Do You Actually Need a QSA? When Self-Assessment Is Enough
A QSA engagement is the most expensive line in PCI -- so it's worth asking precisely when the rules (and your acquirer) actually require one.
When a QSA is mandatory
- Level 1 merchants (6M+ card transactions/year): annual ROC by a QSA company. No exceptions.
- Most service providers (gateways, processors, hosts that touch card data): ROC regardless of volume -- your customers' acquirers will demand your AOC.
- When your acquirer says so. Acquirers can require a QSA-validated SAQ or full ROC at any level. Their letter overrides every rule of thumb on this page.
When self-assessment is enough
Level 2–4 merchants whose acquirer accepts an SAQ can self-assess: complete the right questionnaire, run quarterly ASV scans, submit the AOC. This is the intended path for smaller merchants, and there's no shame in it -- the SAQ types exist precisely so a corner shop doesn't need a Big Four engagement. The catch: you're attesting to your own answers, and a wrong SAQ type or a misunderstood requirement is your liability.
The middle path: QSA-validated SAQ
The option most growing merchants actually take: you do the SAQ work, a QSA reviews it, tests the tricky areas, and co-signs. Typical cost: a few thousand to ~$15K -- a fraction of a ROC -- and it converts your self-attestation into something your acquirer and enterprise prospects trust. Common triggers for this path: SAQ D (the full questionnaire is unforgiving), a new enterprise customer asking questions, or an acquirer that ‘suggests’ independent validation.
What a QSA actually does for you
Beyond the signature: they scope your environment correctly (the highest-value hour in PCI), tell you which requirements actually apply to your SAQ type, pressure-test your evidence before it matters, and translate assessor expectations into an engineering task list. A good QSA also tells you when you're over-scoped -- that conversation alone can pay their fee.
How to engage one well
- Confirm the listing. The firm must be a PCI SSC-listed QSA company today -- and ask who your assessment team is, not just the brand.
- Fix the scope in the SOW. Locations, systems, applications, service providers, sampling methodology. Vague scopes become change orders.
- Nail down re-testing. What triggers re-test fees, at what rate, with what turnaround. Get it in writing before fieldwork.
- Separate prepare from validate where it matters: if the same firm finds the gaps and grades the fixes, ask how independence is preserved -- in the engagement letter.
Need a QSA -- or not sure? Describe your situation once; matched assessors tell you which engagement fits. Free · 2 minutes.
Get matched quotesQuestions
Can a QSA firm also fix our gaps?
They can advise, but the firm that designs or implements your controls shouldn't be the one assessing them. Many buyers hire a readiness consultant to prepare and a separate QSA company to validate.
How do we verify a QSA company?
Check the PCI Security Standards Council's public listing of QSA companies, and confirm the named assessment team -- not just the firm brand -- before signing.
Related reading
Get quotes from PCI QSA firms
Tell us about your environment once -- matched assessors reply with scoped quotes. Free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.