PCI Security Standards Council®

Qualified Integrators and Resellers

Organizations qualified by PCI SSC as Qualified Integrator and Reseller Companies (QIR Companies) are authorized to implement, configure, and/or support validated PA-DSS Payment Applications on behalf of merchants or service providers for purposes of performing Qualified Installations as part of the QIR Program. The quality, reliability, and consistency of a QIR Company’s work provide confidence that the Payment Application has been implemented in a manner that supports the Customer’s PCI DSS compliance.

QIR FEEDBACK FORM FOR PAYMENT BRANDS AND OTHERS

This form is used to review QIRs and their work product, and is intended to be completed after an installation by the QIR customer. While the primary audience of this form is QIR customers (merchants or service providers), there are several questions at the end, under "QIR Feedback Form for Payment Brands and Others," to be completed as needed by Payment Brand participants, banks, and other relevant parties.

Fields marked * are required.

Customer (merchant or service provider) Qualified Integrator and Reseller (QIR) Company
Customer Company Name * QIR Company Name *
Customer Contact Name QIR Company Contact Name *
Customer Contact Title QIR Contact Title
Customer Contact Telephone QIR Contact Telephone
Customer Contact Email QIR Contact E-mail
Location of Assessment QIR employee who performed the installation
Street * QIR Employee Name *
City * QIR Employee Title
State/Province * QIR Role
Country * Telephone
Postal Code * E-mail

I would like to be contacted by a PCI SSC representative

For each question, please indicate the response that best reflects your experience and provide comments.
5 = Strongly Agree     4 = Agree      3=Neutral       2 = Disagree      1 = Strongly Disagree

Question

Select
One

Comments

1. During the initial engagement, the Lead QIR explained the objectives, timing, and review process, and addressed your questions and concerns.

2. The QIR employee(s) understood your business and technical environment, as well as the cardholder data environment

3. The QIR employee(s) had sufficient security and technical skills to effectively perform this installation.

4. The QIR sufficiently understood the PCI Standards.

5. The QIR effectively minimized interruptions to operations and schedules.

6. The QIR provided an accurate estimate for time and resources needed.

7. The QIR provided an accurate estimate for QIR Implementation Statement delivery.

8. The QIR did not attempt to market their own products or services for your company to attain a certified installation.

9. The QIR did not imply that use of a specific brand of commercial product or service was necessary to achieve a certified installation.

10. The QIR used secure transmission to send any confidential documents or data.

11. The QIR demonstrated courtesy, professionalism, and a constructive and positive approach.

12. There was sufficient opportunity for you to ask questions and solicit responses during the installation.

13. During the installation wrap-up, the QIR clearly communicated the status and/or any outstanding issues.

14. If applicable, the QIR provided sufficient follow-up during your company’s installation efforts, until a successful implementation was achieved.

15. The QIR provided me with a copy of the QIR Implementation Statement and reviewed all of their comments with me.

16. The QIR provided me with a clear explanation of my responsibilities for maintaining a Validated Payment Application.

17. The QIR completed the implementation, leaving my site, my cardholder data environment and my payment application in a manner that facilitates compliance with the PCI DSS.

18. The QIR provided me with a clear explanation on how to change passwords and remove accounts, if necessary.

Please provide any additional comments here.



QIR FEEDBACK FORM FOR PAYMENT BRANDS AND OTHERS

Payment Brand
QIR Customer Qualified Integrator and Reseller (QIR) Company
Company Name * Company Name *
Payment Brand Reviewer QIR employee who performed the installation
Title QIR Role
Telephone * Telephone *
E-mail * E-mail *

 

For each question, please indicate the response that best reflects your experience and provide comments.
5 = Strongly Agree     4 = Agree      3=Neutral       2 = Disagree      1 = Strongly Disagree

Question

Select
One

Comments

1. The QIR Customer had a positive and professional experience with the QIR.

2. The QIR demonstrated sufficient understanding of the PCI requirements for a successful installation.

3. From your understanding, the QIR appropriately documented the installation.

Please provide any additional comments here.