Skip to main content

    We value your privacy

    We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Read our Cookie Policy to learn more.

    Skip to main content
    Back to Glossary
    compliance
    2 min read

    QSA

    A Qualified Security Assessor (QSA) is an individual certified by PCI SSC to perform on-site PCI DSS assessments and validate compliance for Level 1 merchants.

    QSAs are certified professionals authorized to assess organizations against PCI DSS requirements.

    QSA requirements: - Employed by a QSA Company (QSAC) - Passed QSA exam - Annual requalification training - Adherence to quality standards

    QSA responsibilities: - Conduct on-site assessments - Review documentation and evidence - Interview personnel - Validate control effectiveness - Issue Report on Compliance (ROC)

    When QSA is required: - Level 1 merchants (6M+ transactions) - Service providers processing/storing cardholder data - Any organization that has experienced a breach

    ISA vs QSA: - ISA (Internal Security Assessor) can assess internally - QSA provides independent third-party validation

    Why It Matters

    For Level 1 merchants processing 6 million+ card transactions annually, a QSA assessment is mandatory—self-assessment is not an option. Choosing the right QSA significantly impacts your PCI compliance journey; experienced QSAs provide practical remediation guidance and help organizations avoid costly overengineering of controls while ensuring genuine security improvements.

    Key Points

    Required for Level 1 PCI DSS assessments
    Must be employed by certified QSAC company
    Issues official Report on Compliance (ROC)
    Annual requalification required
    Validates both design and operating effectiveness

    Applicable Compliance Frameworks

    Related Terms

    Frequently Asked Questions

    Do I need a QSA?

    Level 1 merchants (6M+ transactions annually) typically require QSA assessment. Smaller merchants may use SAQ self-assessment.

    How do I find a QSA?

    PCI SSC maintains a list of approved QSAC companies at their website. Choose based on industry experience and reputation.

    Need Help with QSA?

    Our experts can help you understand and implement the right controls for your organization.