home / frameworks / pci-dss / roles-qsa-isa-asv

// PCI DSS hub

PCI roles: QSA, ISA, and ASV

What Qualified Security Assessors, Internal Security Assessors, and Approved Scanning Vendors do, and how to check them on the PCI SSC site.

Qualified Security Assessors

QSA companies are independent security organizations qualified by the PCI Security Standards Council to validate an entity's adherence to PCI DSS. Individual QSAs work for those companies and must meet the Council's training and qualification requirements. A QSA performs the assessment behind a Report on Compliance and signs the related Attestation of Compliance with the entity. Each needs current qualification.

Many merchants also hire a QSA for readiness work or scoping advice before their formal assessment. Clear separation between the advisory team and the assessment team is good practice, since the same firm shouldn't end up assessing controls it designed. Ask how the firm handles it.

Internal Security Assessors

An Internal Security Assessor is an employee of a sponsor organization approved by the Council who has completed ISA training and qualification. ISAs improve their organization's understanding of PCI DSS and the quality of its internal self-assessments, and they act as a link between the organization and its QSA.

Whether an ISA can sign off a merchant's validation in place of a QSA depends on the payment brand and the acquirer, not the Council. Some brands allow a Level 1 merchant to use an ISA under conditions. Others don't. Confirm with the acquirer before relying on it.

Approved Scanning Vendors

An Approved Scanning Vendor is an organization with a Council-approved scanning solution that runs external vulnerability scans to validate PCI DSS Requirement 11.3.2. Scans run from outside. External scans are required at least once every 3 months, and after significant changes. Since March 31, 2025, they're also expected from e-commerce merchants validating with SAQ A, a change that surprised many small online merchants.

A passing ASV scan has no high-risk vulnerabilities by the program's scoring. The merchant attests to the scope it gives the vendor, so missing an internet-facing system can make a passing scan meaningless.

Other Council-listed roles

The Council keeps several other lists. They cover PCI Forensic Investigators, who investigate suspected card data breaches at the request of brands or acquirers, as well as assessors for point-to-point encryption, PIN security, 3-D Secure, card production, and key management.

Finding and checking an assessor

Each list is published on the Council's website under Assessors and Solutions, with search filters for company name and region. The Council warns that it can't guarantee the lists are current at all times. Check status before you sign. A company that appears on a list in one role isn't automatically qualified for another, since a QSA company is not necessarily an ASV.

Qualification means requirements were met. It is not an endorsement of the company's services or business practices, which buyers still need to judge for themselves before signing. Ask for references from organizations of similar size and payment setup.

Who signs what

Acquirers decide which of these they need from each merchant.

  • Report on Compliance: prepared by a QSA, or by an ISA where the brand and acquirer allow it
  • Self-Assessment Questionnaire: completed by the entity, often with help from an ISA or consultant
  • Attestation of Compliance: signed by the entity, and by the QSA when a QSA was involved
  • ASV scan report: issued by the Approved Scanning Vendor

Resources

All PCI DSS resources

References

  1. Qualified Security Assessors, PCI Security Standards Council
  2. Internal Security Assessors, PCI Security Standards Council
  3. Approved Scanning Vendors, PCI Security Standards Council