PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

ISA — Internal Security Assessor

An Internal Security Assessor (ISA) is an employee of an organisation who has completed the PCI SSC Internal Security Assessor programme and can perform internal PCI DSS assessments for their own employer.

What it means in practice

ISAs improve internal readiness and can complete self-assessments, but their standing with acquirers varies and does not automatically replace a QSA-signed report.
The ISA qualification requires annual requalification training.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.