Do You Need a QSA, or Can You Self-Assess for PCI DSS?
Most merchants can self-assess, and the entity that decides is not the one selling you an assessment. The PCI Security Standards Council publishes self-assessment questionnaires precisely so that eligible merchants and service providers can validate their own compliance, and it directs the question of who must validate, and how, to a different address entirely: "Whether a small merchant is required to validate compliance is determined by the individual payment brands. For questions regarding compliance validation and reporting requirements, merchants should contact their acquirer (merchant bank) or payment brand they do business with, as applicable." A Qualified Security Assessor is, in the Council's words, one of the "independent security organizations that have been qualified by the PCI Security Standards Council to validate an entity's adherence to PCI DSS." Whether you need one is a question with a definite answer, and the answer is sitting in your acquirer's inbox.
Top Floor is not a QSA firm. We cannot sign your Report on Compliance, and saying so up front is the point of this article: the part of PCI worth paying a consultancy for is not the assessment, it is whether the assessment you do owe turns out to be short or long.
Key takeaways
- Most merchants can self-assess, and the entity that decides is your acquirer or the payment brand, not the Council and not a consultant.
- Get the answer in writing. Acquirers can escalate a merchant's requirements after a breach or for their own risk reasons, and a merchant selling through more than one acquirer can face different expectations on each.
- A QSA's independence is the product. A firm that would both remediate your gaps and assess the result has a conflict worth asking about.
- Self-assessment is not a lesser form of compliance, but it fails in three situations: nobody can evidence the answers, the scope is contested, or a customer contract requires an independently validated report.
- Money spent on scope reduction returns more than money spent on assessment. What you segment out, you do not have to assess, harden, scan or explain.
Get the answer, do not infer it
Here is the email, and it takes five minutes.
Tell your acquirer three things: how you accept card payments, roughly what your annual card transaction volume looks like, and whether you handle card data on behalf of any other entity. Then ask two questions. Which merchant level are we, and which validation type do you require from us, a self-assessment questionnaire or a Report on Compliance? Ask for the answer in writing.
We are deliberately not printing transaction thresholds here. The payment brands set merchant levels independently, the thresholds are brand-specific, and Visa's own guidance says only that "A merchant's total Visa transaction volume over a 12-month period determines your merchant level and the necessary requirements for validation." A number copied from a blog into a compliance plan is a liability, because the only threshold that binds you is the one your acquirer applies. Two other facts make the written answer worth having: acquirers can escalate a merchant's requirements after a breach or for their own risk reasons, and a merchant that sells through more than one acquirer can face different expectations on each relationship.
Service providers are a separate track, with their own validation requirements and, for some provider types, registration with the brands. If your product handles or can affect the security of card data on someone else's behalf, start with merchant or service provider, because that classification changes the answer before level does.
What a QSA does, and what an ISA is
A QSA company is qualified by the Council to validate adherence to PCI DSS. In an assessment they examine evidence, interview people, observe processes, and produce a Report on Compliance together with an attestation. Their independence is the product: the value of the report to your customers and your acquirer comes from the fact that the person signing it does not work for you.
The Council also runs an Internal Security Assessor program, which trains and qualifies an organization's own employees to perform assessment work internally. Companies large enough to carry PCI as a permanent function often build an ISA capability, because it makes the annual cycle cheaper and the internal conversations faster. It is a real option, and it is worth knowing it exists before you assume the only two choices are self-assessment and hiring a QSA.
One thing follows for anyone shopping for help. A firm that would both remediate your gaps and assess the result has a conflict, and it is one the assessment community takes seriously. Ask any provider offering both which staff do which, and how the independence is maintained. An honest answer to that question is a good signal on its own.
When self-assessment is genuinely fine, and when it is not
Self-assessment is not a lesser form of compliance. The questionnaire asks about the same requirements, and the attestation you sign is a real assertion. What differs is who checks the work.
Self-assessment works well when your environment is small and stable, your card data flows are few and well understood, and you have someone internally who can honestly answer questions about controls rather than about intentions. It works badly in three situations we see repeatedly.
When nobody can evidence the answers. Filling in a questionnaire optimistically produces a signed record that is worse than no record. If you cannot show the log retention, the access reviews, or the change approvals, the honest response is to fix that before signing, not to sign and hope.
When the scope is contested. If reasonable people in your company disagree about what is in the cardholder data environment, the questionnaire will be answered against the wrong boundary, and every answer inherits the error.
