Every PCI DSS QSA buyer’s guide reads roughly the same way. Confirm credentials. Check capacity. Ask about turnaround. Make sure they’re qualified for your merchant level. It’s a good checklist. It’s also missing something: nobody tells you how to evaluate a QSA for what happens after this year’s report.
That gap makes sense once you notice when this research actually happens. Most companies build their QSA shortlist the first time they need one, comparing vendors on the same handful of criteria, because that’s the moment that feels urgent. The relationship that follows, years of annual reassessments, quarterly ASV scans, the occasional scramble when transaction volume crosses a threshold, gets evaluated later, if at all, usually by whoever inherits the vendor relationship.
What Is a QSA in PCI DSS?
A Qualified Security Assessor, or QSA, is an individual certified by the PCI Security Standards Council to perform PCI DSS assessments on behalf of a qualified QSA Company. Only merchants and service providers required to submit a full Report on Compliance need a QSA; companies eligible for a Self-Assessment Questionnaire can complete one without a QSA, though many still bring one in, sometimes just for guidance, sometimes because their acquirer, card brand, or payment provider requires the SAQ to be signed by a QSA. Becoming a QSA requires PCI SSC training, a passing exam score, and requalification every twelve months, which is part of why the credential is worth confirming rather than assuming.
What the standard checklist gets right
Credentials, capacity, and turnaround aren’t checkbox items, they’re real, and worth taking seriously. PCI SSC recognizes two tiers of QSA credential, a current, active QSA and a more junior Associate QSA, who can assist with the work under a QSA’s direct supervision but can’t independently sign off on the report. Whether your assessor is one or the other, and whether any of the work gets subcontracted, is worth confirming before you sign, not after. None of that should get skipped.
What it leaves out
Here’s what rarely makes the RFP: what happens when your scope changes. If your transaction volume grows enough to cross the Level 1 threshold, or you add a new payment channel, your PCI DSS requirements can change with it, sometimes shifting you from a self-assessment to a full Report on Compliance. An assessor who’s never seen your environment before has more to learn on that rescoping than one who already has context.
What Changes When You Cross the Level 1 Threshold?
PCI DSS requirements scale with transaction volume. A merchant storing, processing, or transmitting fewer than six million transactions a year can typically complete a Self-Assessment Questionnaire on its own. Cross that threshold, and card brands generally require a full Report on Compliance completed by a QSA instead, along with more rigorous, ongoing documentation. That shift doesn’t happen on a predictable calendar. It happens whenever volume crosses the line, which means the assessor who fits well for an SAQ engagement may not be the right choice once a full ROC is what’s required.
SAQ or ROC: Why the Distinction Matters for Who You Hire
Not every company needs the same kind of assessment. Merchants and service providers below the highest volume thresholds can typically complete a Self-Assessment Questionnaire, a shorter, self-administered process across several SAQ types depending on how payment data is handled. Level 1 merchants and high-volume service providers need a full Report on Compliance instead, which does require a QSA. The distinction matters when you’re evaluating a vendor, because a firm that’s built its practice around SAQ support isn’t automatically equipped for a full ROC engagement, and the reverse is also true. Confirming which service you actually need, and whether the vendor you’re evaluating specializes in it, is worth doing before you’re comparing proposals, not after.
Why it’s easy to let this slide
You don’t need anything to have gone wrong with your current QSA for this to matter, which is a fair chunk of why it rarely gets revisited: a QSA who’s worked with you for a few cycles knows your environment well, and familiarity feels like a point in their favor. It can also mean a fresh perspective is exactly what would catch something a familiar one has stopped looking for, a control that’s drifted, a scope boundary that no longer matches your actual environment. Neither instinct is wrong on its own. The point is to check on purpose instead of assuming.
This is also where the three-role structure pays off in a way that’s easy to underestimate. A quality reviewer who has seen your environment across multiple cycles isn’t just checking a new assessor’s work, they’re comparing it against a documented history of your own control environment, which makes drift easier to spot than it would be for someone encountering your CDE for the first time.
Three questions worth adding to your evaluation
- Is the person scoping your CDE this cycle a current, active QSA, or an Associate QSA?
- Is any part of the assessment being subcontracted to another firm?
- If our transaction volume or payment channels change, how do you handle rescoping mid-relationship?
There’s no “correct” answer here to grade a vendor against, though it’s worth knowing that even when an Associate QSA helps gather and document what defines your CDE, the final scope determination still has to trace back to a current QSA, that responsibility doesn’t transfer. What these three questions get at is something the standard checklist doesn’t: whether you’re evaluating a vendor for this year’s report, or a relationship for the renewals attached to it. A vendor’s answers, more than their marketing materials, tend to reveal how they actually think about the work.
You don’t need a complaint about your current QSA to think this through, most companies never do, simply because the moment to ask these questions rarely comes back around on its own. That’s the real difference between a QSA buyer’s guide and a QSA buyer’s guide that’s actually finished. The first gets you to a signed statement of work. The second still holds up the first time your volume grows, the fourth quarterly scan in, and the renewal nobody put on the calendar six months out.
Common Questions About Choosing a PCI DSS QSA
What is a PCI DSS assessment? A PCI DSS assessment is an independent review of whether a company’s payment environment meets the Payment Card Industry Data Security Standard, resulting in either a Report on Compliance for larger merchants and service providers, or a Self-Assessment Questionnaire for smaller ones.
How do you become a PCI DSS QSA? An individual becomes a QSA by working for a PCI SSC-qualified QSA Company, completing PCI SSC’s official training, passing the qualification exam, and requalifying annually to stay listed.
Do you need a QSA if you only complete a Self-Assessment Questionnaire? Not necessarily. SAQs don’t require a QSA, though many companies still bring one in, sometimes for guidance, and sometimes because their acquirer, card brand, or payment provider requires the SAQ to be signed by a QSA, particularly as their environment or transaction volume grows toward the point where a full assessment becomes required.
How long does a PCI DSS assessment typically take? Timelines vary by scope and service. A Report on Compliance generally runs a few months from kickoff to final report, factoring in scoping, evidence collection, interviews, and the additional review a ROC goes through before it’s issued. A Self-Assessment Questionnaire moves considerably faster, often completed in days to a few weeks depending on which SAQ type applies.
Contact us to schedule your PCI DSS assessment or learn more about how Insight Assurance can help you build a QSA relationship that holds up for the renewals that follow.

