What is a QSA? The Buyer's Guide to PCI Assessment

13 minute read
Intermediate

A QSA is the assessor who validates PCI DSS compliance. What the engagement costs, what findings do to a deal, and who is exposed when it fails.

Who Actually Needs One

PCI DSS is not law. It is a contractual standard imposed through the payment chain. That distinction matters, because it determines who can compel you and what happens when you fall short.

Your obligation generally arrives through your acquiring bank or payment processor, and the level of validation depends on transaction volume. The card brands set the thresholds and they vary slightly between brands, but the shape is consistent:

  • Level 1 merchants, generally those above roughly six million card transactions annually for a given brand, or any merchant that has suffered a breach resulting in card data compromise, require an annual assessment producing a Report on Compliance (ROC). This is where a QSA is typically required.
  • Levels 2 through 4 generally validate through a Self-Assessment Questionnaire (SAQ), of which there are several variants depending on how cards are processed.
  • Service providers have their own level structure and are frequently held to Level 1 requirements by contract regardless of volume, because their enterprise customers demand it.

Two things surprise executives. The first is that a breach can move you to Level 1 regardless of volume. The second is that the most common reason organizations engage a QSA is not the card brands at all. It is a customer. A large enterprise buyer will require a current Attestation of Compliance signed off by a QSA as a condition of the contract, and at that point the requirement is commercial rather than regulatory.

QSA, ISA, SAQ, and PCIP: The Governance Choice

These are usually presented as a glossary. They are better understood as a build-versus-buy decision.

  • QSA: an external assessor. Independent, credible to third parties, and the only route to a ROC for most organizations.
  • ISA (Internal Security Assessor): your own employee, trained and certified by the Council, who can perform internal assessments. Builds durable capability and reduces external cost over time. Requires sustained investment and does not confer the same third-party credibility.
  • SAQ: self-assessment. Cheapest, and appropriate where your level permits it, but signed by your own officer with no independent validation behind it.
  • PCIP (PCI Professional): an individual qualification indicating foundational knowledge. Not an assessment credential.

The governance question is whether PCI scope is a permanent feature of your business. If card processing is core and the scope is large, an ISA program plus a QSA for final validation usually costs less over three years and produces better internal control. If PCI scope is incidental and shrinking, buy the assessment and spend the effort on reducing scope instead.

What It Costs

No incumbent publishes this, which is inconvenient for anyone trying to budget. Ranges vary widely by market and firm, and the honest answer is that cost is driven almost entirely by scope rather than by revenue.

The variables that move the number:

  • Cardholder data environment size. How many systems store, process, or transmit card data, and how well segmented they are from everything else.
  • Number of physical locations. On-site assessment work scales with sites requiring visits.
  • Segmentation quality. A well-segmented environment with a small, clearly bounded cardholder data environment costs a fraction of a flat network where scope creeps across the estate. Segmentation is the single largest lever on assessment cost.
  • Compensating controls. Each one requires a documented worksheet and assessor judgment, which adds time.
  • Year one versus year two. The first engagement includes scoping, gap assessment, and remediation support. Subsequent years, assuming stable scope, cost meaningfully less.

Budget for the full program rather than the assessment line item. The sequence is gap assessment, remediation, fieldwork, then ROC drafting. Remediation is usually the largest cost and it is the one most often omitted from the initial estimate.

Timeline

A first-time Level 1 assessment for an organization starting without mature controls realistically runs nine to fifteen months end to end: scoping and gap assessment, then remediation, then fieldwork, then report production. Organizations that engage a QSA for fieldwork without having done the remediation work generate findings, then remediate under time pressure, then pay for additional assessor time. That sequence is more expensive than doing it in order.

The Conflict of Interest Nobody Writes About

Most QSA companies also sell the things that fix the findings. Managed security services, remediation consulting, tooling, sometimes the very controls the assessment evaluates.

The Council's rules address assessor independence, and reputable firms manage the boundary carefully. But the commercial structure is worth understanding before you sign, because it creates a pricing dynamic that works against you.

