Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

PCI DSS compliance cost by validation path in 2026, from SAQ A to a Level 1 ROC

PCI DSS Compliance Cost: A Clear 2026 Price Breakdown

The PCI DSS compliance cost for a US business in 2026 runs from roughly $500 a year for a small e-commerce merchant on SAQ A to well past $200,000 for a Level 1 retailer under a full Report on Compliance. That spread is not vendor markup. It is the difference between attesting to a couple of dozen requirements you have largely outsourced and paying a Qualified Security Assessor to test several hundred controls across your own infrastructure. Before you can budget anything, you have to know which of those two situations you are in.

What the PCI DSS compliance cost actually buys

There is no such thing as a PCI DSS certificate. PCI DSS is validated, not certified: you produce an Attestation of Compliance (AOC) each year, supported either by a Self-Assessment Questionnaire you complete yourself or by a Report on Compliance written by a QSA or an Internal Security Assessor. Anyone selling you a “PCI certification” is selling you an assessment with the wrong label on it, and the distinction matters for your budget, because a self-assessment has no third-party fee attached to it at all.

The current version is PCI DSS v4.0.1, which has been the only active version since v4.0 was retired on 31 December 2024. If a quote you receive still references v3.2.1 or prices “v4.0 readiness”, the vendor is working from an old scope. Our guide to PCI DSS v4.0.1 covers what changed and which future-dated requirements are now being assessed.

Three things drive every number below: your merchant level, your validation path, and the size of your cardholder data environment. Only the third is under your control, and it is where almost all of the savings live.

PCI DSS compliance cost by merchant level

Merchant levels are set by the card brands and applied to you by your acquiring bank — not by the PCI Security Standards Council. The thresholds differ slightly between brands, so the level your acquirer assigns is the one that counts. Visa’s, published on its CISP program pages, are the most commonly quoted:

LevelVisa volume thresholdUsual validationTypical annual spend
Level 1Over 6 million Visa transactions a year, all channelsROC by a QSA or ISA, quarterly ASV scans$35,000 – $200,000+
Level 21 million to 6 million a year, all channelsSAQ (some acquirers require a QSA-signed SAQ), quarterly ASV scans$10,000 – $50,000
Level 320,000 to 1 million e-commerce transactions a yearSAQ, quarterly ASV scans$5,000 – $25,000
Level 4Under 20,000 e-commerce, or up to 1 million totalSAQ, ASV scans if internet-facing$500 – $5,000
Typical 2026 US ranges, aggregated from published pricing by QSA firms and assessment vendors. Confirm your level with your acquirer.

Two structural points before you use that table. Your acquirer can impose a stricter validation path than the brand threshold implies, and a compromise can move you up a level regardless of volume — both of which change the PCI DSS compliance cost far more than a change in transaction count. Note also what the level does not change: all twelve PCI DSS requirements apply at every level. Your level only changes how you are required to prove it. A Level 4 merchant still has to meet the same encryption, access control and logging requirements as a Level 1 bank — it just gets to say so on its own signature.

The line items behind any PCI DSS compliance cost

Build the budget bottom-up rather than accepting a single headline figure. Almost every PCI DSS compliance cost decomposes into the same seven items, and only two of them are ever paid to an assessor.

Line itemTypical 2026 US rangeNotes
Scope definition and network diagrams$0 – $8,000Requirement 12.5.2 wants this confirmed at least every 12 months
Documentation set (policies, procedures, evidence forms)$99 – $20,000Template toolkit versus consultant-written
Gap assessment / readiness review$0 – $25,000Free if run internally; QSA-led for a first ROC
Quarterly ASV scanning (Req 11.3.2)$1,000 – $5,000 a yearMust use a PCI SSC Approved Scanning Vendor
Penetration testing (Req 11.4.3)$8,000 – $30,000 per testAt least every 12 months and after significant change
Remediation and tooling (MFA, logging, encryption, segmentation)$0 – $150,000The widest and least predictable item
QSA assessment fee (ROC) or SAQ signing$0 – $150,000$0 on a genuine self-assessment
Typical ranges from published 2026 guidance by QSA firms and assessment vendors, not from a single citable survey.

The two scanning items are the ones small merchants most often miss. ASV scanning and penetration testing are separate controls in PCI DSS v4.0.1 and one does not substitute for the other: an ASV scan is an automated external scan run at least every three months by an approved vendor, while a penetration test is a human exercise that tries to chain findings into a path to cardholder data. If your budget has one and not the other, it is wrong.

