How to Verify a QSA Company's Status (Walkthrough)
The exact five-minute check: PCI SSC listings, Visa registry cross-check, reading the engagement letter, and the red flags that end the conversation.
The authoritative register
Start at the PCI SSC's assessor listings (listings.pcisecuritystandards.org) and search the firm's legal name — not its marketing name, which may differ. Confirm the listing shows current QSA company accreditation. This register is maintained by the Council itself; everything else is secondary evidence.
The cross-check
Open Visa's Global Registry of Service Providers and search for the firm as a named assessor on validated entities. A genuine QSA company leaves a paper trail of real assessments — its name appears on other companies' validations. Absence from the registry doesn't prove fraud (not every assessment lands there), but presence is strong corroboration. We used this same cross-check when building our directory.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesThe engagement letter
Before signing, the letter should state that the firm is a currently accredited QSA company and that qualified QSAs in its employ will perform the assessment. If the firm claims accreditation but won't put that sentence in writing, you have your answer.
Red flags
- Not on the PCI SSC listings. Disqualifying, full stop.
- “PCI certified” applied to the firm. Firms aren't “PCI certified” — they're accredited QSA companies. Sloppy language about their own credential is telling.
- Accreditation via “partner.” Then contract with the accredited entity directly.
- Won't name the assessment team. You're buying people, not a logo.
- Rush pressure before verification. Five minutes is not an unreasonable delay.
Keep reading
What Is a QSA Company? QSAC, QSA, and ISA Explained
The three credentials buyers confuse — what a Qualified Security Assessor Company is, how it differs from an individual QSA, and why only one combination can sign your ROC.
How Firms Become QSA Companies: The Accreditation Process
What the PCI Security Standards Council actually requires before it lets a firm sign ROCs — company vetting, qualified people, exams, and independence.
QSA vs CPA vs ISO Auditor vs ISA: Who Can Do What
Four credentials, four different powers. Which ones can sign a ROC, which can sign a SOC 2, and why “security auditor” on a website means nothing by itself.
Questions
The firm was accredited last year — is that enough?
No. Accreditation renews annually. Verify current status at engagement time.
What if the legal name differs from the brand?
Search both. Acquisitions and rebrands (common in this industry) explain mismatches — but the accredited legal entity must be the one on your contract.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.