QSA vs CPA vs ISO Auditor vs ISA: Who Can Do What
Four credentials, four different powers. Which ones can sign a ROC, which can sign a SOC 2, and why “security auditor” on a website means nothing by itself.
The signing powers
| Can sign PCI ROC | Can sign SOC 2 | Can certify ISO 27001 | |
|---|---|---|---|
| QSA (at a QSAC) | Yes | No | No |
| CPA (licensed firm) | No | Yes | No |
| ISO 27001 auditor (accredited CB) | No | No | Yes |
| ISA (your employee) | No | No | No |
QSA
Qualified by the PCI Security Standards Council, employed by an accredited QSA company. The only credential that can sign a PCI Report on Compliance. Verify on the PCI SSC listings.
CPA
A licensed CPA firm signs SOC 1 and SOC 2 reports under AICPA standards. Many firms are both a CPA firm and a QSA company (Schellman, Sensiba, and others in our directory) — which is what makes combined PCI + SOC 2 assessments possible. But a CPA license alone authorizes zero PCI ROCs.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesISO 27001 auditor
Works for an accredited certification body (a different accreditation system entirely — national accreditation bodies, not the PCI SSC). Certifies ISO 27001; cannot sign a PCI ROC. “Auditor” is doing a lot of ambiguous work on vendor websites — always ask auditor of what, accredited by whom.
ISA
Internal Security Assessor: Council-trained, but your employee. Strengthens internal assurance; cannot independently attest anything about you.
The combos that matter
For buyers running multi-framework programs, the valuable combination is a firm holding both QSAC accreditation and a CPA practice — one evidence set, two reports (see combined assessments). The credential to be suspicious of is none at all: “security auditor” with no named accreditation behind it.
Keep reading
What Is a QSA Company? QSAC, QSA, and ISA Explained
The three credentials buyers confuse — what a Qualified Security Assessor Company is, how it differs from an individual QSA, and why only one combination can sign your ROC.
How Firms Become QSA Companies: The Accreditation Process
What the PCI Security Standards Council actually requires before it lets a firm sign ROCs — company vetting, qualified people, exams, and independence.
How to Verify a QSA Company's Status (Walkthrough)
The exact five-minute check: PCI SSC listings, Visa registry cross-check, reading the engagement letter, and the red flags that end the conversation.
Questions
We're hiring for PCI and SOC 2 — one firm or two?
One firm holding both credentials is usually cheaper and less disruptive: a single evidence request list mapped to both frameworks.
Does a QSA need to be a CPA?
No. QSA qualification runs through the PCI SSC, not through accountancy licensure. Some assessors hold both; it's not required.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.