What QSAs Actually Test: Inside ROC Fieldwork
Phase 4 demystified — the testing procedures, the evidence requests, and how to walk into fieldwork with everything ready.
The three testing procedures
Every PCI DSS requirement is validated with some combination of three procedures: examine (review documentation and configurations), interview (talk to the people who operate the controls), and test (observe the control working or inspect system evidence). A QSA who only examines paperwork isn't assessing — expect all three, especially on high-risk requirements like MFA, logging, and segmentation.
The evidence request list
Before fieldwork, the QSA sends a request list: network diagrams, firewall rulesets, system inventories, policies and procedures, training records, vulnerability scan reports, pen test reports, access reviews, log samples, change tickets, vendor AoCs. The list is long because the standard is broad — run our readiness quiz to see where your gaps are before the QSA does.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesSampling and interviews
QSAs sample: a subset of firewall rules, a subset of systems, a subset of user accounts. They interview system admins, developers, and managers — not to trap anyone, but to confirm the documented process matches reality. The fastest way to fail an interview is for the documented procedure and the actual practice to disagree.
How to be ready
- Centralize evidence early. A shared evidence package beats a last-minute scramble across five teams.
- Rehearse the interviews. The people who operate controls should be able to describe them plainly.
- Fix the known gaps first. A gap assessment before fieldwork is almost always cheaper than findings during it.
- Keep everything dated. Evidence from the assessment period only — last year's screenshots don't count.
Keep reading
ROC vs SAQ: Which PCI Validation Path Are You On?
The two roads through PCI DSS certification — what happens on each, who decides, and the expensive mistake of picking the wrong one.
SAQ Types A Through D, Explained
Eight questionnaires, one choice that shapes your whole PCI workload. Which SAQ type fits your payment setup — and what each one demands.
What Happens If You Fail a PCI Assessment
Nobody passes on the first try. How findings, remediation, and re-testing actually work — and why “not yet compliant” isn't the disaster it sounds like.
Questions
How long does fieldwork take?
Planning range: 2–12 weeks depending on scope complexity. Simple single-entity scopes sit at the low end; multi-entity, multi-region scopes at the high end.
Can fieldwork be done remotely?
Largely yes — most QSAs now do substantial fieldwork remotely, with on-site visits for physical security and walkthroughs where the standard requires it.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.