When the assessment and the remediation come from the same vendor, the assessment is frequently priced as a loss leader. The margin sits in the remediation that the assessment identifies. That is not necessarily improper, and the findings may be entirely legitimate. It does mean the engagement you thought you were buying (an independent opinion) is partly a sales motion, and you are not well positioned to evaluate whether every finding warranted the recommended fix.

The questions to ask before engaging:

  • Does your firm sell remediation services or security products into organizations you assess?
  • If we engage you for the assessment, are your remediation services quoted separately and competitively?
  • Who owns the working papers, and can we take them to another assessor?
  • Is the fee fixed or time and materials, and what triggers a change order?

A structurally cleaner arrangement, where PCI scope is material, is to separate the parties: one firm assesses, a different firm remediates. It costs more in coordination and it removes the ambiguity entirely.

What Happens If You Fail

The complete absence of this topic across the ranking content is remarkable, given it is the first question a CFO asks.

An assessment does not produce a pass or fail grade in the way an exam does. It produces a report documenting, control by control, whether each requirement is in place, not in place, or satisfied through a compensating control. A ROC with requirements marked not in place is a non-compliant ROC.

What follows depends on the relationship that compelled the assessment:

  • Through your acquirer. The acquiring bank is the entity with the contractual relationship to the card brands, and fines flow through it to you. Acquirers typically work with a remediation plan and timeline before escalating. Sustained non-compliance can result in increased transaction fees, and in severe cases, termination of processing, which for most merchants is an existential outcome.
  • Through a customer contract. A non-compliant ROC may constitute breach of a contractual representation. Review what your MSAs actually promise before assuming this is a technical matter.
  • After a breach. Compliance status at the time of the incident becomes central to liability allocation, card brand assessments, and forensic investigation findings. An organization found non-compliant at the time of a card data breach is in a materially worse position than one that was compliant.

Interim states exist. Organizations frequently operate under a documented remediation plan with acquirer acknowledgement while gaps close. That is a workable position. What is not workable is a lapsed assessment with no plan, which is how a routine compliance matter becomes a board matter.

Can a QSA Be Held Liable?

General Counsel ask this and the ranking content is silent.

Understand what a QSA produces: a report on whether controls were observed to be in place at a point in time, against a defined scope, based on evidence the organization provided. It is closer to an audit opinion than to a warranty. Engagement letters typically contain substantial limitations of liability, and the scope definition, which you supply, constrains the entire exercise.

The practical consequences:

  • An Attestation of Compliance is not a defense against a breach. Organizations have been compliant and breached. Compliance is a point-in-time assessment of a defined scope, and attackers do not confine themselves to your scope.
  • Scope is your responsibility. If cardholder data existed somewhere you did not disclose, the assessment did not cover it, and that is generally not the assessor's exposure.
  • The Council maintains a quality assurance process for assessor firms, including remediation and revocation of qualification. That is a professional standards mechanism, not a compensation route for you.

The person carrying real exposure is usually the officer who signs the Attestation of Compliance. That signature is a representation by your organization, made by a named executive, that the assessment findings are accurate. Whoever signs should understand what they are certifying and should have evidence behind each assertion. Handing the AOC to whoever is available is a governance failure with a name attached to it.

QSA Findings in M&A

For private equity sponsors and corporate acquirers, PCI status in a target is a diligence item that regularly gets treated as a checkbox and regularly should not be.

What to Demand in the Data Room

An Attestation of Compliance alone is close to meaningless without the report behind it. Request:

  • The current Report on Compliance, not just the AOC. The AOC is a summary; the ROC contains the findings.
  • All compensating control worksheets. A compensating control is a legitimate mechanism, but each one signals a requirement the organization could not meet directly. A ROC carrying many of them describes an environment held together by exception.
  • ASV scan records for the past four quarters, showing passing scans.
  • The scope definition and network segmentation documentation. This is where the real risk hides. A narrow scope may reflect excellent segmentation or it may reflect an incomplete data discovery exercise.
  • Any prior non-compliant ROCs and correspondence with the acquiring bank.

Does Compliance Survive the Close?

