Regulation & Assurance

PCI DSS: QSA Review vs Self-Assessment

Understand PCI DSS self-assessment and QSA involvement, compare SAQ, ROC and AOC evidence, and check the scope behind a vendor’s compliance statement.

Two assessment folios and separate document sleeves sit beside a payment terminal and inspection lens.
In this article 6 sections
ShareLinkedInWhatsAppEmail

What supports a PCI DSS compliance claim?

A PCI DSS compliance statement needs supporting documents and a defined scope. Document type, assessment responsibility and independent assessor involvement are separate questions; they cannot be reduced to a simple certified-or-not comparison.

Self-Assessment Questionnaire vs. Qualified Security Assessor review

An eligible organisation can complete the applicable Self-Assessment Questionnaire (SAQ), with or without assistance from a QSA. The organisation remains responsible for accurate responses and eligibility. Its payment brand, acquirer or other compliance-accepting entity determines the required validation route. PCI SSC FAQ 1215: SAQ eligibility

A Qualified Security Assessor (QSA) is qualified through the PCI Security Standards Council programme and works for a qualified QSA company. Where a Report on Compliance is required, the assessment records testing and findings. QSA assistance can also be used with an SAQ; the document type and the assessor’s involvement are separate questions.

The required validation path depends on applicable payment-brand or acquirer requirements and the organisation’s eligibility. It is not determined by a buyer’s risk appetite alone. Ask the entity accepting the compliance submission which assessment and documentation are required.

What to ask before you accept the claim

Ask which assessment path supports the compliance claim: the applicable SAQ or Report on Compliance, and who performed or assisted with the assessment.

Request the appropriate Attestation of Compliance (AOC), alongside a clear description of the assessed services. Confirm which assessment it accompanies and whether the relevant service, legal entity and assessment period match your purchase.

Ask what is in scope. PCI DSS compliance can be scoped narrowly to a specific system or environment; a vendor can be genuinely compliant for the systems in scope while other parts of their environment are outside it entirely.

Match the evidence to the service you rely on

When the claim is about your own organisation, you control the scope and the evidence. When it is about a partner or vendor handling card data on your behalf, you are relying on their attestation being both accurate and current — which is exactly why asking the assessment-path question up front is worth the friction it creates in a vendor conversation.

Read the four terms without confusing them

Use this comparison during procurement. An assessor credential is not a certificate for every service delivered by the assessor’s client.

  • SAQ: a validation questionnaire for an eligible environment. Ask which SAQ was used and why its eligibility conditions fit the actual payment architecture. Outsourcing payment processing does not by itself establish eligibility for a particular SAQ.
  • ROC: a Report on Compliance documenting an assessment. Request the appropriate shareable evidence and identify the entity accepting it. Do not demand an entire restricted report where an AOC and a scoped clarification will answer the buying decision.
  • AOC: the attestation associated with the applicable assessment. Match the entity, services and assessment date to your contract. A dated attestation is evidence about its stated scope, not an assurance that every subsequent change has been assessed.
  • QSA: a qualified assessor working through a qualified assessor company. Check current qualification in the PCI SSC directory where relevant. QSA participation does not remove the assessed organisation’s responsibility for ongoing compliance.
  • Record the customer/provider responsibility split: logging, access control, vulnerability handling and incident communication may be divided. Ask who performs each task and what evidence you receive, rather than assuming the provider handles everything.

A useful procurement decision identifies what the evidence covers, what it excludes and which unresolved question affects the proposed integration. If the architecture or service has changed since assessment, ask how that change was evaluated. Resolve the required validation path with the compliance-accepting entity before purchasing an assessment.

Sources and further guidance

Regulatory applicability depends on the organisation and the provisions in force. Check the linked primary sources before acting.

Related reading and capabilities

Frequently asked questions

Can a QSA help with an SAQ?

Yes. Assistance and the required reporting route are separate matters. Confirm the organisation’s eligibility and required documentation first, then agree what help or independent assessment is appropriate.

Does an AOC cover every product sold by a vendor?

No. Read the assessed entity and service scope. Request clarification when your contracted service or deployment model is not clearly included; do not extend the claim using the vendor’s brand name alone.

Who decides whether an SAQ is acceptable?

The compliance-accepting entity, such as a payment brand or acquirer, determines validation requirements. PCI SSC publishes the standards and tools; a buyer’s preference alone does not establish eligibility.