Directory

PCI DSS assessment firms

18 PCI assessment practices, grouped by the buyer type they fit best. Each profile links to the firm's website. We are an independent directory -- not an assessment firm, and these listings are not paid placements or endorsements.

Verify before you engage. Only a PCI SSC-listed QSA company can sign a Report on Compliance. Before signing, confirm the firm's current listing, ask who your assessment team will be, and get the fee in writing with scope boundaries. Our methodology explains exactly how we vet firms and label prices.

Provenance: profiles are compiled from each firm's public materials (September 2026); every price carries a source label. All 18 firm websites were load-verified September 2026 -- the row-level verification log is on our methodology page.

For small merchants

SAQ-eligible businesses: small card volume, price-sensitive, need speed. These firms bundle ASV scanning and SAQ support or run efficient small-merchant practices.

FirmTypeROC planning rangeFieldwork window
SecurityMetricsPCI-focused compliance company$15K–$75K (published planning range (Sept 2026))4–8 wk
ControlCaseCompliance assessment and managed-compliance firm$15K–$75K (published planning range (Sept 2026))4–8 wk
KirkpatrickPriceAssurance specialist$15K–$75K (published planning range (Sept 2026))4–8 wk
MegaplanITPCI-focused assessment firm$15K–$75K (published planning range (Sept 2026))4–8 wk
RSI SecurityCybersecurity and compliance firm$15K–$75K (published planning range (Sept 2026))4–8 wk
CampusGuardPCI assessment firm focused on education, healthcare, and hospitality$15K–$75K (published planning range (Sept 2026))4–8 wk
HALOCKRisk management and security assessment firm$15K–$75K (published planning range (Sept 2026))4–8 wk
TraceSecurityCompliance and security firm$15K–$75K (published planning range (Sept 2026))4–8 wk
Wolf & CompanyRegional accounting and advisory firm with PCI practiceNot published — request a scoped quoteVaries — confirm in proposal
Prescient AssuranceAICPA-accredited assurance firmNot published — request a scoped quoteVaries — confirm in proposal
BARR AdvisoryCloud-native compliance and assessment firmNot published — request a scoped quoteVaries — confirm in proposal
Linford & CompanyCPA firm with PCI assessment practice$30K–$200K (firm-published price)4–12 wk

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

For mid-market merchants and service providers

Growing card volume or multi-location footprints: you need a credible ROC-capable assessor, possibly with adjacent frameworks (SOC 2, ISO 27001) on the roadmap.

FirmTypeROC planning rangeFieldwork window
CoalfireCybersecurity and compliance assessment firm$25K–$150K (published planning range (Sept 2026))4–12 wk
SecurityMetricsPCI-focused compliance company$15K–$75K (published planning range (Sept 2026))4–8 wk
LevelBlue (formerly Trustwave)Managed security services provider with PCI assessment practice$25K–$150K (published planning range (Sept 2026))4–12 wk
ControlCaseCompliance assessment and managed-compliance firm$15K–$75K (published planning range (Sept 2026))4–8 wk
SchellmanIndependent attestation and assessment firm$25K–$150K (published planning range (Sept 2026))4–12 wk
A-LIGNTechnology-enabled compliance firm$20K–$100K (published planning range (Sept 2026))4–10 wk
KirkpatrickPriceAssurance specialist$15K–$75K (published planning range (Sept 2026))4–8 wk
MegaplanITPCI-focused assessment firm$15K–$75K (published planning range (Sept 2026))4–8 wk
360 AdvancedCybersecurity and compliance assessment firm$20K–$100K (published planning range (Sept 2026))4–10 wk
RSI SecurityCybersecurity and compliance firm$15K–$75K (published planning range (Sept 2026))4–8 wk
CampusGuardPCI assessment firm focused on education, healthcare, and hospitality$15K–$75K (published planning range (Sept 2026))4–8 wk
HALOCKRisk management and security assessment firm$15K–$75K (published planning range (Sept 2026))4–8 wk
TraceSecurityCompliance and security firm$15K–$75K (published planning range (Sept 2026))4–8 wk
Wolf & CompanyRegional accounting and advisory firm with PCI practiceNot published — request a scoped quoteVaries — confirm in proposal
Sysnet Global SolutionsGlobal payment-security and compliance companyNot published — request a scoped quoteVaries — confirm in proposal
BARR AdvisoryCloud-native compliance and assessment firmNot published — request a scoped quoteVaries — confirm in proposal
Linford & CompanyCPA firm with PCI assessment practice$30K–$200K (firm-published price)4–12 wk

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

For Level 1 merchants and service providers

ROC-required environments, complex cardholder data environments, or portfolios of merchants -- deep benches, global delivery, and multi-framework breadth.

