The PCI DSS assessment timeline
A first PCI DSS assessment is a 4–9 month journey, not a 2-week audit. The QSA’s fieldwork is only the middle — scoping, gap work, and remediation decide the calendar.
- Scoping (2–4 weeks). Define the cardholder data environment: every system, location, and service provider that stores, processes, or transmits cardholder data. Get this wrong and everything downstream breaks — most delays start here.
- Gap assessment (2–6 weeks). Measure the scoped environment against PCI DSS v4.0.1. Deliverable: a findings list ranked by effort and risk. Many QSAs credit this fee toward the ROC.
- Remediation (4–12 weeks). Fix the gaps: segmentation, MFA, logging, encryption, patching, policies. The most variable phase — a clean environment needs weeks, a messy one needs quarters.
- QSA fieldwork (2–12 weeks). The on-site (or remote) assessment: evidence review, interviews, testing, sampling. Small SAQ-path merchants: days. Complex Level 1: up to 12 weeks.
- Reporting (2–4 weeks). The QSA drafts the Report on Compliance (ROC) and Attestation of Compliance (AoC), you review for factual accuracy, then it’s signed.
- Submission & steady state. Submit the AoC (and ROC, if required) to your acquirer. Then the annual cycle begins: quarterly ASV scans, annual pen test, and next year’s assessment.
Timeline questions
Can the timeline be compressed?
The fieldwork window compresses when evidence is ready and scope is tight — some QSAs complete small ROCs in 2–4 weeks of fieldwork. What doesn’t compress: remediation (fixing real gaps takes the time it takes) and the QSA’s independent verification. Anyone promising a Level 1 ROC in a week is selling a signature, not an assessment.
How often does the ROC need renewing?
Annually. The ROC is a point-in-time assessment valid for one year, and most acquirers and partners expect a fresh ROC/AoC every 12 months. Renewal fieldwork is typically shorter than the first assessment because controls and evidence pipelines already exist.
What slows assessments down most?
In our experience watching this market: unclear scope (the cardholder data environment turns out bigger than assumed), missing logs, untested incident response, and service providers without current AoCs. The readiness quiz catches most of these.
Plan your timeline with real quotes
Tell QSA companies your target date — they’ll tell you honestly whether it’s feasible. Free, two minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.