Photo: Unsplash
If your business accepts card payments, PCI DSS applies to you, and sooner or later your acquiring bank, payment processor, or an enterprise customer will ask you to prove compliance. The cost of that proof ranges from almost nothing for a small merchant using a hosted checkout to six figures for a large service provider. This guide explains what drives PCI DSS costs, what each validation path costs, and how to cut the bill by shrinking your scope.
Key takeaways
- There is no single "PCI certification". You validate compliance each year, either with a Self-Assessment Questionnaire (SAQ) or a Report on Compliance (ROC) completed by a Qualified Security Assessor (QSA).
- Your merchant or service provider level decides the validation path. High-volume merchants and service providers need a QSA-led ROC. Smaller merchants usually complete an SAQ.
- Scope is the biggest cost driver. The more systems store, process, or transmit cardholder data, the more controls, testing, and assessor time you pay for.
- Recurring costs are part of the price. Quarterly external vulnerability scans by an Approved Scanning Vendor (ASV), annual penetration tests, and ongoing evidence continue every year.
- Outsourcing card handling can cut costs dramatically. Hosted payment pages and tokenization can move a merchant to the shortest SAQ.
How PCI DSS validation works
PCI DSS is maintained by the PCI Security Standards Council. The current version is PCI DSS v4.0.1, and the requirements that were future-dated in v4.0 became mandatory on March 31, 2025.
The Council sets the standard, but the card brands and your acquiring bank decide how you must validate. That depends on your level:
| Level | Merchants (typical card brand thresholds) | Usual validation |
|---|---|---|
| Level 1 | Over 6 million transactions per year for a card brand | Annual ROC by a QSA (or qualified internal auditor), plus quarterly ASV scans |
| Level 2 | 1 to 6 million transactions per year | SAQ, and some acquirers require a ROC |
| Level 3 | 20,000 to 1 million e-commerce transactions per year | SAQ |
| Level 4 | Fewer than 20,000 e-commerce transactions, or up to 1 million total | SAQ, as required by the acquirer |
Service providers that store, process, or transmit cardholder data for others are Level 1 above 300,000 transactions per year, which requires a ROC. Below that, they complete SAQ D for service providers. Exact thresholds vary slightly by card brand, so confirm with your acquirer.
PCI DSS cost breakdown
The ranges below are typical market figures. Your quotes will vary with scope, number of locations, and how ready you are.
| Cost item | What it covers | Typical range |
|---|---|---|
| SAQ completion | Self-assessment, often done in house | Staff time, or $2,000 to $10,000 with outside help |
| QSA-led ROC | Annual on-site or remote assessment for Level 1 | Often $15,000 to $70,000+, rising with scope and complexity |
| Readiness or gap assessment | A pre-assessment to find gaps before the real one | $5,000 to $25,000 |
| ASV scans | Quarterly external vulnerability scans | A few hundred to a few thousand dollars per year |
| Penetration testing | Required annually and after significant changes, including segmentation testing | $5,000 to $30,000+ per year |
| Remediation | Closing gaps such as MFA, logging, encryption, secure configuration | Varies widely |
| Security tooling | Logging and monitoring, file integrity monitoring, endpoint protection, vulnerability scanning | Varies with environment size |
| Policies and training | Written policies and annual security awareness training | Low if you use templates and automation |
| Compliance software | Evidence collection and control monitoring | Roughly $5,000 to $30,000+ per year |
For a small e-commerce merchant using a hosted payment page, annual costs can be close to zero beyond SAQ A and good hygiene. For a Level 1 service provider, first-year costs commonly reach six figures once assessment, testing, tooling, and staff time are counted.
What drives PCI DSS costs
- Scope of the cardholder data environment (CDE). Every system that stores, processes, or transmits card data, and every system connected to it, is in scope unless segmented.
- Whether you store card data at all. Storing primary account numbers brings requirement 3 in full, with encryption and key management.
- Your level and validation path. A ROC costs more than an SAQ, and SAQ D costs more effort than SAQ A.
- Network segmentation. Proper segmentation reduces scope, but it must be tested at least annually (every six months for service providers).
- PCI DSS v4 requirements. Controls that became mandatory in 2025, such as broader MFA for CDE access, script management on payment pages, targeted risk analyses, and authenticated internal scanning, have added effort for many organizations.
- Multiple locations and channels. Card-present, e-commerce, and call center channels each bring their own scope.
How to reduce PCI DSS costs
- Do not store card data. If you do not need it, do not keep it. Use tokens from your processor instead.
- Use a hosted payment page or iframe. Fully outsourcing card capture to a PCI-compliant processor can qualify an e-commerce merchant for SAQ A, the shortest questionnaire.
- Use validated point-to-point encryption (P2PE) for card-present payments where possible, which can qualify you for SAQ P2PE.
- Segment the CDE. Keep card data systems isolated so the rest of your network stays out of scope.
- Automate evidence collection. Logs, access reviews, configuration checks, and scans captured continuously cost less than evidence reassembled for the assessor.
- Reuse work from other frameworks. SOC 2 and ISO 27001 controls overlap heavily with PCI DSS requirements for access, logging, vulnerability management, and incident response.
- Get a readiness assessment before a ROC. Finding gaps before the QSA arrives avoids paying for repeat testing.
For a requirement-by-requirement plan, see our PCI DSS compliance checklist.
How SecureSlate helps
SecureSlate's PCI DSS program combines compliance software with a dedicated compliance lead for one fixed price:
- Your compliance lead scopes your cardholder data environment and identifies ways to reduce it.
- They prepare your SAQ or support your Report on Compliance, and close the gaps along the way.
- The platform maps your controls to PCI DSS v4.0.1 and collects evidence continuously from the tools you already use.
- Security scanning of your code, cloud configuration, and domains evidences vulnerability management and secure development.
FAQ
How much does PCI DSS certification cost?
For small merchants that complete an SAQ, costs can be minimal beyond staff time, scans, and basic security tooling. For Level 1 merchants and service providers that need a QSA-led Report on Compliance, the assessment alone often costs $15,000 to $70,000 or more, with testing, tooling, and remediation on top.
Is PCI DSS compliance mandatory?
PCI DSS is not a law, but it is required by the card brands through your contract with your acquiring bank or payment processor. Non-compliance can lead to fines passed down from the card brands, higher processing fees, or losing the ability to accept cards.
How much does a PCI QSA assessment cost?
A QSA-led Report on Compliance commonly costs from about $15,000 for a small, well-scoped environment to well over $70,000 for complex environments with many systems and locations. Quotes depend on scope, the number of sites, and your readiness.
How often do I need to pay for PCI compliance?
Every year. Validation through an SAQ or ROC is annual, ASV scans are quarterly, and penetration tests are annual and after significant changes. Ongoing controls such as logging and access reviews run continuously.
What is the cheapest way to become PCI compliant?
Avoid touching card data. Use a hosted payment page or tokenization from a PCI-compliant processor so card data never enters your systems, which can reduce your obligations to SAQ A.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory, or professional advice. Validation requirements are set by the card brands and your acquirer and may differ from the typical thresholds shown. Cost ranges are indicative market estimates. Consult your acquirer and qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
