Attestio
PCI QSA · 2026 Buyer's Guide

The PCI QSA directory & buyer’s guide

442 Qualified Security Assessor firms across 18 countries, independently verified each quarter from the PCI Security Standards Council’s official list. Whether you’re a Level 1 merchant preparing for your first ROC or a service provider evaluating your third annual assessment, this is the research base we built for you.

✓ Independently verified Last updated June 14, 2026
442
Indexed firms
18
Countries
67
Global firms
105
Multi-region
Editorial illustration of a compliance audit process
The buyer's guide

How to choose a PCI QSA — and what to expect

Choosing a PCI QSA is a high-stakes decision: the firm you pick writes the report your acquiring bank, your payment processor, and (if you have them) your enterprise customers will rely on to assess your cardholder data security. A weak choice can mean missed findings, audit-fatigue, repeat assessments, or worse — a ROC your acquirer rejects. This guide walks through the seven criteria we use to evaluate firms in our directory, what a typical PCI DSS audit costs and how long it takes, and when you actually need a QSA versus a self-assessment.

01

What is a PCI QSA?

A Qualified Security Assessor (QSA) is an individual certified by the PCI Security Standards Council (PCI SSC) to conduct on-site PCI DSS assessments for Level 1 merchants and Level 1 service providers. The QSA is independent of your company — they can’t be an employee, a recent contractor, or anyone with a financial interest in the outcome. After the assessment, the QSA writes a Report on Compliance (ROC), which is the formal attestation that your cardholder data environment (CDE) meets the PCI DSS standard. QSAs work for QSA Companies — the firms listed in our directory — which are themselves certified by PCI SSC to employ QSAs. The QSA Company is the entity that signs the ROC, even though an individual QSA does most of the work.

02

How to choose a PCI QSA: 7 criteria

1. Industry experience. A QSA firm that does 30% of its audits in your industry (SaaS billing, retail POS, healthcare payments, hospitality) will scope faster and write a tighter ROC. Ask: “How many assessments have you done for [your industry] in the last 12 months?” 2. Geographic coverage. If you operate card processing in 12 countries, you need a firm with QSAs in those countries — or a global firm that can dispatch. Look at the service_type field in our directory: global (4+ regions), multi_region (2-3), or single_region. 3. Associate QSA support. Junior staff (Associate QSAs) do scoping and evidence review at a lower rate, with QSA oversight on findings. This is a 20-40% cost lever. 4. Bandwidth and timeline. Q4 is peak PCI season. Firms book out by October. If you need a Q1 ROC, engage in November. 5. Pricing transparency. The best firms publish ranges; the worst quote a flat fee before scoping. 6. Tools and methodology. Some QSA firms use proprietary platforms (evidence collection, scope visualization, finding tracking). Others use the standard PCI SSC template. Both are valid — the question is whether the tools help your team or just the QSA’s. 7. Reference customers. Ask for two customers in your size range. Talk to them.

03

How much does a PCI DSS audit cost?

For a Level 1 full assessment, expect $50K–$200K depending on scope. The drivers: number of cardholder data environments (CDEs), number of systems in scope, number of physical locations, complexity of network segmentation, and whether you need a QSA on-site or if remote assessment is acceptable. For a smaller gap assessment or pre-ROC readiness review, $5K–$30K is typical. Hourly rates run $200–$450 for a senior QSA, less for an Associate QSA. Red flag: any firm that quotes a flat fee without first scoping your environment is not doing it right. PCI DSS is a 12-section standard with 300+ requirements; an un-scoped quote is a guess.

04

How long does a PCI DSS audit take?

From kickoff to final ROC: typically 3–6 months. Scoping and planning takes 2–4 weeks. The on-site (or remote) assessment is 1–3 weeks for a typical Level 1 environment. The QSA drafts the ROC, your team responds to findings, the QSA re-tests, and the final ROC is signed off. The ROC is valid for one year — you need an annual reassessment. Many QSA firms also offer a 6-month or 9-month interim check-in to catch drift between annual audits. That’s optional but increasingly common.

05

QSA vs. self-assessment: when do you actually need a QSA?

