How much does PCI DSS cost?
Researched PCI DSS validation fee ranges by path, from self-completed SAQs through QSA-led ROC assessments, plus the remediation and operating costs around them.
The short version
PCI DSS validation cost depends almost entirely on which validation path your acquirer or payment brand assigns you:
- Self-completed SAQ: no assessor fee. Where the SAQ requires ASV scanning, a scanning service typically costs a few hundred dollars a year.
- QSA-validated SAQ: commonly $5,000 to $40,000 for an assessor to review or sign the questionnaire.
- QSA-led ROC: typically $25,000 to $60,000 for most assessed organizations. Large or multi-site environments run into six figures.
Those figures are validation fees only: what you pay external parties for the assessment plus the scanning and testing the standard requires. Remediation, tooling, and internal labor are separate, and they are frequently the larger cost.
The fee by validation path
Self-completed SAQ. Most merchants validate this way. The questionnaire itself is free, and the external spend is limited to what your SAQ requires: quarterly ASV scans for several SAQ types (typically a few hundred dollars a year from a scanning vendor), and penetration testing for SAQ D and some others ($3,000 to $30,000 depending on scope). A merchant on SAQ A with a fully hosted checkout may pay nothing at all.
QSA-validated SAQ. Some acquirers, partners, or internal policies require a Qualified Security Assessor to review or sign the SAQ. Practicing QSA firms describe these engagements as time-and-materials or fixed fees up to about $40,000, with simpler SAQ types at the low end.
QSA-led ROC. A full assessment producing a Report on Compliance. For the large majority of assessed organizations, the fee lands between $25,000 and $60,000, driven by the size of the cardholder data environment, the number of sites and payment channels, and how much of the environment is in scope. QSA firms publish ranges reaching $200,000, and multinational or multi-site environments genuinely get there, but those are enterprise engagements, not the typical case. Renewal assessments usually cost less than a first ROC because the scope is already documented.
No QSA firm publishes a rate card, so treat every published range, including this one, as orientation. The reliable way to budget is a fixed-fee proposal after a scoping call, and the useful comparison across proposals is the assumed day count and day rate.
What else you will spend
The validation fee is often the smallest of three buckets:
- Remediation: replacing or reconfiguring systems, changing payment architecture, and fixing findings. For an organization with real gaps, this routinely exceeds the assessment fee.
- Mandated and supporting security work: ASV scans, penetration tests, segmentation testing, monitoring and logging tooling.
- Operations: running the controls year-round, gathering evidence across teams, and repeating failed tests. Internal effort for a typical ROC organization commonly runs 100 to 600 hours in a first cycle; SAQ-only organizations usually spend far fewer.
The cheapest PCI project is usually a scoping project: hosted payment pages, tokenization, and segmentation can shrink the environment the fee is calculated on. See Which PCI SAQ do I need? and What is a QSA-validated SAQ?
What moves the number
- Required validation method: SAQ type, QSA-validated SAQ, or ROC
- Size and complexity of the cardholder data environment
- Payment channels, locations, service providers, and system connections
- Security maturity and the amount of remediation required
- Required scanning, penetration testing, and ongoing monitoring
How we estimate these figures
Cost figures on this site follow one definition so that standards stay comparable: the range covers external validation fees only for the standard’s most common audited path, spanning roughly the middle 80% of organizations on that path. Lighter paths and outliers appear as scenarios and in prose rather than being blended into the headline. Ranges are directional, not quotes. The full definition is in How we estimate cost and effort.
Sources
Industry
PCI compliance audits and assessments · Linford & Company (QSA firm), accessed 2026-09
- QSA-led ROC: $30,000 to $200,000
- QSA-assisted SAQ: time-and-materials or a fixed fee up to $40,000
Published by a practicing QSA firm. The ROC range includes large enterprise engagements above our typical band; corroborates the SAQ scenario.
PCI DSS compliance cost breakdown · SISA, accessed 2026-09
- SAQ completion and validation: $5,000 to $20,000
- QSA-led ROC: $35,000 to $200,000
- Penetration testing: $3,000 to $30,000
Global PCI assessor. Corroborates the SAQ scenario and mandated-testing figures; the ROC high end reflects enterprise engagements above our typical band.
Firsthand
Aeris Secure assessment experience · Aeris Secure, accessed 2026-09
QSA engagement pricing and internal-hours experience from PCI assessment work. Anchors the typical ROC range and the effort hours; published QSA ranges skew toward enterprise tails.
How these sources become the ranges on this site is described in How we estimate cost and effort.
Published September 1, 2026. Updated September 3, 2026.