Skip to content
    August 22, 2026| Top Floor Team| 10 min read

    What Does PCI DSS Compliance Actually Cost?

    Nobody publishes a PCI rate card, and the one site built specifically to answer this question refuses to invent one. pcicompliancecost.com, published by Digital Signet, a firm that builds software and automation for compliance teams, states that "no QSA firm prints a rate card, no acquirer publishes its PCI fee," and that the page "supplies no rates and no estimates of its own." What does exist is seller-side numbers, and as of August 2026 they disagree loudly. Akurateco, a white-label payment gateway vendor whose product is partly sold on shrinking your PCI scope, publishes $50 to $10,000 for self-assessment support and $15,000 to $100,000 for a QSA-led assessment. SISA, which sells PCI assessment and testing services, publishes $5,000 to $20,000 for questionnaire completion and $35,000 to $200,000 for a Report on Compliance. Two vendors, the same two line items, and a floor that differs by more than 2x.

    That disagreement is the useful information, not the midpoint. This article explains why the spread is that wide, which line items never appear in anyone's quote, and the one variable that moves your number more than everything else combined.

    Key takeaways

    • No authoritative PCI price exists. The specialist cost site declines to print rates because QSA firms and acquirers do not publish them, so every figure below belongs to a company selling something adjacent.
    • The two published ROC ranges we could source disagree by $20,000 at the floor ($15,000 versus $35,000) and by $100,000 at the ceiling. Treat any single quoted range as one vendor's book of business, not a market rate.
    • The assessment fee is rarely the biggest line. Scanning, remediation engineering, tooling subscriptions, testing and internal hours land outside it.
    • Scope, not company size, sets your bill. Every system moved outside the cardholder data environment is a system nobody has to assess, scan, harden or explain, every year.
    • Non-compliance has published brand-side numbers too, and they are larger than most assessment fees.

    Why there is no PCI price list

    Three structural reasons, none of them conspiratorial.

    First, PCI validation is not one purchase. Your acquirer sets whether you validate and how, the payment brands set their own rules, an assessor prices fieldwork against a scope nobody has measured yet, and a scanning vendor prices per external IP address. Four different sellers, four unrelated pricing models, and no one of them is positioned to quote a total.

    Second, the scope is genuinely unknown at quoting time. An assessor cannot price an examination of a cardholder data environment before someone has drawn the cardholder data environment. That is why every QSA engagement starts with a scoping call, and why the number you get afterwards can differ from the one you expected by a multiple.

    Third, and most simply, the parties with the real numbers have no incentive to publish them. Acquirer PCI fees appear on merchant statements, not on websites. Assessor rates are negotiated. So the public record consists almost entirely of content marketing, which is what the next section is.

    What the published ranges actually say, and who is saying it

    As of August 2026, here are the sourceable figures, each labelled with the seller.

    Akurateco sells a white-label payment gateway and payments orchestration platform, marketed in part as a way to reduce PCI burden through scope reduction. Its guide publishes $50 to $10,000 for SAQ support, $15,000 to $100,000 for a QSA or ROC assessment, and $100 to $500 per quarter for approved scanning vendor scans. Akurateco also publishes annual budget scenarios: $1,000 to $15,000 for a small e-commerce merchant, $10,000 to $40,000 for a SaaS business holding cards on file, $25,000 to $90,000 for a mid-size merchant, and $60,000 to $250,000 and up where a Report on Compliance is required.

    SISA sells PCI assessment, testing and managed security services, so its numbers describe work it performs. Its breakdown publishes $5,000 to $20,000 for questionnaire completion, $35,000 to $200,000 for a ROC, up to $200 per IP address annually for ASV scanning, and $20 to $30 per employee per session for security awareness training.

    Now do the arithmetic on the disagreement rather than averaging it away. On the assessment line, Akurateco's floor is $15,000 and SISA's floor is $35,000: a gap of $20,000, or better than 2.3x, on what is nominally the same deliverable. On the ceiling, $100,000 against $200,000. On the questionnaire line, Akurateco's floor of $50 and SISA's floor of $5,000 are separated by two orders of magnitude, which tells you the two pages are describing different things under one label: $50 is a self-filed document, $5,000 is a consultant filling it in with you.

    The honest conclusion is that these are not measurements. They are each firm's own deal book, published as a range. Use them to bound your expectations and to spot a quote that sits outside every published band. Do not use them to build a budget you commit to a board.

    The line items that arrive after the quote

    Whatever the assessment costs, it is one of six or seven things you pay for. The others, in rough order of how often they surprise people:

    Remediation engineering

    The gap list from a readiness pass turns into sprints: separating the environment, fixing logging and retention, building access reviews that actually run, closing the change management gaps. None of it is billed by a vendor and all of it is real cost.

    Tooling that recurs

    Logging and retention, vulnerability scanning, file integrity monitoring, and, for e-commerce merchants, script management and payment page change detection under Requirements 6.4.3 and 11.6.1. These renew annually and they do not go away when the assessment ends.

    External scanning

    Where your validation type includes it, ASV scanning runs on a quarterly cycle and prices per address. The two published figures above ($100 to $500 per quarter from Akurateco, up to $200 per IP annually from SISA) are not directly comparable, because one is priced per scan window and the other per address. Our ASV scanning article covers who owes the scans and how the quarterly cycle works.

    Penetration testing

    We are deliberately not printing a range here. Our penetration testing cost breakdown is the site's price authority for that line item, with published ranges by engagement type, and a second Top Floor page quoting a different number for the same work would be worse than useless.

