Industry guide

Accreditation and your acquirer relationship

Most e-commerce merchants never think about accreditation — until their acquirer does. The acquirer is the party that decides what validation you owe and whether your evidence counts.

Your acquirer sets the real requirement

Card-brand levels are the floor; your acquirer sets the ceiling. Acquirers routinely require QSA-led ROCs from merchants who technically qualify for SAQs — after breaches, during rapid growth, or in high-risk categories. When they do, the QSA company must be accredited, full stop. Get your requirement in writing.

Acquirers check too

Acquirers verify assessor credentials on ROCs submitted to them. A ROC from a firm whose accreditation has lapsed will be rejected — which is why verifying at engagement time protects you, not just the firm.

The SAQ filer still needs accredited inputs

Filing a SAQ yourself? Your SAQ still leans on accredited third parties: your processor's AoC, your ASV scan vendor's accreditation, your P2PE solution's validated status. Collect every vendor's current attestation annually — their lapsed status becomes your finding.

Questions

We're a small hosted-platform shop — does this apply?

Mostly through your vendors: your platform, processor, and scan vendor must hold their own credentials. Your SAQ is yours to sign, but its foundations are accredited third parties.

Our acquirer asked for a ROC unexpectedly — what now?

Don't panic, but don't delay: engage an accredited QSA company for scoping immediately. A first ROC takes 4–9 months; acquirer deadlines rarely flex.

Get quotes from QSAs that know your industry

Tell us your environment once — we’ll match QSA companies with experience in it. Free, two minutes.

Get a free quote

← All QSA companies  ·  Cost guide