Fundamentals
QSA vs ISA vs compliance platform: who can sign your ROC?
Three roles get confused constantly — and vendors benefit from the confusion. Here’s the clean version.
| QSA | ISA | Compliance platform | |
|---|---|---|---|
| Stands for | Qualified Security Assessor | Internal Security Assessor | — |
| Employed by | An accredited QSA company | Your own company | A software vendor |
| Qualified by | PCI Security Standards Council | PCI SSC (employee training) | Nobody — it’s software |
| Can sign a ROC | Yes — the only one who can | No | No |
| Can sign your SAQ | Can guide it (you sign) | Yes, for their employer | No — helps you prepare it |
| Best for | Required assessments | Internal assurance, pre-assessment prep | Evidence collection year-round |
The rule that matters. Only a QSA employed by an accredited QSA company can perform the on-site assessment and sign the Report on Compliance. A platform that implies it can “certify” you is misrepresenting the standard — platforms prepare, QSAs attest.
How they work together
The healthy pattern: a compliance platform (or an ISA on staff) keeps evidence organized year-round, and the QSA’s fieldwork becomes verification instead of archaeology. That’s how renewals get cheaper — not by replacing the QSA, but by making their job boring.
Choosing
- You need a QSA company if you’re Level 1 (or your acquirer requires it) — browse the directory.
- Train an ISA if you want internal assessment capability and stronger pre-assessment prep.
- Buy a platform if evidence collection is eating your team — then bring the QSA a clean package.
Start with the QSA quotes
Platforms and ISAs support the assessment — the QSA signs it. Get competing quotes free.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.