Data report
PCI DSS assessment pricing report 2026
Every cost figure we publish, in one table, each with its provenance, date, and scope. QSA firms almost never publish fees, so most bands are planning estimates (September 2026) — compiled from published industry ranges, clearly labeled, never presented as quotes. Structural facts cite their sources directly.
How to read this table. “Planning estimate” rows are our editorial estimates for budgeting — not quotes, not averages of quotes. “PCI Security Standards Council” rows are structural facts from the standard itself. Nothing here is a price any firm will honor without a scoped proposal.
| Cost item | Figure | Provenance | Date | Scope |
|---|---|---|---|---|
| Level 1 merchant ROC assessment (QSA on-site) | $30,000–$100,000+ | Planning estimate (Sept 2026) | Sept 2026 | Merchants processing 6M+ card transactions/year; complex environments exceed $100K |
| Level 2–3 / service-provider ROC assessment | $15,000–$60,000 | Planning estimate (Sept 2026) | Sept 2026 | Mid-size merchants and Level 2 service providers; scope-dependent |
| Guided SAQ completion (QSA-assisted) | $5,000–$25,000 | Planning estimate (Sept 2026) | Sept 2026 | QSA reviews and attests your self-assessment; DIY SAQ filing itself is free |
| Readiness / gap assessment | $10,000–$30,000 | Planning estimate (Sept 2026) | Sept 2026 | Pre-assessment gap analysis against PCI DSS v4.0.1; often credited toward the ROC |
| PCI penetration test (required annually) | $10,000–$50,000 | Planning estimate (Sept 2026) | Sept 2026 | External + internal pen test per Requirement 11; many QSAs bundle it |
| ASV vulnerability scans | $100–$300 per scan; ~$2,000–$5,000/yr managed | Planning estimate (Sept 2026) | Sept 2026 | Quarterly external scans by an Approved Scanning Vendor |
| Remediation (the hidden budget line) | Often 1–2× the assessment fee | Planning estimate (Sept 2026) | Sept 2026 | Segmentation, logging, MFA, encryption gaps found in the gap assessment |
| Internal staff time (year one) | $40,000–$80,000 in loaded cost | Planning estimate (Sept 2026) | Sept 2026 | Evidence collection, interviews, remediation project management |
| First-year all-in, Level 1 | $75,000–$250,000+ | Planning estimate (Sept 2026) | Sept 2026 | Assessment + readiness + pen test + ASV + remediation + staff time |
| Annual renewal (steady state) | Assessment fee + 20–40% for re-testing and upkeep | Planning estimate (Sept 2026) | Sept 2026 | ROC is annual; year-two costs fall once controls and evidence pipelines exist |
| Non-compliance exposure | Monthly non-compliance fees widely cited at $5,000–$100,000/month | Widely cited range — confirm with your acquirer | Sept 2026 | Card-brand programs via acquirers; escalates with level and duration. Not a fine schedule — ask your acquirer |
| Current standard | PCI DSS v4.0.1; v3.2.1 retired March 31, 2025 | PCI Security Standards Council | 2025 | All new assessments are against v4.0.1 |
Price-source ledger
The sources behind the structural facts — checked September 2026:
| Source | Link | What we took from it |
|---|---|---|
| PCI Security Standards Council — PCI DSS v4.0.1 and supporting documents | https://www.pcisecuritystandards.org/document_library/… | Current standard is PCI DSS v4.0.1; PCI DSS v3.2.1 was retired March 31, 2025; ROCs are point-in-time annual assessments |
| Visa — Global Registry of Service Providers (June 30, 2025) | https://d1.awsstatic.com.rproxy.goskope.com/whitepapers/comp… | Names accredited assessors on validated entities (e.g. Coalfire Systems, Inc. on Amazon/AWS; A-LIGN on Vagaro) — cross-checks QSAC status |
| PCI SSC — QSA Program Guide v3.0 | https://listings.pcisecuritystandards.org/documents/QSA_Prog… | QSAs must be employees of accredited QSA companies; companies must re-qualify annually; PCI SSC does not endorse assessors |
| Network Assured — “The Best PCI QSAs of 2026: Reviews & Pricing” | http://networkassured.com/vendors/services/pci-qsa-list/… | 389 QSACs listed on the PCI SSC website; distinguishes value-added QSAs (VAQSA) from check-the-box QSAs (CLQSA) |
| Astra Security — “5 PCI Compliance Companies in 2026” | https://www.getastra.com/blog/compliance/pci-qsa-companies/… | Market overview of PCI QSA companies incl. Coalfire, ControlCase, LevelBlue; ASV vs QSA distinction |
| Business Wire — BARR Advisory accredited as PCI QSA company (Jan 2024) | http://www.businesswire.com/news/home/20240130661230/en/BARR… | Accreditation timeline example: BARR added PCI DSS to its practice in January 2024 |
What we deliberately don’t publish
- A single “average PCI assessment cost.” Averages across wildly different scopes mislead more than they inform.
- Firm-specific fees we didn’t verify. If a band appears on a firm profile, it’s labeled with its provenance there too.
- Stale figures. Every number on this page is dated. Pricing content without a date is how buyers get burned.
Turn estimates into scoped quotes
Three competing quotes beat any report. Free, two minutes, no obligation.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.