You need a QSA assessment if: (a) you’re a Level 1 merchant (more than 6 million Visa transactions per year); (b) you’re a Level 1 service provider; (c) your acquiring bank or payment processor requires a QSA ROC regardless of your volume. For Level 2–4 merchants, a Self-Assessment Questionnaire (SAQ) is permitted — but most do a QSA-led gap assessment first, then complete the SAQ. The exception: if your acquirer or a major customer requires a QSA ROC, do that even if you’re technically SAQ-eligible. The cost of a QSA assessment is usually recovered in faster enterprise sales cycles.

The QSA you pick matters more than the QSA fee you pay. A 10% cost difference between firms is rounding error compared to the cost of a missed finding, a re-test, or a ROC your acquirer challenges. Use the directory below to filter by region, by service type, and by whether the firm supports Associate QSAs. The 442 firms here are not ranked — they all hold the same PCI SSC certification. The differentiators are industry fit, geographic coverage, and team continuity from year to year. Talk to two or three before you sign.
Editor's picks

Six firms worth shortlisting

For each use case below, we picked one firm from the 442 we index. These are not the largest, the most expensive, or the most famous. They are firms we’d shortlist for a buyer with the specific need described.

Best for SaaS billing

A-LIGN

PCI + SOC 2 + HITRUST under one engagement

A-LIGN runs parallel PCI DSS and SOC 2 assessments for SaaS billing platforms, with shared evidence collection across both frameworks. Their methodology is built around cloud-native environments (AWS, GCP, Azure) and they have Associate QSAs who do the bulk of evidence review under QSA oversight, which keeps the engagement price 20-30% below Big-4-style firms.

Audited 100+ SaaS companies in the last 24 months
View profile →
Best for fintech & payments

Coalfire

The incumbent for card-network-side assessments

Coalfire is the QSA firm that acquirers and card brands (Visa, Mastercard, Amex) call when they need an independent assessment of a payments platform. Their QSA bench is large enough to handle a 12-month engagement on a multi-region CDE, and they have specific expertise in tokenization, point-to-point encryption, and the newer PCI MPoC standard.

Issued 1,000+ ROCs across payments platforms
View profile →
Best for global enterprises

KPMG

Coverage in 60+ countries, single QSA-of-record

KPMG runs a global QSA practice with QSAs licensed in the major markets where enterprise merchants process cards. The differentiator vs. other Big 4 firms: KPMG assigns a single QSA-of-record who coordinates the in-country assessors, so your team writes one narrative instead of three.

QSA coverage in 60+ countries
View profile →
Best for SMB and startup

BARR Advisory

Right-sized engagements, no enterprise overhead

BARR specializes in mid-market and growth-stage companies. They publish a sample engagement scope and a fixed-fee structure (rare in PCI), so you know what you’re paying before the kickoff. They run PCI alongside SOC 2 and HITRUST assessments for companies that need all three.

Fixed-fee PCI engagements published on their site
View profile →
Best for healthcare payments

Schellman & Co.

PCI + HITRUST CSF + HIPAA, single assessor

Schellman is one of the few QSA firms that runs PCI, HITRUST CSF, and HIPAA Security Risk Analysis in a single engagement. For healthcare payments platforms, this collapses three annual audits into one evidence-collection cycle.

Joint PCI + HITRUST engagements standard
View profile →
Best for retail POS and omnichannel

Schneider Downs

In-store, e-commerce, and franchise POS expertise

Schneider Downs has deep experience with multi-location retailers: complex segmentation between in-store POS, e-commerce, and franchise systems. They have a methodology for assessing franchisee compliance without auditing every franchise individually.

300+ retail POS audits completed
View profile →
How we pick: Picks are based on the firm’s track record in the named use case (volume of engagements), breadth of related certifications (firms that also do SOC 2 / HITRUST / ISO 27001 are stronger for buyers who need multiple frameworks), geographic coverage, and pricing transparency. We do not accept payment for inclusion in this list, and we update it annually. Disagreements are welcome — <a href="/operators/claim">claim your firm’s profile</a> to update your listing.
How we verify

We aggregate PCI QSA firms from 5 independent sources, not just one. That’s the difference between a directory and a phone book.

