Independent PCI certification guide

Which PCI certification path is yours?

Getting ‘PCI certified’ means one of three things: a self-assessed SAQ, a QSA-led readiness assessment, or a full ROC audit. Picking the wrong path wastes months and tens of thousands of dollars. We’ll help you pick the right one -- then match you with Qualified Security Assessors who fit. Free. Two minutes. No obligation.

Free · 2 minutes · No obligation

3Certification paths: SAQ, readiness, ROC
$3k–$200k+Published cost range across paths
4 wk–6 moTimeline range, path-dependent
QSA onlyOnly a Qualified Security Assessor signs a ROC

How quote matching works

  1. Tell us once — 4 questions, 2 minutes, free.
  2. We match you — licensed CPA firms filtered to your size, scope, and timeline.
  3. Auditors quote you — they send scoped quotes directly; you pick.
The three paths

SAQ self-assessment, QSA-led readiness, or full ROC

Every PCI certification journey follows one of these paths. Your merchant level, acquirer requirements, and risk tolerance decide -- not your preference.

1. SAQ self-assessment

You complete the right Self-Assessment Questionnaire and quarterly scans yourself. Cheapest and fastest -- when your acquirer accepts it. Many merchants still hire a QSA to validate the SAQ.

Typical: $3K–$15K · 4–12 weeks

2. QSA-led readiness

A QSA runs a pre-assessment: gap analysis, evidence review, remediation plan. No signed report -- but the ROC that follows goes dramatically smoother.

Typical: $10K–$40K · 4–8 weeks

3. Full ROC assessment

A Qualified Security Assessor tests every requirement and signs your Report on Compliance. Required for Level 1 merchants and most service providers.

Typical: $20K–$200K+ · 3–6 months

Full path comparison →  ·  Take the 2-minute path quiz →

Assessor directory

QSA firms for every path

18 verified PCI assessment firms -- from SMB-friendly SAQ validators to global ROC practices. Independent directory: listings are not endorsements, and firms can’t pay for placement.

QSA company

Coalfire

Coalfire is one of the largest PCI assessment practices in the world, performing hundreds of PCI DSS assessments a year for merchants and service prov…

Denver, Colorado · Cybersecurity and compliance assessment firm (QSA company)
QSA company

SecurityMetrics

SecurityMetrics grew up as a PCI scanning vendor and built one of the industry's best-known SMB PCI programs: bundled ASV scanning, SAQ guidance, and …

Orem, Utah · PCI-focused compliance company (QSA company and ASV)
QSA company

LevelBlue (formerly Trustwave)

Trustwave -- now operating as LevelBlue -- has run one of the longest-standing PCI assessment practices in the industry, paired with its managed detec…

Chicago, Illinois · Managed security services provider with PCI assessment practice (QSA company)
QSA company

ControlCase

ControlCase is a PCI-centric assessment firm known for fixed-fee engagements and heavy use of its own compliance technology to keep assessment costs p…

United States (global offices) · Compliance assessment and managed-compliance firm (QSA company)

See all 18 firms →

Start here

Certification guides

The 3 PCI Certification Paths

SAQ self-assessment, QSA-led readiness, or full ROC -- which one your business actually needs.

PCI Certification Cost Guide

What each path costs: published SAQ, readiness, and ROC fee ranges plus an estimator.

Certification Timeline

How long each path takes, from first scoping call to signed attestation.

Which Path Fits You?

A 2-minute quiz that points you at the right certification path.

The 12 PCI DSS Requirements

What assessors test -- the same 12 requirements behind every path.

SAQ Types Explained

SAQ A, A-EP, B, B-IP, C, C-VT, D, P2PE -- which questionnaire is yours.

2026 Pricing Report

Every published PCI cost figure we could find, each with its source.

Certification Guides

Step-by-step explainers for the whole certification journey.

Best QSA Firms by Use Case

Buyer-matched picks for each certification path.

Our Methodology

How we vet firms, label every price, and keep rankings unbought.

Common questions

PCI certification basics

What is PCI compliance certification?

There is no single certificate issued by the card brands. ‘PCI certification’ means validating your compliance with PCI DSS -- either by self-assessing with the right SAQ or by hiring a Qualified Security Assessor for a Report on Compliance (ROC). Your acquirer decides which path you take.

Which certification path do I need -- SAQ, readiness, or ROC?

Level 1 merchants (6M+ transactions/year) and most service providers need a QSA-led ROC. Smaller merchants usually self-assess with an SAQ -- and many hire a QSA for a readiness assessment first so the real thing goes smoothly. Our paths guide and 2-minute quiz sort it out.

How much does PCI certification cost?

It depends on the path: SAQ self-assessments run a few thousand dollars with QSA guidance; readiness assessments sit in between; a Level 1 ROC runs $20,000 to $200,000+ in published ranges. See the cost guide.

How long does PCI certification take?

SAQ validations: 4 to 12 weeks. QSA-led readiness: 4 to 8 weeks. Full ROC: 3 to 6 months from scoping to signed report. Details on the timeline page.

All frequently asked questions →

Get quotes from PCI QSA firms

Tell us your path and timeline once. We’ll match you with assessors who fit -- no obligation, no spam.

Get a free quote