Assessors

How to Choose a PCI QSA Firm: 9 Questions to Ask

Start with the non-negotiable

Only a PCI SSC-listed QSA company can sign a Report on Compliance. That is the entire credential that matters. A consultant, a scanning vendor, and a pen-testing shop can all prepare you -- none can sign the ROC. Verify the listing before anything else.

The 9 questions

  1. Are you a currently listed QSA company, and which entity signs the ROC?
    Some firms operate under affiliate names. Know whose name goes on your report.
  2. Who is my actual assessment team?
    Partner bios in the pitch deck mean nothing if juniors do the testing. Ask for the lead QSA and their assessment count.
  3. Fixed fee or time-and-materials -- and what breaks the fixed fee?
    Get scope boundaries in writing: locations, systems, applications, and what triggers a change order.
  4. How do you sample multi-location environments?
    Sampling methodology drives both fee and fieldwork length. Understand it before you sign.
  5. What's your experience with our environment?
    Cloud vs on-prem, e-commerce vs POS, P2PE vs non-P2PE -- an assessor who knows your architecture tests faster and asks smarter questions.
  6. How do you handle evidence collection?
    Do they integrate with your tooling, or will your team be screenshotting into spreadsheets for weeks?
  7. What does your timeline look like from SOW to signed ROC?
    Then ask what they need from you to hit it. The bottleneck is almost always the client.
  8. Can you bundle other frameworks?
    If SOC 2 or ISO 27001 is on your roadmap, one firm doing combined assessments shares evidence and cuts total cost.
  9. Can I talk to two reference clients my size?
    Not logos -- conversations. Ask those references: did the fee hold, did the timeline hold, and would they re-engage?

Red flags

  • Guaranteed passing ROC. No ethical assessor pre-promises the outcome.
  • Won't name the assessment team. You're buying people, not a brand.
  • Vague scope, lump-sum fee. "PCI: $40k" with no locations, no systems, no applications is a change order waiting to happen.
  • They also sell you the remediation. The firm that finds the gaps shouldn't be the one billing to fix them -- independence matters.

Boutique vs large firm

The ROC format is standardized by the PCI SSC, so a passing ROC from a boutique carries the same structural weight as one from a global firm. What differs: bench depth, bundled frameworks, and price. Match the firm to your complexity, not your aspirations. Browse verified assessor profiles or get matched.

Questions

Should I use a Big 4 firm for PCI?

Rarely necessary. The PCI SSC standardizes the ROC, so specialist QSA companies issue equally valid reports at lower cost. Large firms make sense for global, multi-entity programs.

How many quotes should I get?

Two to three scoped quotes is the sweet spot -- enough to see the real price band, few enough to evaluate properly.

Independent directory note. This guide is educational content, not assessment advice. Confirm requirements with your QSA and acquirer.

Related reading

Get quotes from PCI QSA firms

Tell us about your environment once -- matched assessors reply with scoped quotes. Free, 2 minutes.

Get a free quote