Not automatically, and the answer depends on structure. A stock purchase where the legal entity, its processing relationships, and its environment continue largely unchanged preserves more than an asset purchase or a carve-out.

The carve-out case deserves particular attention. A division separating from a compliant parent does not inherit the parent's compliance. It inherits a cardholder data environment that was assessed as part of a larger estate, often relying on shared infrastructure, shared security services, and shared controls that the carve-out entity will no longer have. The new entity requires its own scoping, and frequently its own assessment, on a timeline that transition services agreements rarely accommodate.

Material changes to the environment can also require reassessment mid-cycle. Integration is a material change.

How Findings Reach the Deal Terms

PCI findings show up in transactions in several places, and naming them early is cheaper than arguing them late:

  • Representations and warranties regarding compliance with applicable standards and the absence of known breaches.
  • Escrow or holdback sized to the estimated remediation cost where gaps are identified pre-close.
  • Specific indemnities for known non-compliance or a prior card data incident, which sellers resist and which materially change the risk allocation.
  • Purchase price adjustment where remediation cost is quantifiable.
  • Representations and warranties insurance. Underwriters ask about known issues, and a known open finding disclosed in diligence is typically excluded from coverage. Undisclosed, it is a coverage problem later.

The practical point for a deal team: an open, non-compliant ROC is not a reason to walk. It is a priced item. The failure mode is not discovering it, or discovering it late enough that the remediation cost lands on the buyer's P&L in year one of the hold.

How to Select and Manage the QSA

Beyond checking the Council's registry of qualified firms:

  • Ask for assessors with experience in your specific environment. A QSA fluent in cloud-native architecture is not interchangeable with one whose experience is retail point of sale.
  • Meet the assessor, not the salesperson. The individual doing the fieldwork determines the quality of the engagement.
  • Scope the statement of work precisely, including what triggers additional fees.
  • Clarify working paper ownership at the outset. Switching assessors is considerably harder when the prior firm holds everything.
  • Understand that switching assessors repeatedly is visible. Assessor shopping, cycling firms until one produces a favorable finding, is a pattern the Council and sophisticated counterparties can observe. It is also a poor signal in diligence.

Related Reading

Frequently Asked Questions

What does QSA stand for in PCI?

Qualified Security Assessor. The term refers both to a certified individual and, more loosely, to the QSA Company (QSAC) that employs them. Both the firm and the individual assessor are qualified by the PCI Security Standards Council, and qualification must be maintained through annual requalification and continuing training. Note that the acronym is also used for the Quantum Systems Accelerator, the USDA Quality System Assessment program, and several unrelated companies.

Who is required to use a QSA?

Generally Level 1 merchants, those above approximately six million annual card transactions for a given brand, and any merchant moved to Level 1 following a card data breach. Service providers are frequently held to Level 1 validation by contract regardless of volume. In practice, the most common trigger is neither: it is an enterprise customer requiring a QSA-signed Attestation of Compliance as a condition of doing business. Lower-level merchants typically validate through a Self-Assessment Questionnaire.

How much does a PCI QSA assessment cost?

Cost is driven by scope rather than revenue. The main variables are the size of the cardholder data environment, the number of physical locations requiring on-site work, the quality of network segmentation, the number of compensating controls requiring documented worksheets, and whether this is a first assessment or a subsequent one. Segmentation is the largest single lever: a small, well-bounded cardholder data environment costs a fraction of a flat network. Budget the full program, gap assessment through remediation through fieldwork through report, rather than the assessment line alone. Remediation is usually the largest component and the one most often omitted from initial estimates.

What happens if you fail a PCI assessment?

An assessment produces a report marking each requirement in place, not in place, or met through a compensating control, rather than a pass or fail grade. A report containing requirements not in place is a non-compliant ROC. Consequences flow through whichever relationship compelled the assessment: the acquiring bank may impose increased fees and, in severe sustained cases, terminate processing; a customer contract may treat it as breach of a representation; and after a breach, compliance status at the time of the incident becomes central to liability. Operating under a documented remediation plan with acquirer acknowledgement is a workable interim position.

Can a QSA be held liable if we are breached?

