Skip to content

Qualified Security Assessor (QSA)

Definition

An individual certified by the PCI Security Standards Council to perform on-site PCI-DSS assessments for merchants and service providers that cannot self-certify. QSAs are employed by PCI SSC-approved QSA companies and produce a Report on Compliance (RoC).

Certifying body
PCI Security Standards Council
Scope
On-site PCI-DSS assessments
Employer type
PCI SSC-approved QSA companies
Deliverable
Report on Compliance (RoC)

Common questions

Why can't every merchant self-certify PCI-DSS compliance instead of hiring a QSA?+

PCI-DSS requires merchants and service providers above certain transaction volume thresholds, or those that have suffered a prior breach, to undergo independent on-site assessment by a QSA rather than complete a self-assessment questionnaire, since the higher risk profile calls for external verification.

What role does a QSA's Report on Compliance play in a payment card fraud investigation?+

An RoC documents the assessed entity's security controls at the time of the audit, so investigators can compare it against the environment at the time of a breach to identify whether a previously certified control had failed or had already lapsed.

Related terms

Addressable Implementation Specification
A HIPAA Security Rule specification that organisations must assess for reasonableness and appropriateness. If reasonable and appropriate, it must be implemented; if...
Business Associate
A person or entity that performs services for a HIPAA covered entity that involve creating, receiving, maintaining, or transmitting protected health information...
Cardholder Data Environment (CDE)
The people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data. PCI-DSS requirements apply to the CDE...
Covered Entity
Under HIPAA, a healthcare provider that transmits health information electronically, a health plan, or a healthcare clearinghouse. Covered entities are directly subject...
Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium. PHI includes...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.