PCI DSS frequently asked questions
Straight answers on levels, ROC vs SAQ, costs, timelines, and choosing a QSA company. Updated September 2026.
Do I need a QSA, or is a self-assessment (SAQ) enough?
It depends on your level. Level 1 merchants (6M+ card transactions/year with a brand) and Level 1–2 service providers must have an on-site assessment by a QSA producing a Report on Compliance. Smaller merchants generally validate with the appropriate Self-Assessment Questionnaire — but your acquirer has the final say, and some acquirers require a QSA regardless of level.
What’s the difference between a ROC and a SAQ?
A ROC (Report on Compliance) is produced by an independent QSA after an on-site assessment — it’s the heavyweight validation for Level 1. A SAQ is your own attestation that you meet the applicable requirements; a QSA can guide it but doesn’t sign it. Both are submitted with an Attestation of Compliance (AoC).
Which PCI DSS version applies now?
PCI DSS v4.0.1 is the current standard. Version 3.2.1 was retired on March 31, 2025, so all new assessments are against v4.0.1.
How much does a PCI DSS assessment cost?
Planning estimates (September 2026): Level 1 ROC assessment fees run $30,000–$100,000+; first-year all-in costs run $75,000–$250,000+ including readiness, pen testing, remediation, and staff time. Guided SAQ engagements run $5,000–$25,000. See the cost guide for the breakdown.
How long is a ROC valid?
One year. PCI DSS assessments are point-in-time and must be renewed annually — most acquirers expect a fresh AoC/ROC every 12 months.
What happens if we’re not compliant?
Your acquirer can levy monthly non-compliance fees (widely cited at $5,000–$100,000/month depending on level and duration — confirm with your acquirer), increase transaction fees, or ultimately terminate your ability to process cards. A breach while non-compliant compounds the exposure significantly.
What’s the difference between a QSA and an ISA?
A QSA (Qualified Security Assessor) is employed by an accredited QSA company and can assess anyone — only a QSA can sign a ROC. An ISA (Internal Security Assessor) is your own employee, trained by the PCI SSC, who can perform internal assessments and sign SAQs for their employer — but cannot sign a ROC for a Level 1 assessment.
Can a compliance platform replace a QSA?
No. Platforms (and consultants) can prepare evidence and guide remediation, but only a QSA employed by an accredited QSA company can perform the on-site assessment and sign the ROC. Anyone implying otherwise is misrepresenting the standard.
How do I verify a QSA company is really accredited?
Check the PCI Security Standards Council’s assessor listings (listings.pcisecuritystandards.org) and cross-reference Visa’s Global Registry of Service Providers, which names the assessor on validated entities. Accreditation must be renewed annually — a firm that was accredited last year may not be today.
Can we switch QSA companies between years?
Yes — there’s no lock-in. Time the switch after your current ROC cycle, transfer evidence and documentation cleanly, and let the new QSA re-scope (scope drift between assessors is normal). See our switching guide.
Do service providers we use need their own PCI validation?
If they store, process, or transmit cardholder data on your behalf: yes, and you must collect their current AoC annually. Their non-compliance is your scope problem.
What’s an ASV scan and do we need one?
An Approved Scanning Vendor (ASV) performs quarterly external vulnerability scans of your internet-facing systems — required for most merchants and service providers. It’s separate from the annual penetration test (Requirement 11), which goes deeper.
We’re a SaaS company — are we a merchant or a service provider?
Often both, and the stricter requirements apply. If you process payments for your own product you’re a merchant; if you handle card data on behalf of customers you’re a service provider. Your QSA scopes this in week one — get it in writing.
How do we share our ROC/AoC with customers?
Share the AoC (not the full ROC) under NDA, typically through a trust center or security review process. The full ROC contains sensitive detail about your environment — most companies never distribute it broadly. See our guide to sharing your AoC.
Still have questions? Get them answered with quotes
QSA companies answer scoping questions as part of quoting — free, no obligation.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.