Get Demo
↑

QSA vs ISA vs ASV: Who Does What in a PCI Assessment

PCI QSA vs ISA vs ASV - official PCI SSC role definitions for assessors and Approved Scanning Vendors, and when each is required.

Published: September 2026 Compliance · PCI DSS 8-12 min read

Three PCI SSC programs are easy to confuse: Qualified Security Assessors validate an entity's adherence to PCI DSS; Internal Security Assessors support their employer's PCI program; Approved Scanning Vendors run required external vulnerability scans.

Related: ROC and AOC · ASV scan requirements · Requirement 11 · Preparing for a QSA audit.

Gotcha: An ASV scan is not a PCI DSS assessment. A QSA assessment is not a substitute for quarterly ASV scans. An ISA is not a freelance QSA for other merchants.

Official Definitions

Side-by-Side

Role
Who
Typical output
Independence
QSA
PCI SSC-listed QSA Company / QSA Employees
ROC and related assessment work
Independent assessor of the entity
ISA
Employee of ISA sponsor company
Internal assessment quality / SAQ or QSA prep support
Internal to employer
ASV
PCI SSC-listed ASV Company
Quarterly external vulnerability scan reports (pass/fail per ASV Program Guide)
Scanning vendor; distinct from QSA

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across SAQ and ROC validation paths.

Frequently Asked Questions

Can my IT team run the quarterly external scan instead of an ASV?

No for Requirement 11.3.2 - external scans must be completed by a PCI SSC Approved Scanning Vendor. Internal scans under 11.3.1 follow different rules.

Does an ISA make us Level 1 ROC-ready without a QSA?

Brand and acquirer rules decide the validation method. ISAs strengthen internal capability; ROC validation still typically requires a QSA when a ROC is required.

Are QSA and ASV the same listing?

No. They are separate PCI SSC programs and directories.

ROC and AOC · ASV scans · Requirement 11 · SAQ types · PCI hub

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!