{"title":"Engaging a Qualified Security Assessor","category":"default","creationDate":1583833680,"content":"<div class=\"additional-info-block output-inline\">\n<h5 class=\"article__heading additional-info-block__title\">First time Level 1<\/h5><div class=\"additional-info-block__body\"><p>Consider engaging a QSA if you are migrating from a Level 2 to a Level 1 PCI compliance status.<\/p><\/div><\/div>\n\n<p>If your <a href=\"\/development-resources\/pci-dss-compliance-guide\/merchant-levels\">PCI compliance level<\/a> is <span translate=\"no\"><strong>Level 1<\/strong><\/span>, the compliance assessment must be done either by an external Qualified Security Assessor (QSA), or by your own Internal Security Assessor (ISA). <\/p>\n<p>If you choose to use your internal security resource, you must ensure that they complete the PCI SSC ISA training and pass the annual ISA accreditation program.<\/p>\n<p>If you choose to use a QSA and have not engaged one yet, refer to the <a href=\"https:\/\/www.pcisecuritystandards.org\/assessors_and_solutions\/qualified_security_assessors\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" class=\"external-link no-image\">list of PCI SSC-approved Qualified Security Assessors<\/a>.<\/p>\n<h2>Assessment process by a QSA<\/h2>\n<ol>\n<li>\n<p><strong>Gap analysis<\/strong><\/p>\n<p>The QSA performs an initial gap analysis of your PCI DSS compliance status. The analysis shows what controls you already have in place and what still needs to be implemented in order to be fully PCI DSS compliant. The QSA then shares feedback and remediation checklist items, with detailed insights of what is required.<\/p>\n<\/li>\n<li>\n<p><strong>On-site assessment<\/strong><\/p>\n<p>The QSA performs an on-site assessment to determine how your payments security currently stands. The QSA visits your location, conducts multiple interviews, and collects evidence related to your current PCI DSS compliance status. Both technical and operational components of the business are evaluated according to PCI DSS.<\/p>\n<\/li>\n<li>\n<p><strong>Remediation assistance<\/strong><\/p>\n<p>After the onsite assessment has been completed, your QSA provides initial feedback on your compliance status and the required remediation steps. Your QSA explains areas of non-compliance, provides guidance on how you can become compliant, and gives advice on retesting procedures. If corrective actions to address the identified issues are performed, and the requirements were reassessed during the assessment, you must document this in <span translate=\"no\"><strong>Items Noted For Improvement<\/strong><\/span> (INFI).<\/p>\n<\/li>\n<li>\n<p><strong>Completing the Report on Compliance (RoC)<\/strong><\/p>\n<p>When you meet all the eligible PCI DSS requirements and the audit is complete, your QSA writes your PCI DSS compliance status in a Report on Compliance (RoC). After this document has been reviewed and finalized, your QSA provides an Attestation of Compliance (AoC), which is a summary of the results of the assessment. You should submit the AoC to Adyen.<\/p>\n<div class=\"notices yellow\">\n<p>Because the ROC contains detailed information about the technical infrastructure of your cardholder data environment, you should never share the full ROC with Adyen. You should submit only your AOC.<\/p>\n<\/div>\n<\/li>\n<\/ol>\n<h2 id=\"see-also\">See also<\/h2>\n<div class=\"see-also-links output-inline\" id=\"see-also\">\n<ul><li><a href=\"\/development-resources\/pci-dss-compliance-guide\"\n                        target=\"_self\"\n                        >\n                    PCI DSS compliance guide\n                <\/a><\/li><li><a href=\"\/development-resources\/pci-dss-compliance-guide\/merchant-levels\"\n                        target=\"_self\"\n                        >\n                    PCI compliance levels\n                <\/a><\/li><\/ul><\/div>\n","url":"https:\/\/docs.adyen.com\/development-resources\/pci-dss-compliance-guide\/pci-with-qsa","articleFields":{"description":"Learn more about complying with PCI DSS with the help of a QSA.","last_edit_on":"24-02-2020 11:06"},"algolia":{"url":"https:\/\/docs.adyen.com\/development-resources\/pci-dss-compliance-guide\/pci-with-qsa","title":"Engaging a Qualified Security Assessor","content":"\nFirst time Level 1Consider engaging a QSA if you are migrating from a Level 2 to a Level 1 PCI compliance status.\n\nIf your PCI compliance level is Level 1, the compliance assessment must be done either by an external Qualified Security Assessor (QSA), or by your own Internal Security Assessor (ISA). \nIf you choose to use your internal security resource, you must ensure that they complete the PCI SSC ISA training and pass the annual ISA accreditation program.\nIf you choose to use a QSA and have not engaged one yet, refer to the list of PCI SSC-approved Qualified Security Assessors.\nAssessment process by a QSA\n\n\nGap analysis\nThe QSA performs an initial gap analysis of your PCI DSS compliance status. The analysis shows what controls you already have in place and what still needs to be implemented in order to be fully PCI DSS compliant. The QSA then shares feedback and remediation checklist items, with detailed insights of what is required.\n\n\nOn-site assessment\nThe QSA performs an on-site assessment to determine how your payments security currently stands. The QSA visits your location, conducts multiple interviews, and collects evidence related to your current PCI DSS compliance status. Both technical and operational components of the business are evaluated according to PCI DSS.\n\n\nRemediation assistance\nAfter the onsite assessment has been completed, your QSA provides initial feedback on your compliance status and the required remediation steps. Your QSA explains areas of non-compliance, provides guidance on how you can become compliant, and gives advice on retesting procedures. If corrective actions to address the identified issues are performed, and the requirements were reassessed during the assessment, you must document this in Items Noted For Improvement (INFI).\n\n\nCompleting the Report on Compliance (RoC)\nWhen you meet all the eligible PCI DSS requirements and the audit is complete, your QSA writes your PCI DSS compliance status in a Report on Compliance (RoC). After this document has been reviewed and finalized, your QSA provides an Attestation of Compliance (AoC), which is a summary of the results of the assessment. You should submit the AoC to Adyen.\n\nBecause the ROC contains detailed information about the technical infrastructure of your cardholder data environment, you should never share the full ROC with Adyen. You should submit only your AOC.\n\n\n\nSee also\n\n\n                    PCI DSS compliance guide\n                \n                    PCI compliance levels\n                \n","type":"page","locale":"en","boost":17,"hierarchy":{"lvl0":"Home","lvl1":"Development resources","lvl2":"PCI DSS compliance guide","lvl3":"Engaging a Qualified Security Assessor"},"hierarchy_url":{"lvl0":"https:\/\/docs.adyen.com\/","lvl1":"https:\/\/docs.adyen.com\/development-resources","lvl2":"https:\/\/docs.adyen.com\/development-resources\/pci-dss-compliance-guide","lvl3":"\/development-resources\/pci-dss-compliance-guide\/pci-with-qsa"},"levels":4,"category":"Development Resources","category_color":"green","tags":["Engaging","Qualified","Security","Assessor"]}}
