What Is a QSA Company? QSAC, QSA, and ISA Explained
The three credentials buyers confuse — what a Qualified Security Assessor Company is, how it differs from an individual QSA, and why only one combination can sign your ROC.
The company and the person
PCI assessment credentials come in two layers. The QSA company (formally, Qualified Security Assessor Company, QSAC) is the firm accredited by the PCI Security Standards Council. The QSA (Qualified Security Assessor) is the individual the Council has qualified through training, examination, and experience requirements. A valid Report on Compliance needs both layers: a qualified individual, employed by an accredited company.
QSAC vs QSA
| QSAC (company) | QSA (individual) | |
|---|---|---|
| Accredited/qualified by | PCI Security Standards Council | PCI Security Standards Council |
| Renews | Annually (company requalification) | Ongoing training + re-examination |
| Can sign a ROC | Only through its employed QSAs | Only while employed by a QSAC |
| What to verify | PCI SSC assessor listings | Named on your engagement team |
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesWhere the ISA fits
An ISA (Internal Security Assessor) is an individual trained by the Council who works for your company — they can strengthen internal assurance and pre-assessment prep, and in some cases support a SAQ, but they cannot sign a ROC for you. The ISA is your employee; the QSA must be independent of you.
Why the combination matters
A QSA who leaves their accredited firm can't sign ROCs as a freelancer — the qualification only operates inside an accredited company. And an accredited company staffed entirely by trainees isn't delivering what you're paying for. When you buy an assessment, you're buying the combination: accredited firm plus qualified, experienced individuals. Verify both — see the five-minute check.
Keep reading
How Firms Become QSA Companies: The Accreditation Process
What the PCI Security Standards Council actually requires before it lets a firm sign ROCs — company vetting, qualified people, exams, and independence.
How to Verify a QSA Company's Status (Walkthrough)
The exact five-minute check: PCI SSC listings, Visa registry cross-check, reading the engagement letter, and the red flags that end the conversation.
QSA vs CPA vs ISO Auditor vs ISA: Who Can Do What
Four credentials, four different powers. Which ones can sign a ROC, which can sign a SOC 2, and why “security auditor” on a website means nothing by itself.
Questions
Can an individual QSA work independently?
No — a QSA must be employed by an accredited QSA company to perform assessments and sign ROCs. Independent “QSAs” are a red flag.
Is a QSAC the same as a PCI consultant?
No. Any firm can call itself a PCI consultant. QSAC is a specific accreditation from the PCI Security Standards Council — check the listings.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.