Accreditation and your acquirer relationship
Most e-commerce merchants never think about accreditation — until their acquirer does. The acquirer is the party that decides what validation you owe and whether your evidence counts.
Your acquirer sets the real requirement
Card-brand levels are the floor; your acquirer sets the ceiling. Acquirers routinely require QSA-led ROCs from merchants who technically qualify for SAQs — after breaches, during rapid growth, or in high-risk categories. When they do, the QSA company must be accredited, full stop. Get your requirement in writing.
Acquirers check too
Acquirers verify assessor credentials on ROCs submitted to them. A ROC from a firm whose accreditation has lapsed will be rejected — which is why verifying at engagement time protects you, not just the firm.
The SAQ filer still needs accredited inputs
Filing a SAQ yourself? Your SAQ still leans on accredited third parties: your processor's AoC, your ASV scan vendor's accreditation, your P2PE solution's validated status. Collect every vendor's current attestation annually — their lapsed status becomes your finding.
Questions
We're a small hosted-platform shop — does this apply?
Mostly through your vendors: your platform, processor, and scan vendor must hold their own credentials. Your SAQ is yours to sign, but its foundations are accredited third parties.
Our acquirer asked for a ROC unexpectedly — what now?
Don't panic, but don't delay: engage an accredited QSA company for scoping immediately. A first ROC takes 4–9 months; acquirer deadlines rarely flex.
Get quotes from QSAs that know your industry
Tell us your environment once — we’ll match QSA companies with experience in it. Free, two minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.