Associate QSA FAQ
Associate QSA FAQ
Associate QSA FAQ
The PCI SSC has introduced a new Associate QSA Program for 2018, with the goal of attracting new
cyber talent to the QSA Program and easing the resource constraints felt by QSA Companies. The
Associate QSA certification will provide a professional path for new entrants to join the payment card
industry and gain experience to qualify as a QSA.
This project is part of a broader initiative to evolve the QSA Program to ensure its sustainability and
quality in a changing payment environment. Additional changes to the QSA Program will focus on
supporting future standards and technologies and attracting new cyber talent to develop the next
generation of QSAs.
Q1 Why did the PCI SSC create the Associate QSA Program?
A An overall shortage of cyber security talent is making it difficult for QSA Companies to find
suitable new assessors. As a result, assessors are increasingly expensive to hire and retain,
driving assessment costs up for merchants that rely on their services. The Associate QSA
certification program is designed to bring new cyber talent to the QSA Program, easing the
resource constraints for QSA Companies, and ensuring high quality QSA services are available
for merchants and service providers into the future.
Q2 How is the Associate QSA certification different than the QSA certification?
A The Associate QSA certification is designed for employees of QSA Companies that do not yet
have enough experience to be a QSA but who are interested in achieving QSA certification in
the future. It provides a professional path to gain the necessary experience to become a QSA.
Q5 When will the PCI SSC begin accepting applications for the Associate QSA
Program?
A Applications are now being accepted for the Associate QSA Program via the PCI SSC website.
Q6 What is involved in the application process for the Associate QSA program?
Companies that have been in the QSA program for two years or more are eligible to submit
applications for their employees to become Associate QSAs. There are three key steps to the
application process:
PCI SSC – Frequently Asked Questions (FAQs) for Associate Qualified Security Assessor (QSA) Program
January 2018
Copyright 2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 1
1. Applications must be submitted by Primary Contacts via the PCI SSC website. Applications
must fulfil all of the Associate QSA Qualification Requirements, which include attesting that a
QSA Mentor will be assigned and a Mentor Manual will be submitted to PCI SSC.
2. QSA Mentors must take the PCI SSC one-hour online training module..
3. Associate QSA applicants must successfully complete the Associate QSA online
prerequisite PCI Fundamentals course and the two-day instructor-led course and pass the
exam. Upon certification, they will be listed on the PCI SSC website.
PCI SSC – Frequently Asked Questions (FAQs) for Associate Qualified Security Assessor (QSA) Program
January 2018
Copyright 2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 2
Q 14 How long is the Associate QSA certification good for?
A The certification is good for 12 months. At that time, Associate QSAs will need to recertify to
maintain status as an Associate QSA and listing on the PCI SSC website.
Q 16 Can Associate QSAs take their certification with them from QSA Company to QSA
Company?
A Yes. Associate QSAs are able to take their certification with them from QSA Company to QSA
Company, subject to the terms of the program being met.
PCI SSC – Frequently Asked Questions (FAQs) for Associate Qualified Security Assessor (QSA) Program
January 2018
Copyright 2018 PCI Security Standards Council, LLC. All Rights Reserved. Page 3