What is a QSA-validated SAQ?
When a Qualified Security Assessor reviews or signs a Self-Assessment Questionnaire, what that signature actually means, and who requires it.
The short version
A “validated SAQ” is industry shorthand, not a PCI SSC product. It usually means a Self-Assessment Questionnaire (SAQ) where a Qualified Security Assessor (QSA) reviewed the work, helped complete it, or signed the Attestation of Compliance (AOC).
The company is still the one attesting. The QSA’s job on that form is whatever the parties agree it is.
PCI SSC does not require a QSA on an SAQ. Payment brands and acquirers sometimes do. Mastercard currently requires a QSA or Internal Security Assessor (ISA) for some Level 2 merchants. Visa’s published Level 2 path is an SAQ without that extra assessor step. Your acquirer can be stricter than either brand.
If you are still choosing a questionnaire, start with PCI DSS Self-Assessment Questionnaires. If the question is ROC versus SAQ, that is the receiving organization’s decision; the PCI DSS page covers what to ask them.
What the AOC actually asks
On a current PCI DSS SAQ AOC, the merchant (or service provider) executive signs that the questionnaire was completed as instructed and that the results fairly represent the assessment.
If a QSA was involved, Part 3c is a separate acknowledgement. It does not prescribe a scope of work. It asks the assessor to tick a box and, if needed, write what they actually did:
The form offers two checkboxes:
- the QSA performed testing procedures, or
- the QSA provided other assistance, with a blank to describe every role.
The QSA company, lead QSA, and a duly authorized officer of the QSA company then sign. An ISA section exists for the same idea when an Internal Security Assessor did the work.
That is the whole official job description: “involved or assisted,” plus whatever you write in the blank. There is no PCI SSC menu of validated-SAQ engagement types.
Why the work (and the cost) varies so much
Because the form does not define the role, the market does. A QSA-involved SAQ can look like:
- Coaching. Walk through the requirements, help you interpret eligibility, and stay out of testing.
- Scoping and gap work. Map payment flows, point out missing controls, and leave you to remediate and attest.
- Evidence review. Sample configurations, policies, scans, and interviews, then sign that testing procedures were performed.
- ROC-like testing on an SAQ form. Deep control testing that resembles a Report on Compliance, except the output is still an SAQ and AOC, and the client is still the attesting party.
Those are different projects. Fees follow the testing depth, the size of the cardholder data environment, and how much the QSA is willing to put their name under. A coaching engagement and a full evidence review should not cost the same, and they do not mean the same thing to an acquirer.
Ask the QSA, in writing, what they will test, what they will not test, and which AOC checkbox they expect to use. Ask the acquirer what “QSA involved” has to mean for them.
Look up currently listed QSA companies on the PCI SSC site before you hire, and again when you sign.
Who requires it
PCI SSC publishes SAQs as self-assessment tools. It does not assign merchant levels or require a QSA signature on an SAQ.
Mastercard, through its Site Data Protection program, is the brand with the long paper trail. In 2009 it told Level 2 merchants they would need a QSA for annual validation. After merchant pushback it delayed enforcement and, from June 2011, allowed a QSA or a PCI SSC-certified ISA instead of forcing every Level 2 onto a ROC. That assessor-involved SAQ rule is what people still mean when they talk about a “required validated SAQ.”
Mastercard narrowed the rule in March 2021. Level 2 merchants still complete an annual SAQ. Those using SAQ A, SAQ A-EP, or SAQ D must still engage a QSA or ISA for compliance validation. Those using SAQ B, B-IP, C-VT, C, or P2PE may self-assess without that assessor. Level 2 merchants may still choose a ROC instead. Mastercard publishes the current table in its Site Data Protection program materials.
Visa’s published Level 2 merchant path is an annual SAQ and an AOC. It does not, on that table, require a QSA to sign the SAQ. See Visa’s PCI DSS Validation Best Practice Review.
Acquirers and other compliance-accepting entities can require more than the brand table: a QSA signature on any SAQ, a specific SAQ type, or a ROC. After a breach or a messy filing, they often do. That decision is the one that counts for your submission.
Service-provider programs are separate. A Level 2 service provider may be SAQ-eligible under a brand’s rules and still have customers or an acquirer who want a QSA-signed AOC.
How to find out if you need one
- Confirm your merchant or service-provider level in writing with the organization that receives your paperwork.
- Confirm the SAQ type you are actually eligible to complete.
- Ask whether a QSA or ISA must be involved, and whether “involved” means coaching, testing procedures, or something in between.
- If a QSA will sign, agree the role description that will appear on the AOC before fieldwork starts.
Do not infer the answer from a decade-old headline. The Mastercard Level 2 rule is real, but it is brand-specific, SAQ-specific, and still subject to what your acquirer will accept this year.
Published August 28, 2026. Updated September 3, 2026.