Buying guide

How to Choose a PCI QSA Company: 11 Questions Before You Sign

What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.

Start with accreditation

Before anything else: confirm the firm is currently listed as a QSA company on the PCI SSC’s assessor listings, and cross-check Visa’s Global Registry of Service Providers, which names the assessor on validated entities. Accreditation renews annually — last year’s status proves nothing about this year.

The 11 questions

  1. Are you currently an accredited QSA company, and will you put it in the engagement letter? Verbal assurance is worthless.
  2. Who exactly is on my assessment team — names and CVs? Not the sales contact. You want the QSAs who will be in your environment.
  3. How many ROCs has that team completed in the last 12 months, in environments like mine? Volume in your vertical matters more than total headcount.
  4. Is the fee fixed, and exactly what breaks it? Scope expansion is the classic fee-breaker — get the boundaries in writing.
  5. How do you scope the cardholder data environment, and what happens if it grows mid-assessment? You want a defined re-scoping process, not a blank check.
  6. What’s included: gap assessment, pen test, ASV scans, remediation support? Bundled vs. unbundled changes the comparison completely.
  7. What’s your fieldwork window, and what happens if our evidence is late? Understand whose delay costs whom.
  8. How do you handle findings — and do you also sell the remediation? A QSA that profits from finding problems has a conflict worth naming. Independence matters.
  9. Can we speak to two reference clients our size, in our industry? Then actually call them and ask about timeline slips.
  10. What does the report review process look like? You should get to correct factual errors before the ROC is signed.
  11. What happens at renewal? Year-two pricing, evidence carryover, and whether the same team returns.

Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.

Request quotes

Red flags

The quote comparison

Get at least three scoped quotes and compare the engagement letters line by line — not just the headline fee. Our RFP and quote worksheet gives you the brief template and a printable comparison sheet.

Keep reading

ROC vs SAQ: Do You Actually Need a QSA On Site?

The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.

PCI DSS Assessment Cost in 2026: What the Fee Actually Covers

Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.

PCI DSS 4.0: What Changed and What It Means for Your Next Assessment

v3.2.1 is retired. Here’s what’s actually different in v4.0.1, which changes bite first-timers hardest, and how to plan the transition.

Questions

Should we pick the cheapest QSA?

Pick the cheapest credible QSA. A bargain assessment that your acquirer questions — or that misses real gaps — is the most expensive option.

Big global firm or boutique?

Complex, multi-entity scope favors the globals; straightforward scope favors boutiques on price and attention. Match the firm to the scope, not the logo.

Turn reading into quotes

Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.

Get a free quote