How this site works

Our methodology

Exactly how we choose QSA companies, what we verify, how we label prices — and what we refuse to do.

Which firms get listed

A firm appears in our directory only if, as of our last check, it meets all three:

What we verify — and what we don’t claim

For each firm we record headquarters, firm type, and the frameworks its own public materials say it supports. Directory facts were last verified in September 2026; we aim to re-check quarterly.

What we don’t verify. We do not audit each firm’s PCI SSC accreditation paperwork ourselves, and we won’t pretend we did — accreditation status changes annually. Check any firm yourself in about five minutes on the PCI SSC’s assessor listings (listings.pcisecuritystandards.org) before signing. If a firm’s status changes, tell us and we’ll update or delist.

How we label every price

QSA fees are scoped per engagement, so firms almost never publish prices. Where we show a planning range, it always carries one of three labels:

LabelMeaning
Firm-publishedThe firm publishes the figure itself (rare for QSA work).
Planning estimate (Sept 2026)Our editorial estimate compiled from published industry fee ranges. Useful for budgeting; not a quote.
Not publishedNo band shown. Request a scoped quote — that’s what our quote form is for.

None of these are quotes. Your fee depends on scope, locations, service providers, readiness, and the QSA’s brand. Treat every band as a planning figure and get scope and fee in writing.

Timelines

Where shown, the “fieldwork window” is the QSA’s assessment phase once evidence is ready — not the full engagement. Scoping, gap work, and remediation add weeks to months. Vendor marketing timelines don’t count.

What we will never do

How we make money

When you request quotes, matched QSA companies may pay us a lead or referral fee. That payment cannot change which firms we list, what our guides say, or which firms we recommend — the firewall is absolute, and firms can’t buy their way around it.

Corrections

Wrong price, stale fact, firm missing? Tell us. We check corrections against the firm’s own public materials and note material fixes on the affected page with a date.

Verification log

This log is append-only: new entries go on top, old entries are never silently rewritten. Row-level: firm name, URL, HTTP status, date checked.

DateWhat was checkedResult
2026-09-24All 17 firm websites listed in the directory (direct load check, browser UA, sequential)16 returned HTTP 200: coalfire.com, schellman.com, a-lign.com, kirkpatrickprice.com, barradvisory.com, vikingcloud.com, securitymetrics.com, controlcase.com, prescientassurance.com, sensiba.com, 360advanced.com, truvantis.com, nccgroup.com, foregenix.com, wolfandco.com. rsisecurity.com returned 307 then 200 on the canonical URL — live. venza.org failed; venzagroup.com redirects to venza.io (HTTP 200) — profile uses venza.io. compliancepoint.com failed to connect and was dropped from the directory.
2026-09-24QSAC cross-checksCoalfire Systems, Inc. and A-LIGN (A-LIGN Compliance and Security, U.S. Inc., dba A-LIGN) named as assessors in Visa’s Global Registry of Service Providers (June 30, 2025). BARR Advisory’s QSA accreditation confirmed via its January 2024 Business Wire announcement. VENZA’s v4 QSA accreditation confirmed via 2025 industry announcement. PCI SSC QSA listings checked as the standing authority.
2026-09-24Pricing-report figuresFee bands labeled as editorial planning estimates (Sept 2026) — QSA firms do not publish fees, so no band is presented as firm-published. Structural facts (levels, v4.0.1 currency, annual ROC cycle) sourced to PCI SSC / Visa / card-brand published criteria.
This methodology describes an independent directory’s research process, not an assessment standard. It doesn’t replace your own diligence: verify accreditation, meet the engagement team, and read the engagement letter before you sign anything.

Browse the directory

17 verified QSA companies, grouped by buyer profile, with every price labeled by source.

Get a free quote