Independent PCI QSA company directory

Find the right PCI assessor. Know the real cost.

We’ve profiled 17 accredited PCI QSA companies — their assessment fees, their timelines, who to avoid. Tell us about your environment and we’ll match you with the best-fit firms, then make them compete for your business with side-by-side quotes. Free. Two minutes. Signing with the first assessor who calls you is how companies overpay.

Free · 2 minutes · No obligation

ROCReport on Compliance — signed by a QSA, valid 1 year
2–12 wkTypical QSA fieldwork window
QSA onlyOnly accredited QSA companies can sign a ROC
$30k–$100k+Planning estimate: Level 1 ROC assessment fee

How quote matching works

  1. Tell us once — 4 questions, 2 minutes, free.
  2. We match you — accredited QSA companies filtered to your size, scope, and timeline.
  3. QSAs quote you — they send scoped quotes directly; you pick.
QSA company directory

Accredited PCI assessment firms

Every firm below is a real, operating QSA company with a website we load-verified in September 2026. We are an independent directory — listings are not endorsements, and we encourage you to confirm each firm’s current QSA status on the PCI SSC listings before engaging.

QSA company

Coalfire Systems

Coalfire is one of the largest QSA companies operating in North America. It is the named assessor on Amazon and AWS PCI DSS validations in Visa's Glob…

Westminster, Colorado · QSA company (QSAC)
QSA company

SecurityMetrics

SecurityMetrics is a PCI-focused QSA company whose published materials emphasize practical, deadline-driven assessments with strong communication. Its…

Orem, Utah · QSA company (QSAC)
QSA company

KirkpatrickPrice

KirkpatrickPrice is an assurance firm with PCI DSS, SOC, ISO, HIPAA, and HITRUST practices. Its published materials emphasize a concierge-style client…

Brentwood, Tennessee · QSA company (QSAC)
QSA company

BARR Advisory

BARR Advisory announced its accreditation as a PCI QSA company by the PCI Security Standards Council in January 2024 (Business Wire), adding PCI DSS t…

Kansas City, Missouri · QSA company (QSAC)

See all 17 firms →

Compare by buyer

The right QSA depends on your size and scope

A 30-person SaaS startup and a multinational retailer should not hire the same assessor. We’ve grouped the directory by buyer profile, with planning-range pricing for each.

Startups & first-timers

First PCI assessment, small cardholder data environment, price-sensitive. Boutique QSAs with low planning ranges and fast fieldwork.

Growth-stage teams

Scaling transaction volume, multi-framework needs. Credible ROCs for bigger customers and acquirers.

Enterprise buyers

Complex, multi-entity, or multi-region scope — or an acquirer that expects a globally recognized QSA name.

Start here

PCI DSS, explained honestly

PCI DSS Cost Guide

What a Level 1 ROC really costs, what drives the fee, and an interactive estimator.

PCI Assessment Timeline

Every phase from scoping to signed ROC — and the annual cycle after it.

PCI Readiness Check

A 2-minute scored quiz: are you ready for a QSA, or do you need gap work first?

2026 Pricing Report

Every cost figure we publish, with its source and date. No invented averages.

ROC vs SAQ

Do you actually need a QSA on-site, or is a self-assessment enough?

Choosing a QSA Company

Eleven questions to ask before you sign an engagement letter.

Best QSA Companies by Use Case

Buyer-matched picks: startups, SaaS scaleups, hospitality, enterprise.

RFP & Quote Comparison

What to put in your brief, a printable comparison worksheet, and engagement-letter red flags.

Our Methodology

How we vet QSA companies, label every price, and keep rankings unbought.

Common questions

PCI DSS basics

What is a PCI DSS assessment?

A PCI DSS assessment is the formal validation that your systems meet the Payment Card Industry Data Security Standard. For Level 1 merchants and Level 1–2 service providers it means an on-site assessment by a Qualified Security Assessor (QSA) employed by an accredited QSA company, producing a Report on Compliance (ROC). Smaller merchants typically validate with a Self-Assessment Questionnaire (SAQ) instead.

How much does a PCI DSS assessment cost?

Planning estimates (September 2026): a Level 1 ROC assessment typically runs $30,000 to $100,000+ in QSA fees depending on scope, with first-year all-in costs of $75,000 to $250,000+ once readiness, pen testing, remediation, and staff time are included. Guided SAQ engagements run $5,000–$25,000. See our cost guide and the 2026 pricing report for every figure with its source.

How long does a PCI DSS assessment take?

The QSA's fieldwork typically runs 2 to 12 weeks depending on size and complexity, but the full journey — scoping, gap assessment, remediation, then the ROC — usually takes 4 to 9 months for a first assessment. The ROC is valid for one year. See the timeline.

Who can perform a PCI DSS assessment?

Only a Qualified Security Assessor (QSA) — an individual employed by an accredited QSA company and qualified by the PCI Security Standards Council — can perform an on-site PCI DSS assessment and sign a ROC. Compliance platforms can prepare you, but they cannot sign the report. Verify any firm on the PCI SSC's assessor listings before engaging.

All frequently asked questions →

Get quotes from accredited QSA companies

Tell us about your environment and timeline once. We’ll match you with QSA companies that fit — no obligation, no spam.

Get a free quote