Somewhere in your PCI DSS vendor research, you’ve probably assumed a QSA is a QSA, one credential, one standard of rigor, interchangeable between firms. It’s an understandable assumption, and it’s not quite right. PCI SSC recognizes two different tiers of assessor, and knowing which one is actually running your engagement matters more than most companies realize when they’re comparing vendors.
What Is a Qualified Security Assessor (QSA) Company?
A QSA Company is a firm the PCI Security Standards Council has qualified to perform PCI DSS assessments, subject to its own qualification requirements, code of professional responsibility, and annual requalification. Working for a qualified QSA Company is what allows an individual to hold current QSA status in the first place. Every QSA Company is required to have an internal quality assurance process and a documented conflict-of-interest policy, both reviewable by PCI SSC on request, which is part of what separates a credential from a formality.
Two credentials, not two names for the same one
A current, active QSA has passed PCI SSC’s qualification training and requalifies every twelve months. An Associate QSA is a more junior designation, someone who wants to become a QSA but doesn’t yet have the necessary experience, who has started that process but hasn’t completed the full requirements. An Associate QSA can assist with an assessment under a QSA’s direct supervision, gathering and documenting evidence, conducting interviews, following up on remediation, even drafting sections of the report, but signing the AOC or the ROC, and making the final call on compliance, has to stay with a current QSA. Neither document is required to spell out how much of the fieldwork an Associate QSA actually did.
Subcontracting is real, and it’s allowed
PCI SSC also permits a QSA Company to subcontract assessment work to another firm entirely, with its consent. From the outside, a subcontracted assessment can look identical to one performed in-house, same cover page, same signature block. What actually changes is quieter than the paperwork suggests: whether you know who stands behind your AOC, or you’re simply assuming it.
Why this matters more than it seems to
A PCI DSS assessment is only as valuable as the confidence your acquiring bank and your merchant customers place in it. The AOC itself always has to carry a current QSA’s signature, that part isn’t optional, but a report where an Associate QSA quietly did most of the fieldwork under light supervision, or one produced by a subcontracted firm nobody disclosed, is a weaker asset in a vendor risk review than one you can trace to a QSA who was genuinely involved in the work, not just the signature. The strength of the credential behind the work is part of the strength of the report.
What it costs if it’s never checked
Most of the time, none of this surfaces a problem. But if an acquiring bank or a customer’s security team ever questions your AOC, whether the assessment holds up depends on exactly this kind of detail, who signed it, and what standing they actually had to. A report that can’t withstand that kind of scrutiny doesn’t just cost you the questioning, it can mean redoing the assessment altogether, at a real cost well beyond whatever you saved by not asking upfront.
Why PCI SSC Requires an Internal Quality Review
PCI SSC doesn’t just require a QSA Company to produce a report, it requires that report to be checked before it goes out. Every PCI DSS assessment has to go through a quality assurance review completed by separately qualified personnel, someone holding QSA, Associate QSA, or PCI Professional status, distinct from whoever did the original fieldwork. That requirement exists because a self-reviewed assessment has an obvious blind spot: the person most invested in a report looking complete is the same person who produced it. A second set of eyes, formally required rather than optional, is part of what makes a PCI DSS report defensible.
What a Conflict-of-Interest Policy Actually Covers
Every QSA Company is required to maintain a documented conflict-of-interest policy, one that identifies where a conflict, or the appearance of one, could arise for the people conducting an assessment. In practice, that covers things like whether an assessor has a financial interest in a client’s outcome, whether the firm sells remediation products alongside assessment services, and how the firm keeps assessment staff separated from any advisory work happening elsewhere in the business. None of this is unique to any one vendor, PCI SSC requires it of every QSA Company, but how seriously a firm treats the policy in practice varies more than the existence of the policy itself does.
How Long Is a PCI DSS AOC Valid?
An Attestation of Compliance is generally treated as valid for twelve months from the date it’s issued, which is why PCI DSS runs on an annual assessment cycle in the first place. That validity window is also why the credential question matters every single cycle, not just the first time you hire a QSA. A firm’s staffing, subcontracting arrangements, and even its own PCI SSC qualification status can change year over year, so an AOC that checked out cleanly two cycles ago doesn’t guarantee the same rigor produced this year’s version. That’s part of why re-confirming credentials each renewal is worth the few extra minutes it takes, rather than treating last year’s answer as still current.
What Happens If a QSA Company Loses Its Own Qualification?
QSA Companies requalify with PCI SSC annually, the same way individual QSAs do, and it’s possible, though uncommon, for a firm to lose its qualified status. If that happens mid-engagement, any assessment work performed under that qualification becomes a real problem, not a paperwork inconvenience, since the AOC depends on the firm holding valid QSA Company status at the time the work was done. It’s a low-probability scenario, but it’s part of why the credential question isn’t a one-time box to check and forget.
What to ask a vendor
- Is the assessor assigned to my engagement a current, active QSA, or an Associate QSA?
- Will any part of the assessment be subcontracted, and if so, to whom?
- Who signs the AOC, and is that the same person who actually ran the assessment?
None of these are trick questions. A QSA firm that’s comfortable with the distinction will answer plainly, because the structure isn’t something they have to work around, it’s built into how they staff an engagement. A vendor that hesitates, or answers vaguely, is telling you something too, often more clearly than a confident answer would.
Common Questions About QSA Credentials
What does QSA stand for in PCI DSS? QSA stands for Qualified Security Assessor, the PCI SSC-certified individual authorized to conduct PCI DSS assessments on behalf of a qualified QSA Company.
What’s the difference between a QSA and an Associate QSA? A QSA has completed PCI SSC’s full qualification training and exam requirements and requalifies annually. An Associate QSA is someone who wants to become a QSA but doesn’t yet have the necessary experience, who has started that process but hasn’t completed every requirement. An Associate QSA can assist with an assessment under a QSA’s direct supervision, gathering evidence, conducting interviews, and preparing draft sections of the report, but only a current QSA can sign the AOC or ROC.
Can a PCI DSS assessment be subcontracted to another company? Yes, with PCI SSC’s consent. A QSA Company can subcontract assessment work to another qualified firm, though the arrangement isn’t always disclosed to the client unless they ask.
Contact us to talk through who would actually be assigned to your PCI DSS assessment, or learn more about how Insight Assurance staffs every engagement.

