How Firms Become QSA Companies: The Accreditation Process
What the PCI Security Standards Council actually requires before it lets a firm sign ROCs — company vetting, qualified people, exams, and independence.
Why the bar exists
A ROC is a trust instrument: acquirers, card brands, and enterprise customers accept it as proof. That trust only works if the firms issuing ROCs are vetted — which is why the PCI Security Standards Council runs the QSA program as an accreditation regime, not a membership club. Here's what it takes, in outline (the QSA Program Guide v3.0 is authoritative).
The company requirements
The firm applies to the Council and demonstrates it is a legitimate, structured business capable of delivering independent assessments — proper organization, professional conduct commitments, and the operational maturity to perform assessments to the Council's standards. New entrants are scrutinized; the Council has an interest in keeping the assessor pool credible.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesThe people requirements
A QSA company is only as accredited as its people. Individuals must meet experience prerequisites, complete the Council's PCI DSS training, and pass the QSA examination. The firm must maintain a bench of qualified QSAs — accreditation isn't granted to a company with no qualified assessors on staff.
Independence
The assessment practice must be capable of independent judgment. The Council's program guards against conflicts where the firm auditing the controls also profits from the outcome in ways that compromise objectivity — one reason buyers should ask how a firm separates assessment from remediation sales.
Then every year again
Accreditation renews annually: the firm requalifies, its QSAs complete continuing training and re-examination, and program fees are paid. Firms that can't maintain the bench or the standards don't get renewed — which is why verifying current status matters more than a firm's history.
Keep reading
What Is a QSA Company? QSAC, QSA, and ISA Explained
The three credentials buyers confuse — what a Qualified Security Assessor Company is, how it differs from an individual QSA, and why only one combination can sign your ROC.
How to Verify a QSA Company's Status (Walkthrough)
The exact five-minute check: PCI SSC listings, Visa registry cross-check, reading the engagement letter, and the red flags that end the conversation.
QSA vs CPA vs ISO Auditor vs ISA: Who Can Do What
Four credentials, four different powers. Which ones can sign a ROC, which can sign a SOC 2, and why “security auditor” on a website means nothing by itself.
Questions
How long does accreditation take?
The Council doesn't publish a fixed timeline; expect a multi-month process of application, vetting, and qualifying people. Firms typically build the practice first, then accredit.
Can a firm lose accreditation after earning it?
Yes — suspension or revocation for program violations, quality failures, or unmet ongoing requirements. See when accreditation lapses.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.