FirmTypeROC planning rangeFieldwork window
CoalfireCybersecurity and compliance assessment firm$25K–$150K (published planning range (Sept 2026))4–12 wk
LevelBlue (formerly Trustwave)Managed security services provider with PCI assessment practice$25K–$150K (published planning range (Sept 2026))4–12 wk
SchellmanIndependent attestation and assessment firm$25K–$150K (published planning range (Sept 2026))4–12 wk
A-LIGNTechnology-enabled compliance firm$20K–$100K (published planning range (Sept 2026))4–10 wk
360 AdvancedCybersecurity and compliance assessment firm$20K–$100K (published planning range (Sept 2026))4–10 wk
Sysnet Global SolutionsGlobal payment-security and compliance companyNot published — request a scoped quoteVaries — confirm in proposal

Planning ranges are not quotes. See our methodology for how prices are labeled and verified.

All 18 assessor profiles

QSA company

Coalfire

Coalfire is one of the largest PCI assessment practices in the world, performing hundreds of PCI DSS assessments a year for merchants and service providers of every size. Its PCI practice covers Level 1 ROC assessments, SAQ validation, penetration testing, and ASV scanning alongside broader advisory services.

Denver, Colorado · Founded 2001
PCI DSS, SOC 2, ISO 27001, HITRUST, FedRAMP
QSA company

SecurityMetrics

SecurityMetrics grew up as a PCI scanning vendor and built one of the industry's best-known SMB PCI programs: bundled ASV scanning, SAQ guidance, and QSA-led assessments under one roof. It is a practical pick for merchants that want the scanning, the questionnaire, and the assessor from a single vendor.

Orem, Utah · Founded 2000
PCI DSS, SOC 2, HIPAA, GDPR
QSA company

LevelBlue (formerly Trustwave)

Trustwave -- now operating as LevelBlue -- has run one of the longest-standing PCI assessment practices in the industry, paired with its managed detection, SpiderLabs testing, and ASV scanning businesses. A fit for organizations that want assessment plus ongoing managed security from the same relationship.

Chicago, Illinois · Founded 1995
PCI DSS, SOC 2, ISO 27001, HIPAA
QSA company

ControlCase

ControlCase is a PCI-centric assessment firm known for fixed-fee engagements and heavy use of its own compliance technology to keep assessment costs predictable. It serves merchants and service providers across retail, hospitality, and SaaS, with a strong mid-market footprint.

United States (global offices) · Founded 2004
PCI DSS, SOC 2, ISO 27001, HIPAA, HITRUST
QSA company

Schellman

Schellman is a top-50 attestation firm that stakes its name on assessor independence, with a large PCI practice covering Level 1 ROCs for merchants, service providers, and payment facilitators. It also bundles PCI with SOC and ISO work for multi-framework programs.

Tampa, Florida · Founded 2002
PCI DSS, SOC 1, SOC 2, ISO 27001, FedRAMP, HITRUST
QSA company

A-LIGN

A-LIGN runs a high-volume, technology-enabled PCI practice alongside its SOC, ISO, and FedRAMP work. Its pitch is scale and speed: standardized evidence collection and a large assessor bench for merchants and service providers that need predictable delivery.

Tampa, Florida · Founded 2009
PCI DSS, SOC 1, SOC 2, ISO 27001, HITRUST, FedRAMP, CMMC
QSA company

KirkpatrickPrice

KirkpatrickPrice is a Nashville-based assurance specialist with a long-running PCI practice supporting SaaS, managed services, fintech, and healthcare clients. It sits between the boutiques and the global firms, with PCI, SOC, and HITRUST under one roof.

Nashville, Tennessee · Founded Not disclosed
PCI DSS, SOC 1, SOC 2, HITRUST, ISO 27001
QSA company

MegaplanIT

MegaplanIT is a PCI-centric QSA company serving merchants and service providers, with a practice built around ROC assessments, SAQ validation, and remediation guidance. Its narrow PCI focus suits buyers who want assessors that do this work all day, every day.

