FAQ

PCI certification frequently asked questions

Straight answers about the certification paths -- SAQ, readiness, ROC -- and how to navigate them.

Is PCI DSS actually a certification?

Strictly speaking, no -- it's a validation: a Report on Compliance (ROC) or Self-Assessment Questionnaire (SAQ) plus an Attestation of Compliance (AOC), renewed annually. In practice the market treats it like a certification: ‘PCI certified’ means ‘we hold a current, validated AOC.’ This site uses the industry's language while staying precise about what each path produces.

Which certification path do I need -- SAQ, readiness, or ROC?

Your acquirer decides what validation you owe them; you decide how to get there. Level 1 merchants (6M+ transactions/year) and most service providers need a QSA-led ROC. Smaller merchants usually self-assess with an SAQ. Anyone facing a first ROC should consider a readiness assessment first. See our path comparison.

What does the SAQ path involve, step by step?

One: confirm your SAQ type (A, A-EP, B, B-IP, C, C-VT, D, or P2PE) with your acquirer in writing. Two: complete the questionnaire honestly against your environment. Three: run quarterly ASV scans and remediate failures. Four: sign and submit the SAQ and AOC. Many merchants hire a QSA to validate the SAQ -- a few thousand dollars for assurance an acquirer trusts. Which SAQ type are you?

What does the readiness path involve?

A QSA reviews your environment against the requirements, tests your evidence, and delivers a gap report with a remediation roadmap -- no pass/fail, no signed report. Typical: 4–8 weeks. Its product is a fix list that makes the subsequent ROC (or SAQ D) dramatically smoother.

What does the ROC path involve, step by step?

One: scoping with your QSA (locations, systems, applications, service providers). Two: evidence collection against every applicable requirement. Three: fieldwork -- the QSA tests controls and samples locations. Four: remediation of findings and re-testing. Five: the signed ROC and AOC. Expect 3–6 months end to end for a first ROC. Full timeline.

How much does each certification path cost?

Published ranges: SAQ with QSA guidance $3K–$15K; readiness assessments roughly $10K–$40K; Level 1 ROC $20K–$200K+ depending on scope. Remediation typically adds 60–70% on top of the assessment fee in year one. See the cost guide.

How long does each path take?

SAQ validations: 4–12 weeks. QSA-led readiness: 4–8 weeks. Full ROC: 3–6 months from scoping to signed report, including 4–12 weeks of fieldwork.

Who can perform each step?

Only a PCI SSC-listed QSA company can sign a ROC. ASV scans must come from an Approved Scanning Vendor. SAQs are self-assessments -- but a QSA can validate them. Readiness can come from a QSA practice or an independent readiness consultant; many buyers deliberately separate readiness from the validating QSA to preserve independence.

What is a QSA vs a QSAC?

A QSA (Qualified Security Assessor) is the certified individual; a QSAC (QSA Company) is the firm authorized by the PCI SSC to perform assessments. When people say ‘hire a QSA,’ they mean engage a QSAC.

What happens if we fail the assessment?

You don't ‘fail’ permanently -- findings must be remediated before the QSA can issue a passing ROC or validated SAQ. You get time to fix gaps and the assessor re-tests (re-testing fees should be in your engagement letter). This is exactly why readiness assessments exist: finding gaps early is far cheaper.

Can we switch paths mid-journey?

Yes. A common upgrade: SAQ D validated by a QSA this year, readiness next year, full ROC the year after as volume grows. Your acquirer must accept each step's validation -- confirm in writing before changing.

Do we need penetration testing and ASV scans on every path?

ASV scans: yes on effectively every path -- quarterly external scans are required for SAQ and ROC alike (roughly $100–$500/quarter published). Pen testing: required annually for ROC (requirement 11.4); SAQ merchants need it only where their SAQ type and environment trigger it. Published pen-test ranges: $5,000–$30,000.

What changed in PCI DSS v4.0.1 that affects our path?

The 47 previously future-dated requirements became mandatory March 31, 2025: payment-page script inventory (6.4.3), tamper detection (11.6.1), MFA for all CDE access (8.3.6), and targeted risk analyses (12.3.2). Every path -- SAQ included -- must now cover them where applicable.

How do we choose a QSA firm?

Confirm the firm is a PCI SSC-listed QSA company, ask who your assessment team is, whether the fee is fixed and what breaks it, how multi-location sampling works, and whether you can speak to two reference clients your size. Our process guide walks through selection.

Can one firm handle PCI plus SOC 2 or ISO 27001?

Yes -- firms like Schellman, A-LIGN, 360 Advanced, BARR Advisory, and KirkpatrickPrice run combined programs where one evidence set feeds multiple reports, often at lower total cost than separate engagements.

How often must certification be renewed?

Annually. The AOC is valid one year from signing; ASV scans, pen testing, and the assessment or SAQ repeat every year. Treat it as a program, not a project.

We were told we need PCI certification for an enterprise deal -- where do we start?

First, get the exact requirement in writing: ROC or SAQ, and by when. Second, take our path quiz. Third, if it's a ROC and your first, budget a readiness assessment before fieldwork. Then get competing quotes -- we'll match you with assessors.

Does this site perform assessments?

No. We are an independent directory and quote-matching service -- not an auditor or certification body. Assessments must be performed by qualified assessors; only a PCI SSC-listed QSA company can sign a Report on Compliance.

Still have questions?

Talk to matched assessors directly -- describe your situation once, get path-appropriate quotes.

Get a free quote