Data report

PCI DSS assessment pricing report 2026

Every cost figure we publish, in one table, each with its provenance, date, and scope. QSA firms almost never publish fees, so most bands are planning estimates (September 2026) — compiled from published industry ranges, clearly labeled, never presented as quotes. Structural facts cite their sources directly.

How to read this table. “Planning estimate” rows are our editorial estimates for budgeting — not quotes, not averages of quotes. “PCI Security Standards Council” rows are structural facts from the standard itself. Nothing here is a price any firm will honor without a scoped proposal.
Cost itemFigureProvenanceDateScope
Level 1 merchant ROC assessment (QSA on-site)$30,000–$100,000+Planning estimate (Sept 2026)Sept 2026Merchants processing 6M+ card transactions/year; complex environments exceed $100K
Level 2–3 / service-provider ROC assessment$15,000–$60,000Planning estimate (Sept 2026)Sept 2026Mid-size merchants and Level 2 service providers; scope-dependent
Guided SAQ completion (QSA-assisted)$5,000–$25,000Planning estimate (Sept 2026)Sept 2026QSA reviews and attests your self-assessment; DIY SAQ filing itself is free
Readiness / gap assessment$10,000–$30,000Planning estimate (Sept 2026)Sept 2026Pre-assessment gap analysis against PCI DSS v4.0.1; often credited toward the ROC
PCI penetration test (required annually)$10,000–$50,000Planning estimate (Sept 2026)Sept 2026External + internal pen test per Requirement 11; many QSAs bundle it
ASV vulnerability scans$100–$300 per scan; ~$2,000–$5,000/yr managedPlanning estimate (Sept 2026)Sept 2026Quarterly external scans by an Approved Scanning Vendor
Remediation (the hidden budget line)Often 1–2× the assessment feePlanning estimate (Sept 2026)Sept 2026Segmentation, logging, MFA, encryption gaps found in the gap assessment
Internal staff time (year one)$40,000–$80,000 in loaded costPlanning estimate (Sept 2026)Sept 2026Evidence collection, interviews, remediation project management
First-year all-in, Level 1$75,000–$250,000+Planning estimate (Sept 2026)Sept 2026Assessment + readiness + pen test + ASV + remediation + staff time
Annual renewal (steady state)Assessment fee + 20–40% for re-testing and upkeepPlanning estimate (Sept 2026)Sept 2026ROC is annual; year-two costs fall once controls and evidence pipelines exist
Non-compliance exposureMonthly non-compliance fees widely cited at $5,000–$100,000/monthWidely cited range — confirm with your acquirerSept 2026Card-brand programs via acquirers; escalates with level and duration. Not a fine schedule — ask your acquirer
Current standardPCI DSS v4.0.1; v3.2.1 retired March 31, 2025PCI Security Standards Council2025All new assessments are against v4.0.1

Price-source ledger

The sources behind the structural facts — checked September 2026:

SourceLinkWhat we took from it
PCI Security Standards Council — PCI DSS v4.0.1 and supporting documentshttps://www.pcisecuritystandards.org/document_library/…Current standard is PCI DSS v4.0.1; PCI DSS v3.2.1 was retired March 31, 2025; ROCs are point-in-time annual assessments
Visa — Global Registry of Service Providers (June 30, 2025)https://d1.awsstatic.com.rproxy.goskope.com/whitepapers/comp…Names accredited assessors on validated entities (e.g. Coalfire Systems, Inc. on Amazon/AWS; A-LIGN on Vagaro) — cross-checks QSAC status
PCI SSC — QSA Program Guide v3.0https://listings.pcisecuritystandards.org/documents/QSA_Prog…QSAs must be employees of accredited QSA companies; companies must re-qualify annually; PCI SSC does not endorse assessors
Network Assured — “The Best PCI QSAs of 2026: Reviews & Pricing”http://networkassured.com/vendors/services/pci-qsa-list/…389 QSACs listed on the PCI SSC website; distinguishes value-added QSAs (VAQSA) from check-the-box QSAs (CLQSA)
Astra Security — “5 PCI Compliance Companies in 2026”https://www.getastra.com/blog/compliance/pci-qsa-companies/…Market overview of PCI QSA companies incl. Coalfire, ControlCase, LevelBlue; ASV vs QSA distinction
Business Wire — BARR Advisory accredited as PCI QSA company (Jan 2024)http://www.businesswire.com/news/home/20240130661230/en/BARR…Accreditation timeline example: BARR added PCI DSS to its practice in January 2024

What we deliberately don’t publish

Turn estimates into scoped quotes

Three competing quotes beat any report. Free, two minutes, no obligation.

Get a free quote