Scottsdale, Arizona · Founded Not disclosed
PCI DSS, SOC 2, HIPAA
QSA company

360 Advanced

360 Advanced, founded in 2004, delivers integrated assessment, advisory, and testing services across PCI, SOC, ISO, HITRUST, and FedRAMP. Its PCI practice covers Level 1 ROCs and SAQ engagements, useful when PCI is one track of a larger assurance program.

St. Petersburg, Florida · Founded 2004
PCI DSS, SOC 1, SOC 2, SOC 3, ISO 27001, HIPAA, HITRUST, FedRAMP

Comparing firms? Tell us your scope once -- get quotes from your shortlist. Free · 2 minutes · no obligation.

Get matched quotes
QSA company

RSI Security

RSI Security pairs a PCI QSA practice with security testing and advisory services, serving merchants, service providers, and SaaS companies on the West Coast and nationally. It positions for mid-market buyers that need assessment plus hands-on security help.

San Diego, California · Founded 2008
PCI DSS, SOC 2, ISO 27001, HIPAA, NIST
QSA company

CampusGuard

CampusGuard built its name serving colleges, universities, healthcare systems, and hospitality groups -- organizations with sprawling, decentralized card-acceptance footprints. Its PCI practice specializes in multi-location merchants and complex SAQ/ROC scoping.

United States · Founded Not disclosed
PCI DSS, P2PE
QSA company

HALOCK

HALOCK is a long-running risk and security consultancy whose PCI practice serves merchants and service providers in the Midwest and nationally. It is known for its risk-analysis methodology work, which maps well to PCI DSS v4.x targeted risk analyses.

Schaumburg, Illinois · Founded 1996
PCI DSS, SOC 2, ISO 27001, HIPAA, NIST
QSA company

TraceSecurity

TraceSecurity combines a PCI QSA practice with its TraceCSO compliance platform, aimed at community banks, credit unions, and mid-market merchants. The bundled platform-plus-assessor model appeals to organizations that want year-round compliance management, not just an annual assessment.

Baton Rouge, Louisiana · Founded 2004
PCI DSS, SOC 2, HIPAA, GLBA
QSA company

Wolf & Company

Wolf & Company is a century-old New England accounting firm whose technology-risk practice includes PCI DSS assessments for merchants and service providers. A fit for buyers in the Northeast that prefer a regional firm relationship with partner access.

Boston, Massachusetts · Founded 1911
PCI DSS, SOC 1, SOC 2, ISO 27001
QSA company

Prescient Assurance

Prescient Assurance, founded in 2021, positions itself as the security-testing-led assessor for SaaS companies, pairing assessment teams with cloud-native and application-security experience. Its PCI services suit startups that need PCI alongside SOC 2 from one modern firm.

New York, New York · Founded 2021
PCI DSS, SOC 1, SOC 2, SOC 2+, CSA STAR, HIPAA/HITECH, GDPR, ISO 27001
QSA company

Sysnet Global Solutions

Sysnet is one of the largest dedicated PCI compliance companies in the world, serving acquirers, ISOs, and merchants across dozens of countries. Its managed-compliance model is built for portfolios: acquirers and payment facilitators managing PCI across thousands of sub-merchants.

Dublin, Ireland (global offices) · Founded 1989
PCI DSS, P2PE, SOC 2
QSA company

BARR Advisory

BARR Advisory is a cloud-native assessment firm with PCI DSS services alongside its SOC, ISO, and CMMC practices. It fits SaaS and cloud-first companies that want PCI validation from assessors fluent in AWS, Azure, and GCP architectures.

Franklin, Tennessee · Founded Not disclosed
PCI DSS, SOC 1, SOC 2, ISO 27001, ISO 27701, ISO 42001, CMMC
QSA company

Linford & Company

Linford & Company is a Denver CPA firm whose PCI practice is unusually transparent about money: it publishes that a PCI audit resulting in a ROC typically runs $30,000–$200,000, and that QSA-assisted SAQ assessments can run up to $40,000. That candor makes it a useful benchmark when comparing quotes.

Denver, Colorado · Founded Not disclosed
PCI DSS, SOC 1, SOC 2

How we built this directory

Read the full methodology →

Get matched with the right assessor

Answer four quick questions and receive quotes from firms that fit your size, scope, and timeline.

Get a free quote