Fundamentals

QSA vs CPA vs ISO Auditor vs ISA: Who Can Do What

Four credentials, four different powers. Which ones can sign a ROC, which can sign a SOC 2, and why “security auditor” on a website means nothing by itself.

The signing powers

Can sign PCI ROCCan sign SOC 2Can certify ISO 27001
QSA (at a QSAC)YesNoNo
CPA (licensed firm)NoYesNo
ISO 27001 auditor (accredited CB)NoNoYes
ISA (your employee)NoNoNo

QSA

Qualified by the PCI Security Standards Council, employed by an accredited QSA company. The only credential that can sign a PCI Report on Compliance. Verify on the PCI SSC listings.

CPA

A licensed CPA firm signs SOC 1 and SOC 2 reports under AICPA standards. Many firms are both a CPA firm and a QSA company (Schellman, Sensiba, and others in our directory) — which is what makes combined PCI + SOC 2 assessments possible. But a CPA license alone authorizes zero PCI ROCs.

Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.

Request quotes

ISO 27001 auditor

Works for an accredited certification body (a different accreditation system entirely — national accreditation bodies, not the PCI SSC). Certifies ISO 27001; cannot sign a PCI ROC. “Auditor” is doing a lot of ambiguous work on vendor websites — always ask auditor of what, accredited by whom.

ISA

Internal Security Assessor: Council-trained, but your employee. Strengthens internal assurance; cannot independently attest anything about you.

The combos that matter

For buyers running multi-framework programs, the valuable combination is a firm holding both QSAC accreditation and a CPA practice — one evidence set, two reports (see combined assessments). The credential to be suspicious of is none at all: “security auditor” with no named accreditation behind it.

Keep reading

What Is a QSA Company? QSAC, QSA, and ISA Explained

The three credentials buyers confuse — what a Qualified Security Assessor Company is, how it differs from an individual QSA, and why only one combination can sign your ROC.

How Firms Become QSA Companies: The Accreditation Process

What the PCI Security Standards Council actually requires before it lets a firm sign ROCs — company vetting, qualified people, exams, and independence.

How to Verify a QSA Company's Status (Walkthrough)

The exact five-minute check: PCI SSC listings, Visa registry cross-check, reading the engagement letter, and the red flags that end the conversation.

Questions

We're hiring for PCI and SOC 2 — one firm or two?

One firm holding both credentials is usually cheaper and less disruptive: a single evidence request list mapped to both frameworks.

Does a QSA need to be a CPA?

No. QSA qualification runs through the PCI SSC, not through accountancy licensure. Some assessors hold both; it's not required.

Turn reading into quotes

Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.

Get a free quote