Decision guide

Do You Actually Need a QSA? When Self-Assessment Is Enough

A QSA engagement is the most expensive line in PCI -- so it's worth asking precisely when the rules (and your acquirer) actually require one.

When a QSA is mandatory

  • Level 1 merchants (6M+ card transactions/year): annual ROC by a QSA company. No exceptions.
  • Most service providers (gateways, processors, hosts that touch card data): ROC regardless of volume -- your customers' acquirers will demand your AOC.
  • When your acquirer says so. Acquirers can require a QSA-validated SAQ or full ROC at any level. Their letter overrides every rule of thumb on this page.

When self-assessment is enough

Level 2–4 merchants whose acquirer accepts an SAQ can self-assess: complete the right questionnaire, run quarterly ASV scans, submit the AOC. This is the intended path for smaller merchants, and there's no shame in it -- the SAQ types exist precisely so a corner shop doesn't need a Big Four engagement. The catch: you're attesting to your own answers, and a wrong SAQ type or a misunderstood requirement is your liability.

The middle path: QSA-validated SAQ

The option most growing merchants actually take: you do the SAQ work, a QSA reviews it, tests the tricky areas, and co-signs. Typical cost: a few thousand to ~$15K -- a fraction of a ROC -- and it converts your self-attestation into something your acquirer and enterprise prospects trust. Common triggers for this path: SAQ D (the full questionnaire is unforgiving), a new enterprise customer asking questions, or an acquirer that ‘suggests’ independent validation.

What a QSA actually does for you

Beyond the signature: they scope your environment correctly (the highest-value hour in PCI), tell you which requirements actually apply to your SAQ type, pressure-test your evidence before it matters, and translate assessor expectations into an engineering task list. A good QSA also tells you when you're over-scoped -- that conversation alone can pay their fee.

How to engage one well

  1. Confirm the listing. The firm must be a PCI SSC-listed QSA company today -- and ask who your assessment team is, not just the brand.
  2. Fix the scope in the SOW. Locations, systems, applications, service providers, sampling methodology. Vague scopes become change orders.
  3. Nail down re-testing. What triggers re-test fees, at what rate, with what turnaround. Get it in writing before fieldwork.
  4. Separate prepare from validate where it matters: if the same firm finds the gaps and grades the fixes, ask how independence is preserved -- in the engagement letter.

Need a QSA -- or not sure? Describe your situation once; matched assessors tell you which engagement fits. Free · 2 minutes.

Get matched quotes

Questions

Can a QSA firm also fix our gaps?

They can advise, but the firm that designs or implements your controls shouldn't be the one assessing them. Many buyers hire a readiness consultant to prepare and a separate QSA company to validate.

How do we verify a QSA company?

Check the PCI Security Standards Council's public listing of QSA companies, and confirm the named assessment team -- not just the firm brand -- before signing.

Independent directory note. This guide is educational content, not assessment advice. Confirm requirements with your QSA and acquirer.

Related reading

Get quotes from PCI QSA firms

Tell us about your environment once -- matched assessors reply with scoped quotes. Free, 2 minutes.

Get a free quote