How much does a PCI DSS assessment cost?
The honest answer: it depends on your merchant level, your cardholder data environment, and your starting maturity -- but published ranges are narrower than most vendors admit. Start with the estimator, then see what drives the number.
Published 2025–2026 sources put a Level 1 Report on Compliance fee between $20,000 and $200,000+, with mid-size engagements most often quoted $20,000–$100,000 (our synthesis of the cited sources below). QSA-assisted SAQ engagements run $3,000–$15,000. First-year all-in program costs -- assessment plus remediation, tooling, and staff time -- typically run far higher; see every figure below with its source.
PCI cost estimator
How this estimate is calculated (formula & assumptions)
Assessment-fee bands by merchant level are derived from published 2025–2026 ranges: Level 1 ROC $20k–$200k+ (Accorp, Linford, TrustNet, UnderDefense, ValueMentor, Centraleyes); SAQ with QSA guidance $3k–$15k (Accorp). SAQ path = ~25–35% of the ROC fee. Each location past the first adds ~15% (multi-site sampling). ASV scanning: $500–$2,000/yr (Akurateco, Basis Theory). Pen testing $5k–$30k for Level 1 ROCs (Akurateco, UnderDefense). Remediation: 50–100% of the assessment fee -- the swing factor (UnderDefense notes remediation, tooling, and labor are 60–70% of total spend). Internal staff time excluded.
Worked example (no JavaScript needed)
A Level 2 merchant with 3 locations, pursuing QSA-assisted SAQ, with some controls in place:
- Assessment fee: $2,500–$5,250 (SAQ band $3k–$15k scaled to ~25–35% of ROC band, +30% for 3 locations)
- ASV scanning: $500–$2,000/year
- Remediation: 50–100% of assessment fee → $1,250–$5,250
- Total: roughly $4,250–$12,500, excluding internal staff time.
Bands are derived from the published sources cited below -- see the formula disclosure above for the exact math.
Your estimate is a starting point. Estimates use published planning ranges (sources: 2026 pricing report). A scoped quote is what a firm actually charges you -- get 2–3 and compare.
Get scoped quotesCost by certification path
Your path is the first cost decision -- bigger than which firm you pick. Published planning ranges per path:
| Path | Assessment fee (published range) | Typical first-year all-in |
|---|---|---|
| SAQ self-assessment | $3K–$15K (QSA-guided) | $5K–$25K |
| QSA-led readiness | $10K–$40K (planning estimate) | $15K–$60K incl. remediation start |
| Full ROC | $20K–$200K+ | $50K–$500K+ (remediation is 60–70%) |
The readiness row is the one buyers skip and regret: a $25K readiness engagement routinely saves multiples of itself in avoided re-testing and deadline-driven remediation. Compare the paths.
PCI cost by merchant level
The single most-asked cost question is level-keyed: what does it cost for a merchant like us? The table below gives planning estimates interpolated from the published ranges above -- not quotes, and not measured averages. See the pricing report for every underlying source.
| Merchant level | Assessment fee | Scans + testing | First year, all in |
|---|---|---|---|
| Level 4 (small e-commerce) | $3K–$10K (SAQ) | $0.5K–$2K | $5K–$25K |
| Level 3 (mid e-commerce) | $5K–$15K (SAQ) | $1K–$5K | $15K–$60K |
| Level 2 (1M–6M txns) | $10K–$50K | $2K–$15K | $40K–$200K |
| Level 1 (6M+ txns) | $25K–$200K+ (ROC) | $5K–$100K | $150K–$500K+ |
What drives the fee
- CDE scope. Every system, location, and application touching cardholder data adds assessor hours. Segmentation is the biggest cost lever you control.
- Merchant level and validation path. A ROC is a full on-site assessment; an SAQ is a guided questionnaire. The fee difference is 3–4x.
- Starting maturity. Missing MFA, logging, or policies means remediation before the assessor can pass you -- and remediation is billed by someone.
