How QSA accreditation works
A QSA company (QSAC) is a firm the PCI Security Standards Council has accredited to perform on-site PCI DSS assessments. This is the full lifecycle: what accreditation means, how firms earn it, how they keep it, how they lose it — and how you verify it before you sign.
What accreditation is (and isn't)
QSAC accreditation is the PCI Security Standards Council's license for a company to perform PCI DSS assessments. Separately, individual QSAs (Qualified Security Assessors) are people the Council has qualified — through training, examination, and experience requirements — who must be employed by an accredited QSA company to sign a Report on Compliance. The company accreditation and the individual qualification are two different things, and a valid ROC needs both: a qualified assessor working for an accredited firm.
How firms earn it
Per the PCI SSC's QSA Program Guide, becoming a QSA company requires, in outline:
- Company application and vetting. The firm applies to the Council, demonstrating it is a legitimate business with the structure to deliver assessments independently.
- Qualified people. The firm must employ individuals who meet the QSA requirements — information-security experience, PCI DSS training through the Council, and passing the QSA examination.
- Independence. The assessment practice must be able to render independent judgments — the firm can't have conflicts that compromise objectivity.
- Ongoing obligations from day one. Accredited firms commit to the Council's quality and conduct requirements, including how assessments are performed and documented.
The bar is real but not mysterious: the Council wants firms with genuine security expertise, trained and examined people, and the independence to say “not compliant” when it's true. For the full requirements, see the QSA Program Guide v3.0.
How firms keep it
Accreditation renews annually. Each year the firm requalifies: confirming it still meets the program requirements, that its QSAs have completed required training and re-examination, and paying the program fees. Individual QSAs must also maintain their qualification through the Council's continuing requirements. A firm that was accredited last year is not automatically accredited this year — which is why buyers verify at engagement time.
How firms lose it
The Council can suspend or revoke a QSA company's accreditation for program violations — poor assessment quality, misconduct, or failure to meet ongoing requirements. When that happens, the firm's ROCs stop being issued under accreditation, and clients mid-assessment face an ugly choice: finish with a firm whose reports may not be accepted, or restart with an accredited one. It doesn't happen often, but the possibility is exactly why the annual check matters. More: when accreditation lapses.
How buyers verify it
The authoritative source is the PCI SSC's assessor listings (listings.pcisecuritystandards.org) — the Council's own register of currently accredited QSA companies. Cross-check with Visa's Global Registry of Service Providers, which names the assessor on validated entities (useful corroboration: if a firm claims QSA status, its name should appear as an assessor somewhere real). Then get the status stated in the engagement letter. The whole check takes five minutes: the verification walkthrough.
Get quotes from accredited QSA companies
One request reaches matched, accredited QSA companies. Free, two minutes, no obligation.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.