How a QSA prices a Report on Compliance

A ROC fee is assessor days multiplied by a day rate, and the day count is driven by how many distinct systems, payment channels, locations and third parties the QSA has to sample. A single-channel e-commerce business with one cloud environment is a very different engagement from a retailer with 400 stores, a call center and a loyalty platform, even at the same transaction volume. That is why published ROC ranges are so wide — the fee is tracking your architecture, not your revenue.

Two practical consequences. First, ask any QSA for their assumed day count and sampling approach before comparing quotes; a cheaper quote is usually a smaller sample, which means more findings surface next year. Second, the first year is always the most expensive. Once the evidence, diagrams and control ownership exist, year two is largely a refresh, and the recurring PCI DSS compliance cost tends to settle at roughly half to two-thirds of year one — provided nothing significant changed in the environment.

Four costs that are missing from most budgets

Four items sit outside the quote and inside the real PCI DSS compliance cost. They are the reason a project that was budgeted at $40,000 lands at $70,000.

  • Internal staff time. Evidence collection, interviews and screenshots are done by your people. On a first ROC this routinely runs to several hundred hours and it is almost never in the business case.
  • Re-scanning. ASV scans must produce a passing result. Failed scans mean remediation and a rescan, and rescans are often billed separately.
  • Non-compliance fees. Card brands fine acquirers, and acquirer contracts pass that through to the merchant. Figures of $5,000 to $100,000 a month are widely reported by acquirers and payment vendors; they are contractual, not published by PCI SSC, so read your merchant agreement rather than an article.
  • Scope creep between assessments. A new payment page, a new call-recording tool or a new third-party integration can pull systems back into scope mid-year and turn next year’s refresh back into a first-year engagement.

Cutting the PCI DSS compliance cost is a scoping exercise

Every meaningful saving comes from having fewer systems in the cardholder data environment, because assessor days, tooling licenses and remediation all scale with that count. The levers, in rough order of return:

  1. Stop storing card data. Tokenization and a hosted payment page move the primary account number out of your environment entirely and can move an e-commerce merchant from SAQ D to SAQ A.
  2. Segment the network. Properly isolated segments take systems out of scope, but segmentation has to be tested, so budget for that test as well as the saving.
  3. Document the scope once, properly. Assessors bill for the time they spend working out what your environment looks like. A current, accurate scope document and data-flow diagram is the cheapest hour you will ever buy. Our guide to PCI DSS scope walks through the categorization.
  4. Pick the right questionnaire. The SAQ you are eligible for is determined by how you accept payments, and the difference between the shortest and longest is enormous. See how the SAQ types compare before you assume you need SAQ D.
  5. Write the policies from templates. Policy drafting is billable consultant time for work that is largely identical between organizations of the same shape.

On that last point: our PCI-DSS Toolkit ships 180+ editable PCI DSS v4.0.1 policies, procedures, registers and evidence forms for $99, which is the single easiest line item in the table above to take from five figures to two. It does not make you compliant — nothing does that except the controls — but it removes the drafting from your critical path.

PCI DSS compliance cost FAQ

Is there a cheapest possible PCI DSS compliance cost?

For a Level 4 e-commerce merchant using a fully hosted, PCI-validated payment page, the realistic floor is quarterly ASV scanning plus your own time — often under $1,000 a year. That only holds if you genuinely never touch card data, and SAQ A has eligibility criteria you have to meet in full, not approximately.

Do I have to hire a QSA?

Only if your acquirer or a card brand requires a ROC, which in practice means Level 1, and sometimes Level 2 by acquirer contract. Everyone else can self-assess. Many mid-sized merchants still buy a few QSA days for a readiness review, which is usually money well spent on a first attempt. Our overview of PCI DSS validation explains who requires what.

How does PCI DSS compliance cost compare with SOC 2 or ISO 27001?

At the small end PCI DSS is usually cheaper, because a self-assessment carries no assessor fee at all, whereas both SOC 2 and ISO 27001 require an external firm from day one. At the Level 1 end it is comfortably the most expensive of the three. For the comparison points, see our breakdowns of SOC 2 cost and ISO 27001 certification cost.

Is the cost annual or one-off?

Annual. An AOC covers a point in time and validation repeats every year, with ASV scanning every three months in between. Treat PCI DSS as an operating cost, not a project, and expect year one to be the outlier.

Where do I check what my assessor or scanning vendor is allowed to do?

The PCI Security Standards Council publishes the current standard, the SAQs and the qualification programs in its Document Library, and maintains the lists of qualified QSA companies and Approved Scanning Vendors. Check a vendor against those lists before signing — an assessment from an unlisted firm is not accepted by your acquirer, and that is the most expensive PCI DSS compliance cost of all.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.