QSA (Qualified Security Assessor)
PCIComplianceHubLast updated
A company qualified by the PCI SSC to perform PCI DSS assessments and produce Reports on Compliance, and the individual employees of such a company who hold the QSA qualification. Both the company and the individual must be qualified, and both are listed on the Council's website.
Applies to. Entities that validate by a Report on Compliance rather than a self-assessment: typically Level 1 merchants and service providers, and any entity whose acquirer or brand requires an assessment.
Example. A Level 1 merchant engages a listed QSA company. A named QSA employee performs the assessment, writes the ROC and signs the Attestation of Compliance alongside the merchant.
Limits. A QSA assesses an entity against PCI DSS. It does not certify a product, a website or a piece of writing, and 'PCI certified' is not a status the Council grants. The QSA qualification is for PCI DSS; other Council programmes have their own assessor types. An Internal Security Assessor can perform an entity's own assessment where the brand permits it. Whether an entity must use a QSA is decided by its acquirer and the brands, not by the Council.