Qualified Security Assessors
QSA companies are independent security organizations qualified by the PCI Security Standards Council to validate an entity's adherence to PCI DSS. Individual QSAs work for those companies and must meet the Council's training and qualification requirements. A QSA performs the assessment behind a Report on Compliance and signs the related Attestation of Compliance with the entity. Each needs current qualification.
Many merchants also hire a QSA for readiness work or scoping advice before their formal assessment. Clear separation between the advisory team and the assessment team is good practice, since the same firm shouldn't end up assessing controls it designed. Ask how the firm handles it.
Internal Security Assessors
An Internal Security Assessor is an employee of a sponsor organization approved by the Council who has completed ISA training and qualification. ISAs improve their organization's understanding of PCI DSS and the quality of its internal self-assessments, and they act as a link between the organization and its QSA.
Whether an ISA can sign off a merchant's validation in place of a QSA depends on the payment brand and the acquirer, not the Council. Some brands allow a Level 1 merchant to use an ISA under conditions. Others don't. Confirm with the acquirer before relying on it.
Approved Scanning Vendors
An Approved Scanning Vendor is an organization with a Council-approved scanning solution that runs external vulnerability scans to validate PCI DSS Requirement 11.3.2. Scans run from outside. External scans are required at least once every 3 months, and after significant changes. Since March 31, 2025, they're also expected from e-commerce merchants validating with SAQ A, a change that surprised many small online merchants.
A passing ASV scan has no high-risk vulnerabilities by the program's scoring. The merchant attests to the scope it gives the vendor, so missing an internet-facing system can make a passing scan meaningless.
Other Council-listed roles
The Council keeps several other lists. They cover PCI Forensic Investigators, who investigate suspected card data breaches at the request of brands or acquirers, as well as assessors for point-to-point encryption, PIN security, 3-D Secure, card production, and key management.
Finding and checking an assessor
Each list is published on the Council's website under Assessors and Solutions, with search filters for company name and region. The Council warns that it can't guarantee the lists are current at all times. Check status before you sign. A company that appears on a list in one role isn't automatically qualified for another, since a QSA company is not necessarily an ASV.
Qualification means requirements were met. It is not an endorsement of the company's services or business practices, which buyers still need to judge for themselves before signing. Ask for references from organizations of similar size and payment setup.
Who signs what
Acquirers decide which of these they need from each merchant.
- Report on Compliance: prepared by a QSA, or by an ISA where the brand and acquirer allow it
- Self-Assessment Questionnaire: completed by the entity, often with help from an ISA or consultant
- Attestation of Compliance: signed by the entity, and by the QSA when a QSA was involved
- ASV scan report: issued by the Approved Scanning Vendor
Resources
- PCI Data Security Standard (PCI DSS), PCI Security Standards Council
- Document Library (standard, SAQs, and guidance), PCI Security Standards Council
- Merchant Resources, PCI Security Standards Council
- Qualified Security Assessors list, PCI Security Standards Council
- Approved Scanning Vendors list, PCI Security Standards Council
References
- Qualified Security Assessors, PCI Security Standards Council
- Internal Security Assessors, PCI Security Standards Council
- Approved Scanning Vendors, PCI Security Standards Council
General information, reviewed 2026-10-11. Not legal advice.