- Service providers. Each provider in scope needs its AOC reviewed; non-compliant providers expand your assessment.
- v4.x new requirements. Script inventory (6.4.3), payment-page tamper detection (11.6.1), and targeted risk analyses (12.3.2) are now fully enforced -- budget for them.
Cost questions
What is the average cost of a PCI DSS ROC assessment?
Published sources cluster a Level 1 ROC fee between $20,000 and $200,000+, with most mid-size engagements quoted $20,000–$100,000. First-year all-in program costs (assessment + remediation + tooling + staff) run far higher -- one 2026 source puts Level 1 year-one totals at $200,000–$1M.
Is an SAQ cheaper than a ROC?
Dramatically. QSA-assisted SAQ engagements run roughly 25–35% of a ROC fee: published ranges put SAQ support at $50–$10,000 and QSA-guided SAQs at $3,000–$15,000. But you only get to choose SAQ if your merchant level and acquirer allow it.
What drives PCI cost up the most?
Scope. The size and complexity of your cardholder data environment (CDE) -- locations, systems, applications, service providers -- plus your starting maturity. Network segmentation that shrinks the CDE is the single biggest cost lever.
How much does PCI cost for a small e-commerce store?
Planning estimate: roughly $5,000–$25,000 all-in for the first year (SAQ support, ASV scans, tooling, modest remediation). This is our estimate interpolated from published ranges -- get scoped quotes for your actual situation.
How much does a Level 1 ROC cost for a large merchant?
Planning estimate: roughly $150,000–$500,000+ all-in for the first year, with the QSA fee alone typically $25K–$150K and remediation the biggest line item. Complex multi-location environments go higher.
Do costs drop after the first year?
Yes. Once scoping, segmentation, tooling, and evidence habits exist, renewal assessments are mostly the annual assessor fee plus scans and testing -- many programs report 30–50% lower year-two costs.
Sources
- Linford & Company — “What is the cost of a PCI DSS assessment?”
ROC: $30k–$200k (fee depends on CDE scope and complexity) · QSA-assisted SAQ: time-and-material or fixed fee up to $40k - Accorp Partners — PCI QSA Services FAQ
SAQ with QSA guidance: $3,000–$15,000 · Full Level 1 ROC: $20,000–$70,000+ - UnderDefense — “PCI DSS Audit Preparation and Automation: Checklist, Tools, and Cost Breakdown for 2026”
Level 1 year-1 total: $200K–$1M · QSA-led ROC: $30K–$200K · Pen testing: $15K–$75K · Tooling: $20K–$100K/yr - Akurateco — “PCI DSS Cost: Pricing Breakdown and Budgeting Guide”
SAQ support: $50–$10,000 · QSA/ROC assessment: $15,000–$100,000 · ASV scans: $100–$500/quarter · Pen test: $5,000–$30,000 - Basis Theory — “PCI Compliance Levels”
Level 1 assessment: $20,000–$75,000/yr · Quarterly scans: $500–$5,000/yr · Pen test: $5,000–$20,000/yr - ValueMentor — “What Is a QSA and Why Do You Need One for PCI DSS?”
Average-complexity QSA assessment: $20,000–$30,000 · Level 1 on-site: $40,000–$70,000 · Large enterprise: $100,000+ - TrustNet — “PCI DSS Compliance Costs & Budgeting Guide (Part 3)”
Level 1 on-site QSA-led ROC: $25,000–$100,000+ - Centraleyes — “How Much Does PCI DSS Compliance Cost in 2025?”
Level 1 QSA audit: $50,000–$150,000 - Compyl — “How Much Does PCI Compliance Cost?”
Basic QSA assessment: ~$15,000 · Complex/large-enterprise: $100,000+ - RedSecLabs — PCI DSS QSA Company FAQ
SAQ consultancy: £8,000–£35,000/yr · ROC: £35,000–£150,000+ (fixed-fee after scoping)
Get your own number
Published ranges are a starting point. Get scoped quotes from QSA firms for your actual environment.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.