PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

How to choose a QSA

A QSA must be an individual certified by PCI SSC working for a listed QSA Company, so start by verifying the company on the PCI SSC website. After that, the differentiators are scoping accuracy, sector experience, how the assessor handles evidence and disagreement, and whether the quote is based on a real scoping conversation rather than a headcount.

Verify first

Confirm the QSA Company appears on the PCI SSC list of Qualified Security Assessors, for the region you operate in.
Confirm the named assessor is a current QSA — individual qualification is renewed annually.
Check whether the same firm is also selling you the controls it will assess, and how it manages that conflict.

Scope the engagement properly

A credible quote follows a scoping call covering payment channels, data flows, system counts, locations and cloud footprint.
Agree the assessment boundary and sampling approach in writing before work starts.
Establish whether you need a validated SAQ and AoC, or a full Report on Compliance.
Confirm who performs penetration testing and ASV scanning, and whether it is inside the price.

Questions that expose a bad fit

How do you handle a requirement we cannot meet as written — compensating control or customised approach, and who writes it?
What evidence will you ask for, and in what format, before the fieldwork starts?
Who is the named assessor, and how much of the work is delegated?
What happens, commercially and practically, if we fail a requirement mid-assessment?

Signals of a good engagement

The assessor pushes back on your scope rather than accepting it unchallenged.
A readiness or gap phase is offered before validation, so surprises surface early.
Findings arrive continuously, not in a report at the end.
The statement of work names deliverables, dates and the re-test position explicitly.

Turn the reading into an answer

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Written by Haumaru Whānau QSAs. PCI DSS content paraphrased from PCI DSS v4.0.1 and PCI SSC published guidance; payment brand programmes are set by the brands and your acquirer. Independent summary; not endorsed by PCI SSC.