Verified quarterly Last verified June 14, 2026 Last crawled June 14, 2026
The primary registry. 442 active QSA Companies as of June 2026.
Cross-reference for UK-based and international QSA Companies accredited by UKAS.
ANSI National Accreditation Board — US accreditation body for QSA firms.
International Accreditation Forum registry — cross-checks for global QSA firms.
Direct verification
Firms with a claimed profile on attestio.co can update their service type, regions, and Associate QSA support directly.
📋

Get the free checklist

We'll email you the PDF. Plus weekly compliance insights. No spam, unsubscribe with one click.

We use this only to send your checklist. One-click unsubscribe in every email.

The full directory

All 442 PCI QSA firms

Filter by category or search.

Clear all
Showing 16 firms in Australia

1stSecureIT LLC (dba GM SECTEC)

Global
🌐 1stsecureit.com
📍 United States · Latin America & Caribbean · Europe · Europe, Middle East & Africa · Australia
🗣 English, Portuguese, Spanish, Hindi

BOTECH FRAUD PREVENTION & INTELLIGENCE SL.

Global
🌐 botech.info
📍 Europe · Latin America & Caribbean · United States · Australia
🗣 English, Spanish, Portuguese

CBIZ Security & Compliance, LLC

Global
🌐 cbiz.com
📍 United States · Latin America & Caribbean · Europe, Middle East & Africa · Australia
🗣 English

Thales Cyber Services Australia Pty Ltd

Global
🌐 tesserent.com
📍 Australia · Europe · Hong Kong · New Zealand
🗣 English

Bastion Security Group Limited

Multi-region Associate QSA
🌐 bastionsecurity.co.nz
📍 New Zealand · Australia
🗣 English

CLOUDTRACE PTY LTD

Multi-region
🌐 cloudtrace.com.au
📍 Australia · United States
🗣 English

CampusGuard LLC

Multi-region
🌐 campusguard.com
📍 United States · Australia
🗣 English

Dot.Bit d.o.o.

Multi-region
🌐 dotbit.eu
📍 Europe, Middle East & Africa · Europe · Australia
🗣 Bosnian, Croatian, English, Serbian

CYBERNETIC GLOBAL INTELLIGENCE

🌐 cyberneticgi.com
📍 Australia
🗣 English

CYPHERLEAP PTY LTD

🌐 cypherleap.com
📍 Australia
🗣 English, Malyalam

Cyberensic Pty Ltd

🌐 cyberensic.com.au
📍 Australia

DotSec Pty Ltd

🌐 dotsec.com
📍 Australia
🗣 English

Information Systems Services Pty. Ltd. t/a CyberZone Global

🌐 cyberzoneglobal.com
📍 Australia
🗣 English, Hindi, Indian, Punjabi

MORRISEC PTY LTD

🌐 morrisec.com.au
📍 Australia
🗣 English

Security Centric Pty Ltd

🌐 securitycentric.com.au
📍 Australia
🗣 English

Triskele Labs

🌐 triskelelabs.com
📍 Australia
🗣 English
FAQ

Common questions

Is a PCI QSA the same as a PCI DSS auditor?

Yes. "QSA" is the certification; "auditor" is the role. All QSAs are PCI DSS auditors; not all PCI DSS auditors are QSAs (some do gap assessments or readiness reviews without being certified).

How long is a PCI QSA certificate valid?

Individual QSA certifications are renewed annually by PCI SSC. QSA Company certifications are also annual. A QSA who lets their certification lapse cannot sign a ROC until it’s renewed.

Can a QSA firm audit its own client?

No. PCI SSC prohibits QSAs from auditing any company they have a consulting, integration, or financial relationship with. This is a conflict-of-interest rule enforced at the QSA Company level.

What’s the difference between a QSA and a PA-QSA?

A PA-QSA (PIN Transaction Security Qualified Security Assessor) assesses point-of-interaction devices and PIN transaction security. A QSA assesses PCI DSS. They’re separate certifications. Some firms hold both.

Do all QSAs do SOC 2 and HITRUST too?

No. Many QSA firms only do PCI. The directory filter service_type shows PCI-only firms, multi-framework firms, and global firms. Use the "Also listed in" pills on a firm’s profile to see what other verticals they audit for.