    Internal hours

    The line nobody invoices. Someone has to draw the data flow, chase evidence, answer the assessor, and argue with an engineering team about a checkout integration. On a first-time program that person is usually senior and usually already busy.

    The other side of the ledger

    The published numbers on the failure side are, awkwardly, larger and easier to source than the ones on the compliance side. pcicompliancecost.com summarises the brand schedules as Mastercard penalties escalating to a ceiling of up to $200,000 per violation per calendar year by the fourth violation, and a Visa penalty of $100,000 per incident for failing to report a compromise within three calendar days.

    Two caveats before anyone puts those in a slide. They are one compliance-software firm's summary of card brand schedules that the brands do not publish in full publicly, and penalties flow through your acquirer under your merchant agreement rather than arriving as a direct bill. So treat them as an order of magnitude, not a quote. The order of magnitude is still the point: for most merchants the ceiling on the penalty side is larger than the floor on the assessment side.

    The variable that actually moves the number

    Everything above is line items. This is the multiplier.

    Assessors bill against the size of the environment they have to examine. Scanning vendors bill per address. Tooling bills per host or per seat. Your own engineers spend time proportional to how many systems have to be brought up to standard. Every one of those meters is driven by the same quantity: how much of your estate sits inside the cardholder data environment.

    Work an illustrative example, using nothing but the published ranges above. Suppose you are quoted at the bottom of SISA's ROC band, $35,000, for an environment of a given size. Halving the number of in-scope systems does not merely halve that fee. It also removes their share of the ASV addresses, their logging and monitoring licences, their remediation sprints, and the internal hours spent evidencing them, and it removes all of that again next year and the year after. The assessment fee is the only part of the saving that appears in a vendor quote, and it is usually the smaller part.

    This is why we put scope reduction ahead of assessor selection in every PCI engagement, and why it has its own article: how to reduce your PCI DSS scope covers the four levers in order of how much they actually remove.

    When you should not spend anything at all

    A section against our own interest, because it applies to a meaningful share of the people reading this.

    If you take card-not-present payments through a fully hosted checkout, hold no card data on any system you control, and your acquirer has told you in writing which validation type you owe, your PCI cost this year should be close to zero in cash and a few hours in time. Read the eligibility section of the current questionnaire, answer it honestly, fix whatever the exercise surfaces, and file it. Anyone quoting you a project for that is selling you a document you could have produced yourself.

    Two more cases where the money is better spent elsewhere. If nobody has drawn your card data flow yet, do not buy an assessment; you would be paying an assessor to discover your scope, which is the most expensive possible way to learn it. And if your real problem is that an enterprise customer wants assurance about your product rather than about your card handling, PCI may be the wrong instrument entirely, and SOC 2 is the conversation you are actually in.

    Where Top Floor fits

    We are not a Qualified Security Assessor. We cannot sign a Report on Compliance and we do not issue attestations, which is exactly why we have no stake in how large your assessment turns out to be. Under our PCI DSS practice the work is readiness: mapping where card data really goes, arguing the boundary down before anyone bills against it, closing gaps, and preparing evidence so the validation you owe is short. Where PCI runs alongside SOC 2 or ISO 27001, Compliance as a Service is the multi-framework version of the same programme, and where a test is required rather than assumed, penetration testing is scoped separately and priced on its own page.

    How to decide this week

    Email your acquirer and ask two questions: which merchant level are we, and which validation type do you require. Get the answer in writing. Until you have it, every number in this article is hypothetical, because you do not yet know which product you are buying.

    Then draw the card data flow on one page, including the paths nobody designed: phone refunds, support chat, a finance spreadsheet, call recordings. Count the systems on it. That count, not your headcount and not your revenue, is what every meter in your PCI budget is attached to.

    Finally, when you do collect quotes, ask each seller what scope their number assumes and what happens to it if the scope is 30 percent larger. A quote that cannot answer that is not a quote.

    Frequently asked questions

    How much does PCI DSS compliance cost?

    There is no authoritative figure, because assessors and acquirers do not publish rates. As of August 2026 the sourceable numbers are vendor-published ranges: Akurateco, a payment gateway vendor, publishes $50 to $10,000 for self-assessment support and $15,000 to $100,000 for a QSA-led assessment; SISA, a PCI assessment and testing firm, publishes $5,000 to $20,000 for questionnaire completion and $35,000 to $200,000 for a Report on Compliance. Those floors differ by more than 2x for nominally the same work, which is the most honest answer available: read each range as one seller's book of business rather than as a market price.

    Why do PCI cost estimates vary so much between websites?

    Because they are not measurements of a market, they are descriptions of each publisher's own deals, and because the underlying work is not one product. Validation type, the number of in-scope systems, whether scanning applies, whether a test is required, and how much remediation the environment needs all move the total independently. The specialist site pcicompliancecost.com goes as far as declining to publish rates at all, on the grounds that no QSA firm prints a rate card and no acquirer publishes its PCI fee.

    Is a self-assessment questionnaire cheaper than hiring an assessor?

    In cash, almost always, and the published ranges reflect that. The trap is assuming the questionnaire is the cost. A questionnaire answered honestly surfaces work, and that work (remediation, tooling, evidence, internal hours) is where most first-year PCI money goes regardless of who validates. Paying someone to complete the document while the controls stay unchanged buys a signed record you will have to buy again next year.

    What is the single biggest lever on PCI cost?

    Scope. Assessors bill against the size of the environment they examine, scanning vendors bill per address, tooling bills per host, and your own engineers spend time proportional to how many systems must be brought up to standard. All four meters run off the same quantity, so removing systems from the cardholder data environment reduces the bill in four places at once, and does so again every subsequent year.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.