Independent PCI DSS assessor directory

Find the right PCI QSA. Know the real cost.

We've profiled 18 PCI assessment firms -- their prices, their timelines, who to avoid. Tell us about your environment and we'll match you with the best-fit Qualified Security Assessors, then make them compete for your business with side-by-side quotes. Free. Two minutes. Signing with the first assessor who calls you is how companies overpay.

Free · 2 minutes · No obligation

12PCI DSS requirements (v4.0.1)
4–12 wkTypical ROC fieldwork window
QSA onlyOnly a Qualified Security Assessor can sign a ROC
$20k–$200k+Published ROC fee range

How quote matching works

  1. Tell us once — 4 questions, 2 minutes, free.
  2. We match you — licensed CPA firms filtered to your size, scope, and timeline.
  3. Auditors quote you — they send scoped quotes directly; you pick.
Assessor directory

PCI QSA firms

Every firm below is a real, operating PCI assessment practice with a verified website. We are an independent directory -- listings are not endorsements, and we encourage you to confirm each firm's current QSA-company listing with the PCI Security Standards Council before engaging.

QSA company

Coalfire

Coalfire is one of the largest PCI assessment practices in the world, performing hundreds of PCI DSS assessments a year for merchants and service prov…

Denver, Colorado · Cybersecurity and compliance assessment firm (QSA company)
QSA company

SecurityMetrics

SecurityMetrics grew up as a PCI scanning vendor and built one of the industry's best-known SMB PCI programs: bundled ASV scanning, SAQ guidance, and …

Orem, Utah · PCI-focused compliance company (QSA company and ASV)
QSA company

LevelBlue (formerly Trustwave)

Trustwave -- now operating as LevelBlue -- has run one of the longest-standing PCI assessment practices in the industry, paired with its managed detec…

Chicago, Illinois · Managed security services provider with PCI assessment practice (QSA company)
QSA company

ControlCase

ControlCase is a PCI-centric assessment firm known for fixed-fee engagements and heavy use of its own compliance technology to keep assessment costs p…

United States (global offices) · Compliance assessment and managed-compliance firm (QSA company)

See all 18 firms →

Compare by buyer

The right assessor depends on your size

A 5-location retailer doing SAQ B-IP and a Level 1 service provider should not hire the same firm. We've grouped the directory by buyer type, with planning-range pricing for each.

Small merchants

SAQ-eligible businesses, price-sensitive. Firms with bundled ASV scanning and SAQ support.

Mid-market

Growing card volume or complexity. Fixed-fee assessments and multi-framework runway (SOC 2, ISO 27001).

Level 1 & service providers

ROC-required environments -- or a portfolio of merchants to manage. Deep benches and global delivery.

Start here

PCI DSS, explained honestly

The 12 PCI DSS Requirements

Every requirement in plain English -- what the assessor actually tests.

SAQ Types Explained

SAQ A, A-EP, B, B-IP, C, C-VT, D, P2PE -- which questionnaire is yours.

PCI Cost Guide

Published ROC and SAQ fee ranges, what drives price, and an interactive estimator.

PCI Assessment Timeline

How long a ROC really takes, from scoping to signed report.

Readiness Check

A 2-minute scored quiz that tells you if you're assessment-ready.

2026 Pricing Report

A meta-analysis of published PCI cost data, every number cited.

Choosing a QSA

Nine questions to ask before you sign an assessment engagement.

ROC vs SAQ

Which validation path your merchant level actually requires.

Best QSA Firms by Use Case

Buyer-matched picks: SMBs, mid-market, Level 1, multi-location.

Our Methodology

How we vet firms, label every price, and keep rankings unbought.

Common questions

PCI DSS basics

What is PCI DSS?

The Payment Card Industry Data Security Standard: 12 requirements for protecting cardholder data, maintained by the PCI Security Standards Council. Any organization that stores, processes, or transmits cardholder data must comply -- and validate that compliance annually.

How much does a PCI DSS assessment cost?

Published sources put a Level 1 Report on Compliance (ROC) between $20,000 and $200,000+ depending on environment size and complexity, with QSA-assisted SAQs from a few thousand dollars. See our cost guide and the 2026 pricing report for sourced numbers.

Do I need a QSA, or can I self-assess?

Level 1 merchants (6M+ transactions/year) and most service providers must use a Qualified Security Assessor for a ROC. Smaller merchants can self-assess with the right SAQ -- though many hire a QSA to validate it. See ROC vs SAQ.

How long does a PCI assessment take?

A Level 1 ROC typically runs 3 to 6 months from signed statement of work to signed report, with 4 to 12 weeks of active fieldwork. SAQ engagements are faster: 4 to 12 weeks. Details on the timeline page.

All frequently asked questions →

Get quotes from PCI QSA firms

Tell us about your environment and timeline once. We'll match you with assessors who fit -- no obligation, no spam.

Get a free quote