How to Choose a PCI QSA Company: 11 Questions Before You Sign
What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.
Start with accreditation
Before anything else: confirm the firm is currently listed as a QSA company on the PCI SSC’s assessor listings, and cross-check Visa’s Global Registry of Service Providers, which names the assessor on validated entities. Accreditation renews annually — last year’s status proves nothing about this year.
The 11 questions
- Are you currently an accredited QSA company, and will you put it in the engagement letter? Verbal assurance is worthless.
- Who exactly is on my assessment team — names and CVs? Not the sales contact. You want the QSAs who will be in your environment.
- How many ROCs has that team completed in the last 12 months, in environments like mine? Volume in your vertical matters more than total headcount.
- Is the fee fixed, and exactly what breaks it? Scope expansion is the classic fee-breaker — get the boundaries in writing.
- How do you scope the cardholder data environment, and what happens if it grows mid-assessment? You want a defined re-scoping process, not a blank check.
- What’s included: gap assessment, pen test, ASV scans, remediation support? Bundled vs. unbundled changes the comparison completely.
- What’s your fieldwork window, and what happens if our evidence is late? Understand whose delay costs whom.
- How do you handle findings — and do you also sell the remediation? A QSA that profits from finding problems has a conflict worth naming. Independence matters.
- Can we speak to two reference clients our size, in our industry? Then actually call them and ask about timeline slips.
- What does the report review process look like? You should get to correct factual errors before the ROC is signed.
- What happens at renewal? Year-two pricing, evidence carryover, and whether the same team returns.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesRed flags
- Guaranteed pass. No honest QSA guarantees an outcome before seeing your environment.
- A ROC in a week. For any non-trivial scope, that’s a signature, not an assessment.
- No named team. “We’ll staff it later” means you’re buying whoever’s free.
- Remediation upsell pressure. Findings should come with guidance, not a sales quota.
- Can’t explain v4.0.1 changes. If they’re fuzzy on the current standard, walk away.
The quote comparison
Get at least three scoped quotes and compare the engagement letters line by line — not just the headline fee. Our RFP and quote worksheet gives you the brief template and a printable comparison sheet.
Keep reading
ROC vs SAQ: Do You Actually Need a QSA On Site?
The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.
PCI DSS Assessment Cost in 2026: What the Fee Actually Covers
Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.
PCI DSS 4.0: What Changed and What It Means for Your Next Assessment
v3.2.1 is retired. Here’s what’s actually different in v4.0.1, which changes bite first-timers hardest, and how to plan the transition.
Questions
Should we pick the cheapest QSA?
Pick the cheapest credible QSA. A bargain assessment that your acquirer questions — or that misses real gaps — is the most expensive option.
Big global firm or boutique?
Complex, multi-entity scope favors the globals; straightforward scope favors boutiques on price and attention. Match the firm to the scope, not the logo.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.