The PCI Certification Process, Step by Step
Most PCI guides start with the requirements. That's backwards. The process starts with a letter from your acquirer and ends with an annual program -- here's every step in between.
Step 1: Confirm what you owe
Before anything else, get your validation requirement in writing from your acquirer: ROC or SAQ, which SAQ type, and the deadline. Merchant level follows transaction volume (Level 1: 6M+/year needs a QSA-led ROC), but acquirers can and do require more than the minimum. The most expensive mistake in PCI is buying a ROC when an SAQ would do -- or submitting an SAQ your acquirer rejects.
Step 2: Pick your path
Three paths: SAQ self-assessment (you do the work, cheapest), QSA-led readiness (a dry run with a gap list, no signed report), or full ROC (a QSA tests everything and signs). Your volume, service-provider status, and acquirer letter decide. Compare the three paths or take the 2-minute path quiz.
Step 3: Scope the environment
Inventory every place card data lives, moves, or is processed: systems, applications, locations, people, and service providers. Draw the data flows. Then shrink the scope -- segment the cardholder data environment (CDE) off from everything else, outsource what you can, and stop storing what you don't need. Scoping is where PCI budgets are won or lost: every system in scope gets tested.
Step 4: Close the gaps
Run a gap analysis against the 12 requirements (yourself, or as a formal readiness assessment). The usual suspects: MFA not enforced everywhere (8.3.6), payment-page scripts uninventoried (6.4.3), logging gaps (10), patching lag (6), and missing risk analyses (12.3.2). Fix now, while fixes are cheap -- remediation under assessment deadlines costs multiples.
Step 5: The assessment
On the SAQ path: complete the questionnaire honestly, run quarterly ASV scans, document everything. On the ROC path: your QSA collects evidence, interviews staff, tests controls, and samples locations over 4–12 weeks of fieldwork. Cooperate fully -- an assessor fighting for evidence bills more hours and finds less charity in gray areas.
Step 6: Remediation and re-testing
Findings are normal, even in mature programs. You get time to remediate; the assessor re-tests. Make sure re-testing terms and fees are in your engagement letter before fieldwork starts -- surprise re-test billing is a classic dispute.
Step 7: Submit and attest
The deliverable: a signed ROC or SAQ plus the Attestation of Compliance (AOC), submitted to your acquirer (and to partners who demand it, if you're a service provider). The AOC is valid for one year from signing.
Step 8: Operate the program
PCI is annual: ASV scans quarterly, pen testing yearly, policies reviewed, access re-certified, and the whole validation repeated. The organizations that treat it as a continuous program spend less every year than the ones that re-learn it each cycle. How renewal works.
Starting the process? Tell us your situation once -- matched assessors reply with path-appropriate quotes. Free · 2 minutes.
Get matched quotesQuestions
How long does the whole process take?
SAQ path: 4–12 weeks. Readiness: 4–8 weeks. First ROC: 3–6 months end to end. See our timeline breakdown by path.
Can we do steps out of order?
You can start scoping and gap-closing before your path is final, but never sign an assessment engagement before your acquirer confirms your required validation in writing.
Related reading
Get quotes from PCI QSA firms
Tell us about your environment once -- matched assessors reply with scoped quotes. Free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.