The accreditation lifecycle

How QSA accreditation works

A QSA company (QSAC) is a firm the PCI Security Standards Council has accredited to perform on-site PCI DSS assessments. This is the full lifecycle: what accreditation means, how firms earn it, how they keep it, how they lose it — and how you verify it before you sign.

What accreditation is (and isn't)

QSAC accreditation is the PCI Security Standards Council's license for a company to perform PCI DSS assessments. Separately, individual QSAs (Qualified Security Assessors) are people the Council has qualified — through training, examination, and experience requirements — who must be employed by an accredited QSA company to sign a Report on Compliance. The company accreditation and the individual qualification are two different things, and a valid ROC needs both: a qualified assessor working for an accredited firm.

What accreditation isn't. It isn't a quality rating, a guarantee of assessment rigor, or a permanent status. It's a license that expires every year — and assessment quality varies enormously between accredited firms. See beyond the badge.

How firms earn it

Per the PCI SSC's QSA Program Guide, becoming a QSA company requires, in outline:

The bar is real but not mysterious: the Council wants firms with genuine security expertise, trained and examined people, and the independence to say “not compliant” when it's true. For the full requirements, see the QSA Program Guide v3.0.

How firms keep it

Accreditation renews annually. Each year the firm requalifies: confirming it still meets the program requirements, that its QSAs have completed required training and re-examination, and paying the program fees. Individual QSAs must also maintain their qualification through the Council's continuing requirements. A firm that was accredited last year is not automatically accredited this year — which is why buyers verify at engagement time.

How firms lose it

The Council can suspend or revoke a QSA company's accreditation for program violations — poor assessment quality, misconduct, or failure to meet ongoing requirements. When that happens, the firm's ROCs stop being issued under accreditation, and clients mid-assessment face an ugly choice: finish with a firm whose reports may not be accepted, or restart with an accredited one. It doesn't happen often, but the possibility is exactly why the annual check matters. More: when accreditation lapses.

How buyers verify it

The authoritative source is the PCI SSC's assessor listings (listings.pcisecuritystandards.org) — the Council's own register of currently accredited QSA companies. Cross-check with Visa's Global Registry of Service Providers, which names the assessor on validated entities (useful corroboration: if a firm claims QSA status, its name should appear as an assessor somewhere real). Then get the status stated in the engagement letter. The whole check takes five minutes: the verification walkthrough.

This page summarizes the PCI SSC's QSA program as publicly documented (September 2026). Program requirements change — the QSA Program Guide is authoritative, not this page.

Get quotes from accredited QSA companies

One request reaches matched, accredited QSA companies. Free, two minutes, no obligation.

Get a free quote