The core decision

The 3 PCI certification paths, compared

‘PCI certification’ isn’t one thing. It’s three different journeys with different costs, timelines, and levels of assurance. Here’s how to tell which one is yours.

Level 1 merchants and most service providers must take the ROC path with a QSA. Smaller merchants usually take the SAQ path -- self-assessed, sometimes QSA-validated. Anyone facing their first ROC should consider the readiness path first.

SAQ self-assessmentQSA-led readinessFull ROC
What it isYou complete the right SAQ + quarterly scansQSA gap analysis & remediation plan -- no signed reportQSA tests everything, signs your Report on Compliance
Who it’s forLevel 2–4 merchants whose acquirer accepts SAQFirst-time ROC candidates; complex SAQ D environmentsLevel 1 merchants; most service providers
Typical cost$3K–$15K$10K–$40K$20K–$200K+
Typical timeline4–12 weeks4–8 weeks3–6 months
DeliverableSigned SAQ + ASV scan reportsGap report & remediation roadmapSigned ROC + Attestation of Compliance
Assessor required?No -- but QSA validation is commonYes, a QSA practiceYes, a QSA company
Confirm your required validation first. Before spending anything, get your acquirer’s validation requirement in writing. The most expensive mistake in PCI is buying a ROC when an SAQ would do.

Path 1: SAQ self-assessment

The Self-Assessment Questionnaire route. You determine your SAQ type (A, A-EP, B, B-IP, C, C-VT, D, or P2PE), complete it honestly, run quarterly ASV scans, and submit to your acquirer. Cost stays low because you’re doing the work -- but the liability for a wrong answer is yours. Many merchants hire a QSA to validate the SAQ: a few thousand dollars for assurance your acquirer trusts. Which SAQ type are you? →

On the SAQ path? Get QSA-validated SAQ quotes from matched firms. Free · 2 minutes.

Get SAQ quotes

Path 2: QSA-led readiness

A readiness (or gap) assessment is a dry run: a QSA reviews your environment against the requirements, tests your evidence, and hands you a remediation roadmap -- without the pass/fail pressure of a formal assessment. For first-time ROC candidates it’s the highest-ROI spend in PCI: findings fixed now cost a fraction of findings fixed under ROC fieldwork deadlines. Budget 4–8 weeks and treat the roadmap as your project plan.

Path 3: Full ROC assessment

The Report on Compliance: a QSA company tests every applicable requirement across your cardholder data environment, samples your locations, and signs the ROC and Attestation of Compliance. It’s the most rigorous path -- and the only one Level 1 merchants and most service providers can take. Expect 3–6 months from scoping to signed report. See the full timeline →

On the ROC path? Get competing ROC quotes from matched QSA firms. Free · 2 minutes.

Get ROC quotes

Path questions

Can I choose my path, or does someone decide for me?

Your acquirer (and the card brands, for Level 1) decide what validation you owe them. You choose how to get there -- self-assessed SAQ, QSA-validated SAQ, or readiness-then-ROC. Never pay ROC prices for an SAQ requirement: confirm your required validation in writing first.

Is a readiness assessment worth it before a ROC?

Usually, yes -- if your environment hasn’t been assessed before. Readiness finds the gaps a ROC would fail you on, while fixes are cheap. First-time ROCs without readiness fail or stall far more often.

Can a QSA do my SAQ for me?

A QSA can guide, validate, and co-sign your SAQ process -- common for SAQ D and for merchants whose acquirer wants independent validation. The questionnaire is still ‘self’-assessment; the QSA adds assurance your acquirer trusts.

→ Not sure? Take the 2-minute path quiz  ·  Cost by path

Tell us your situation -- we’ll point you at the right path

One short brief. Matched assessors reply with path-appropriate quotes. Free, no obligation.

Get a free quote