%20smaller%20(1)-1.webp)
No Comments Yet
Let us know what you think