When the assessment is a customer's condition. If an enterprise customer or a partner requires an independently validated report, self-assessment does not satisfy it regardless of your level. That is a commercial requirement, not a regulatory one, and it is decided in a contract rather than by the brands.
What is worth paying for when you can self-assess
This is the part where we describe our own product, so read it with that in mind.
Money spent on scope reduction returns more than money spent on assessment. The Council defines segmentation as isolating "system components that store, process, or transmit cardholder data from systems that do not," and its definition of the cardholder data environment reaches components with unrestricted connectivity to those systems. Both sentences are levers: what you segment out, you do not have to assess, harden, scan or explain. Getting that architecture right before an assessment is the single highest-return PCI activity available, whoever performs the assessment.
After that, in order: an accurate data-flow map, closing the gaps that would otherwise become findings, and assembling the evidence so the questionnaire takes days instead of months. Where you also owe external scanning, our ASV scanning article covers who needs it and how the quarterly cycle works, and where you owe penetration testing, that is the separate 11.4.x family.
What is not worth paying for: someone to fill in the questionnaire for you while your controls stay where they are. You will pay again next year for the same document.
The honest caveat
If you run a fully outsourced card-not-present checkout, hold no card data anywhere, and your acquirer has told you which questionnaire to file, you do not need a consultancy and you do not need a QSA. Read the eligibility section of the current questionnaire, answer it honestly, fix anything the exercise surfaces, and file it. That advice costs us work and it is the right advice for a meaningful share of the companies that call us.
Call someone when the scope is genuinely contested, when card data has spread into systems that were never meant to hold it, when you have become a service provider without planning to, or when an assessment is booked and you would rather find the gaps yourself than pay an assessor to find them for you.
Where Top Floor fits
Under our PCI DSS practice we do readiness: scoping and segmentation, gap remediation, evidence, and support through the questionnaire or through a QSA-led assessment run by someone else. We are not a QSA and we will not pretend otherwise; if you need a Report on Compliance we will help you prepare for it and, where useful, help you choose between assessors. Where PCI is one of several frameworks in play, Compliance as a Service covers the program, and where the gap is security leadership rather than a single assessment, that is vCISO work. For how a consultancy differs from a platform in this space, our platform versus consultant article makes the argument in both directions.
How to decide this week
Send the acquirer email. Two questions, written answer, five minutes. Everything else in your PCI plan depends on it, and most companies we meet have never sent it.
While you wait, draw the card data flow, including phone, support and finance paths, and mark what could be segmented out. That drawing determines the size of whatever assessment you end up owing.
Then check whether any customer contract independently requires an independently validated report. If one does, the brands' rules stopped being the binding constraint and the contract is what you are planning against.
Frequently asked questions
Do we have to hire a QSA for PCI DSS?
Usually not. The PCI Security Standards Council publishes self-assessment questionnaires so that eligible merchants and service providers can validate their own compliance, and it directs questions about validation and reporting requirements to your acquirer or payment brand rather than answering them itself. The requirement to have an independent assessor produce a Report on Compliance attaches to certain merchant levels and provider types, set by the payment brands, so the reliable route is to ask your acquirer which validation type they require and keep the answer in writing.
What does a QSA actually do?
A Qualified Security Assessor company is an independent security organization qualified by the PCI Security Standards Council to validate an entity's adherence to PCI DSS. In an assessment, a QSA examines evidence, interviews staff, observes processes, and produces a Report on Compliance and an attestation. The independence is the product: the report carries weight with acquirers and enterprise customers because the person signing it does not work for you. The Council also runs an Internal Security Assessor program that qualifies an organization's own employees to perform assessment work internally.
Is a self-assessment questionnaire less valid than a QSA assessment?
No. The questionnaire covers the same requirements and the attestation you sign is a real assertion about your controls. The difference is who verifies the answers. Self-assessment stops being appropriate when nobody in the company can evidence the answers, when the scope of the cardholder data environment is genuinely contested, or when a customer contract requires an independently validated report, which is a commercial requirement rather than a payment brand one.
If we can self-assess, what should we spend money on?
Scope reduction, before anything else. Segmentation isolates the systems that store, process or transmit cardholder data from those that do not, and the definition of the cardholder data environment reaches systems with unrestricted connectivity to them, so every system you move outside the boundary is one you do not have to assess, harden, scan or explain. After that: an accurate data-flow map, closing the gaps that would otherwise become findings, and assembling evidence so the questionnaire takes days rather than months. Paying someone to complete the questionnaire while the controls stay unchanged buys a document, not compliance.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.