Fundamentals

What Is a QSA Company? QSAC, QSA, and ISA Explained

The three credentials buyers confuse — what a Qualified Security Assessor Company is, how it differs from an individual QSA, and why only one combination can sign your ROC.

The company and the person

PCI assessment credentials come in two layers. The QSA company (formally, Qualified Security Assessor Company, QSAC) is the firm accredited by the PCI Security Standards Council. The QSA (Qualified Security Assessor) is the individual the Council has qualified through training, examination, and experience requirements. A valid Report on Compliance needs both layers: a qualified individual, employed by an accredited company.

QSAC vs QSA

QSAC (company)QSA (individual)
Accredited/qualified byPCI Security Standards CouncilPCI Security Standards Council
RenewsAnnually (company requalification)Ongoing training + re-examination
Can sign a ROCOnly through its employed QSAsOnly while employed by a QSAC
What to verifyPCI SSC assessor listingsNamed on your engagement team

Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.

Request quotes

Where the ISA fits

An ISA (Internal Security Assessor) is an individual trained by the Council who works for your company — they can strengthen internal assurance and pre-assessment prep, and in some cases support a SAQ, but they cannot sign a ROC for you. The ISA is your employee; the QSA must be independent of you.

Why the combination matters

A QSA who leaves their accredited firm can't sign ROCs as a freelancer — the qualification only operates inside an accredited company. And an accredited company staffed entirely by trainees isn't delivering what you're paying for. When you buy an assessment, you're buying the combination: accredited firm plus qualified, experienced individuals. Verify both — see the five-minute check.

Keep reading

How Firms Become QSA Companies: The Accreditation Process

What the PCI Security Standards Council actually requires before it lets a firm sign ROCs — company vetting, qualified people, exams, and independence.

How to Verify a QSA Company's Status (Walkthrough)

The exact five-minute check: PCI SSC listings, Visa registry cross-check, reading the engagement letter, and the red flags that end the conversation.

QSA vs CPA vs ISO Auditor vs ISA: Who Can Do What

Four credentials, four different powers. Which ones can sign a ROC, which can sign a SOC 2, and why “security auditor” on a website means nothing by itself.

Questions

Can an individual QSA work independently?

No — a QSA must be employed by an accredited QSA company to perform assessments and sign ROCs. Independent “QSAs” are a red flag.

Is a QSAC the same as a PCI consultant?

No. Any firm can call itself a PCI consultant. QSAC is a specific accreditation from the PCI Security Standards Council — check the listings.

Turn reading into quotes

Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.

Get a free quote