What are the roles of QSAs and ASVs?
Approved Scanning Vendors (ASVs) are organizations that validate adherence to certain DSS requirements by performing vulnerability scans of Internet facing environments of merchants and service providers. Qualified Security Assessor (QSA) companies are organizations that have been qualified by the PCI Security Standards Council (SSC) to validate an entitys adherence to the PCI DSS. Many QSA companies are also ASVs, but not all ASVs are QSAs. PCI compliance for Level 1 merchants must be validated by a QSA. PCI compliance for Level 2, 3 and 4 merchants requires validation using a self-assessment questionnaire.