Skip to content

Do I need a QSA for PCI DSS?

By Sam Rivera, Founder, SentinelPanda · June 18, 2026 · 3 min read · Compliance

Most small and mid-sized merchants can self-assess with an SAQ and sign their own AOC. A QSA is required only at the top — here is exactly where the line sits.

The short answer

Most small and mid-sized merchants do not need a Qualified Security Assessor. You qualify to self-assess with a Self-Assessment Questionnaire (SAQ) and sign your own Attestation of Compliance (AOC). A QSA is required only when you must produce a Report on Compliance (ROC) — generally Level 1 merchants, the largest service providers, or when your acquiring bank specifically demands one.

If you are a startup or SMB taking cards, you are almost certainly in SAQ territory, and the expensive-auditor fear is usually misplaced.

What decides it: your merchant level

Validation depends on your annual transaction volume — your merchant level, set by the card brands:

  • Level 1 — more than 6 million transactions a year, or any merchant after a breach: Report on Compliance, typically QSA-led.
  • Level 2 — 1 to 6 million transactions: usually an SAQ (a few acquirers want a QSA signature, so ask yours).
  • Level 3 — 20,000 to 1 million e-commerce transactions: SAQ.
  • Level 4 — everyone below that: SAQ.

Service providers have their own scale

If you process, store, or transmit card data on behalf of other businesses, you are a service provider. The largest (broadly, above 300,000 transactions a year) need a QSA-led Report on Compliance; the rest self-assess with SAQ D for service providers. As always, your acquirer or the client demanding your compliance has the final say on which path applies.

Self-assess does not mean skip the work

Self-assessment removes the assessor, not the requirements. You still complete the correct SAQ honestly, run quarterly external vulnerability scans through an Approved Scanning Vendor where your SAQ type requires them, keep the supporting evidence, and sign the AOC your acquirer files. Which SAQ you complete depends on how you take payments — a fully outsourced checkout, a card terminal, a virtual terminal, or storing card data yourself each map to a different questionnaire.

When a QSA is worth it anyway

Even when it is optional, a QSA can be worth engaging: a complex cardholder-data environment you are not sure how to scope, an acquirer that asks for a signed ROC, or an enterprise customer that wants third-party assurance. Outside those cases, a QSA is a cost most SMBs can defer.

The one caveat: your acquirer has the final say

The levels above are the card-brand baseline, but your acquiring bank can require more than the minimum. Always confirm your merchant level and validation path with them in writing before you build your plan around an SAQ. Thresholds reflect the standard card-brand levels; confirm the current numbers with the PCI SSC and your acquirer.

Find your path in two minutes

The free SAQ finder asks a few questions about how you take payments and tells you which SAQ type applies, plus a checklist of exactly what it requires — scans, policies, and evidence. It is free and the result is yours to keep. SentinelPanda helps you self-assess and stay audit-ready; it does not certify you, and it does not replace your ASV scans or the signed AOC your acquirer files.

Find your SAQ type — free Which PCI SAQ type applies to you? Start the free self-assessment

Run your compliance program in one workspace.