PCI DSS guides & explainers
Practical, source-backed guides to PCI costs, timelines, QSA selection, and assessment prep — written for the person who has to get it done.
ROC vs SAQ: Do You Actually Need a QSA On Site?
The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.
How to Choose a PCI QSA Company: 11 Questions Before You Sign
What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.
PCI DSS Assessment Cost in 2026: What the Fee Actually Covers
Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.
PCI DSS 4.0: What Changed and What It Means for Your Next Assessment
v3.2.1 is retired. Here’s what’s actually different in v4.0.1, which changes bite first-timers hardest, and how to plan the transition.
PCI Merchant Levels 1–4 (and Service Provider Levels) Explained
The transaction thresholds that decide whether you need a QSA on site — and why your acquirer can override all of it.
How to Share Your PCI AoC (and ROC) With Customers
What to share, what to never share, and how mature companies handle the 47th ‘please send your PCI docs’ request of the quarter.
PCI DSS by industry
Scope, cost drivers, and first-timer traps differ by industry:
SaaS · E-commerce & retail · Fintech · Healthcare
Reading is step one. Quotes are step two.
When you're ready, get scoped quotes from accredited QSA companies matched to your environment.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.