PCI ISA: What It Verifies
- Published
- 2026-08-01
- Content type
- Certification / Standards Authority
- Read time
- 1 min
PCI ISA — Internal Security Assessor — is a PCI Security Standards Council credential that authorizes an individual to assess their own employer's PCI DSS compliance internally, in place of (or alongside) an external QSA. Unlike PCI DSS itself, ISA is a real, individually-issued credential with a checkable status.
What it verifies
ISA confirms someone completed PCI SSC's internal-assessor training and holds current authorization to evaluate PCI DSS controls inside their organization's cardholder data environment. It's employer-sponsored — the credential is tied to working at a company that has sponsored the individual into the program, not a general-market certification anyone can sit independently.
Who typically holds it
On the calibre° roster, PCI-ISA is checked for Backend Engineer and PCI Data Analyzer — roles building or mapping systems inside PCI scope, where internal-assessment fluency is a direct asset.
How calibre° verifies it
PCI-ISA status is checked against PCI SSC's program listing before roster eligibility — not accepted as a self-reported claim. Full procedure: Verification.
FAQ
Is PCI-ISA the same as a QSA?
No. A QSA (Qualified Security Assessor) is certified to assess any organization externally. ISA is scoped to assessing the sponsoring employer's own environment internally — a narrower, employer-tied credential.
Does ISA require annual renewal?
Yes — ISA status requires annual re-training and re-sponsorship by an employer to stay current, which is why calibre° checks current status rather than a resume claim.
Why does PCI Data Analyzer check ISA?
Because mapping cardholder-data flows and defining CDE scope draws on the same internal-assessment framework — see [PCI Data Analyzer](/calibre/roles#pci-data-analyzer) for the full certification set.
Specify the role. We calibrate the match.