A QSA produces an opinion on whether controls were observed in place, within a scope you define, at a point in time, based on evidence you supply. Engagement letters typically limit liability substantially. Because scope definition is the organization's responsibility, cardholder data in undisclosed locations is generally not the assessor's exposure. The Council maintains a quality assurance process for assessor firms including revocation of qualification, but that is a professional standards mechanism rather than a compensation route. The party with meaningful exposure is usually the executive who signs the Attestation of Compliance.

Does PCI compliance transfer in an acquisition?

Not automatically. A stock purchase leaving the entity, its processing relationships, and its environment largely intact preserves more than an asset purchase or carve-out. A division separating from a compliant parent does not inherit that compliance: it inherits an environment that was assessed as part of a larger estate, frequently relying on shared infrastructure and controls it will no longer have. The separated entity typically requires its own scoping and often its own assessment, on a timeline transition services agreements rarely accommodate. Material environment changes, including integration, can also require reassessment mid-cycle.

What is the difference between a QSA and an ISA?

A QSA is an external assessor from a Council-qualified firm, independent of your organization, and for most organizations the only route to a Report on Compliance. An ISA is your own employee, trained and certified by the Council, who can perform internal assessments. The choice is effectively build versus buy: an ISA program builds durable internal capability and reduces external cost where PCI scope is permanent and large, but lacks third-party credibility with customers and acquirers. Many organizations with material scope run both.

Do QSA firms have a conflict of interest?

Frequently, structurally. Most QSA companies also sell remediation consulting, managed services, or security products into organizations they assess. The Council's rules address assessor independence and reputable firms manage the boundary, but the commercial dynamic is real: where assessment and remediation come from the same vendor, the assessment is often priced as a loss leader with margin in the follow-on work. Ask directly whether the firm sells remediation into assessed clients, whether remediation is quoted separately, and who owns the working papers. Where PCI scope is material, separating the assessing firm from the remediating firm removes the ambiguity.

Target 2013: Compliant and Breached

Target Corporation was certified PCI DSS compliant in September 2013. The intrusion that ultimately exposed approximately 40 million payment card records was underway within weeks of that certification.

The detail that matters for anyone relying on an Attestation of Compliance is the entry point. Attackers did not defeat the cardholder data environment directly. They obtained credentials belonging to a third-party HVAC vendor with access to Target's network, and moved laterally from there into systems processing card data.

Both things were true simultaneously: the assessment was valid, and the environment was compromised. The assessment evaluated a defined scope against a defined standard at a point in time. The attackers entered through a vendor relationship that the scope did not meaningfully contemplate and moved through internal network paths that segmentation did not prevent.

Two conclusions follow, and they point in different directions.

For executives treating the AOC as assurance: it is not. A current attestation demonstrates that specified controls were observed in a specified scope. It says nothing about the paths into that scope, and it is not evidence that an intrusion is not already underway.

For deal teams reviewing a target's PCI documentation: the scope definition and the segmentation documentation are more informative than the compliance conclusion. A clean ROC over a narrow scope in a flat network describes an organization that has passed an assessment, not one that has controlled its risk.

6 Million

Annual card transactions above which a merchant is generally classified Level 1 by the major card brands, triggering a requirement for an annual on-site assessment resulting in a Report on Compliance. Below that threshold the obligation is usually self-assessment, which is why most organizations discover they need a QSA not from a regulator but from an acquiring bank or an enterprise customer's procurement team.

How Cloudskope Can Help

Cloudskope advises organizations on PCI scope reduction and assessment readiness, with a deliberate separation between advisory work and the assessment itself. For PE sponsors and corporate acquirers, PCI posture review is a standard component of M&A Cyber Due Diligence: scope validity, compensating control density, segmentation reality, and the remediation cost that belongs in the model rather than in a footnote.

Where the question is whether the assessed environment is currently clean, Cloudskope SARTUS is the instrument: a six-day, fixed-fee engagement that spends three days finding what current controls missed across Microsoft 365, Azure, dark web exposure, and active compromise, and three days fixing it. A Report on Compliance documents control design. It does not tell you whether someone is already inside.