SY0-701 · Security Program Management and Oversight · Updated July 25, 2026
PCI DSS Assessments: QSA Audits vs Self-Assessment Questionnaires
The Payment Card Industry Data Security Standard (PCI DSS) is validated in one of two ways: an on-site audit performed by an independent Qualified Security Assessor (QSA), or a Self-Assessment Questionnaire (SAQ) completed by the organization’s own staff. A QSA audit is a form of external compliance monitoring that produces a formal Report on Compliance (ROC); an SAQ is internal self-assessment attested by the company itself. Which one applies depends mostly on how many card transactions the organization processes each year.
What PCI DSS is — and what it is not
PCI DSS is a set of technical and operational security requirements for any organization that stores, processes, or transmits payment card data. It was created by the PCI Security Standards Council, a body founded by the major card brands (Visa, Mastercard, American Express, Discover, and JCB).
Here is the detail Security+ cares about: PCI DSS is not a law. No government passed it, and no regulator enforces it. It is an industry standard enforced through contract. When a merchant signs an agreement with its acquiring bank (the bank that processes its card payments), that contract obligates the merchant to comply with PCI DSS. In governance terms, PCI DSS is an external consideration of the industry or contractual type — sitting alongside, but distinct from, legal considerations such as HIPAA or GDPR, which are actual laws.
The enforcement mechanism follows from the contract. An organization that fails to comply doesn’t get prosecuted; it faces fines from the card brands (passed through the acquiring bank), higher per-transaction fees, and — the real hammer — loss of the ability to accept card payments at all. For a retailer, that consequence is close to existential, which is why the standard has teeth despite not being legislation.
The two validation paths
Compliance with the standard is one thing; proving compliance is another. PCI DSS defines two validation mechanisms, and the SY0-701 exam expects you to distinguish them cleanly (the full SY0-701 study guide shows where compliance topics fit in the overall plan).
QSA audits (external assessment)
A Qualified Security Assessor is an individual certified by the PCI Security Standards Council, working for a QSA company, who is authorized to perform formal PCI DSS assessments. The QSA is independent — not an employee of the organization being assessed — which is exactly what makes the result trustworthy to the card brands and acquiring banks.
A QSA engagement is an on-site audit. The assessor examines network diagrams, samples system configurations, interviews staff, observes processes, and tests whether each PCI DSS requirement is actually in place. The output is a Report on Compliance (ROC) — a detailed document recording what was tested and whether it passed — plus an Attestation of Compliance (AOC), a signed summary the organization can hand to banks and partners as proof.
Because the evaluation is performed by an outside party, hiring a QSA is classified as external compliance monitoring. When an exam scenario describes an independent third-party assessor validating card-data security, that is the category being tested.
Self-Assessment Questionnaires (internal assessment)
A Self-Assessment Questionnaire is a checklist-style document the organization completes with its own personnel — no outside auditor involved. Staff walk through a series of yes/no questions mapped to PCI DSS requirements, gather their own evidence, and an officer of the company signs an attestation that the answers are truthful.
SAQs come in several flavors matched to how the merchant handles card data. You don’t need to memorize every variant for Security+, but knowing the spread helps the concept stick: SAQ A is the shortest, for merchants who fully outsource card handling (for example, a website that redirects to a hosted payment page); SAQ D is the longest, for merchants who store cardholder data themselves. Less card-data exposure means fewer questions to answer.
Because the company evaluates itself, the SAQ is the textbook example of internal compliance monitoring through self-assessment — attestation without independent verification.
Who gets which?
The card brands sort merchants into levels by annual transaction volume. The exact thresholds vary slightly by brand, but the pattern is consistent: the largest merchants (roughly over six million transactions per year) and all payment processors must undergo an annual QSA (or equivalent internal-auditor) assessment producing a ROC. Smaller merchants may validate with the appropriate SAQ instead. Any merchant that suffers a breach can be bumped up a level and forced into full QSA audits regardless of size.
QSA vs SAQ at a glance
| QSA audit | Self-Assessment Questionnaire | |
|---|---|---|
| Performed by | Independent certified assessor (third party) | The organization’s own staff |
| Monitoring type | External compliance monitoring | Internal self-assessment |
| Deliverable | Report on Compliance (ROC) + AOC | Completed SAQ + signed attestation |
| Typical requirement | Large merchants, service providers/processors | Small and mid-size merchants |
| Assurance level | High — independently verified | Lower — relies on honesty and competence of self-reporting |
| Cost and effort | Significant (on-site engagement) | Modest (internal effort) |
Compliance attestation and acknowledgment
Two governance terms show up around both paths. Attestation is the formal signed statement that the organization meets the requirements — the AOC after a QSA audit, or the signature block on an SAQ. Acknowledgment is the related idea of individuals formally confirming they understand obligations that apply to them (think of employees signing off on a cardholder-data handling policy). The exam sometimes asks which element of effective compliance a scenario describes; a mandated annual independent assessment maps to external compliance monitoring and reporting, while the signed statement itself is attestation.
Validation is a point-in-time snapshot, though — what keeps an organization compliant during the other 364 days is covered in continuous compliance monitoring. And because every system that touches card data is fair game for the assessor, smart organizations shrink the audit footprint first — see reducing PCI DSS scope.
How the SY0-701 exam tests this
- A scenario names a retailer that “hires an independent Qualified Security Assessor” and asks what type of compliance monitoring this is — the answer is external. The word independent or third-party is your cue; don’t pick “self-assessment” just because PCI DSS is mentioned.
- A scenario says a company’s own staff complete a PCI DSS questionnaire “without hiring an outside auditor” and asks what the activity is called — that is a self-assessment. The discriminator is who performs the evaluation, not what standard is being evaluated.
- A governance question asks what type of external consideration PCI DSS represents — the answer is an industry/contractual obligation, not a legal/regulatory one. Distractors will include laws like HIPAA or GDPR framing; remember no government enforces PCI DSS.
- A scenario describes a payment processor required to undergo an annual on-site assessment by an independent assessor and asks which element of effective compliance this illustrates — again external compliance monitoring/reporting. Processors and large merchants get audits; small merchants get questionnaires.
The who-performs-the-evaluation discriminator is easy to state and easy to fumble under time pressure — Security+ practice questions make it stick.
Quick reference
- PCI DSS = Payment Card Industry Data Security Standard; applies to anyone storing, processing, or transmitting cardholder data.
- It is an industry standard enforced by contract with acquiring banks and card brands — not a law.
- Non-compliance risks fines and losing the ability to process card payments.
- QSA = Qualified Security Assessor: independent, certified, performs on-site audits → external compliance monitoring.
- QSA audits produce a Report on Compliance (ROC) and an Attestation of Compliance (AOC).
- SAQ = Self-Assessment Questionnaire: completed internally by the organization’s own staff → internal self-assessment.
- Large merchants and payment processors need annual QSA assessments; smaller merchants may use the appropriate SAQ.
- On the exam, decide by who performs the evaluation: outsider = external monitoring; own staff = self-assessment.