Can a PCI QSA also do my SOC 2 audit?
QSA qualification covers PCI DSS validation, not SOC 2 signing. Dual delivery exists only when a CPA practice in the same group will issue the report. Verify current QSA status and the CPA signer, because the two deliverables may use different teams or entities.
A Qualified Security Assessor company performs PCI DSS assessments. The SOC 2 signer is a licensed CPA firm, not the Council-qualified QSA team, even when both sit in one company.
The PCI Security Standards Council’s registry is the source to verify before you sign. Confirm current status, region, personnel availability, CPA signer, and contracting entities. Listed timelines and prices cover SOC 2 planning only; PCI DSS work is scoped separately.