PCI DSS ranges from under US$1,000 for a small self-assessing merchant to US$50,000+ for a Level 1 QSA audit. Here is what sets your number.
PCI DSS compliance costs anywhere from under US$1,000 a year for a small merchant that self-assesses to well over US$50,000 for a large Level 1 merchant that needs a Qualified Security Assessor. What you pay depends almost entirely on your merchant level, which is set by how many card transactions you process each year, and on whether you can validate with a Self-Assessment Questionnaire or need a formal Report on Compliance. A compliance platform such as CertAssist, at US$3,999 per year, organises the work; the larger costs are scans, remediation and, for the biggest merchants, the QSA. Here is the breakdown.
The cost of PCI DSS compliance is driven by your merchant level and validation route, not by the standard itself. A small merchant that qualifies for a Self-Assessment Questionnaire can validate for very little, mostly time plus quarterly scans. A large Level 1 merchant must engage a Qualified Security Assessor for an on-site assessment and a Report on Compliance, which is where the five figure fees appear. The version in force is PCI DSS v4.0.1, and its requirements apply regardless of level.
| Cost driver | Typical range (USD) | Applies to |
|---|---|---|
| SAQ self-assessment | $0 to a few thousand | Levels 2 to 4, most merchants |
| ASV quarterly scans | $500 to $3,000/yr | Anyone with external-facing systems |
| Compliance platform | $3,999/yr (CertAssist) | Any merchant organising evidence |
| QSA Report on Compliance | $15,000 to $50,000+ | Level 1 merchants |
| Remediation | Highly variable | Any gaps found |
Merchant levels are set by annual card transaction volume defined by the card brands. Most small businesses fall into Levels 2 to 4 and self-assess.
For a small business, PCI DSS is usually inexpensive because most small merchants fall into Levels 2 to 4 and validate with a Self-Assessment Questionnaire rather than a paid audit. The real costs are quarterly Approved Scanning Vendor scans, from roughly US$500 to US$3,000 a year, any remediation the scans surface, and your time. Using a platform to organise the questionnaire and evidence keeps that time down; CertAssist covers PCI DSS v4.0.1 for US$225 per month during its launch.
You need a Qualified Security Assessor when you are a Level 1 merchant, generally those processing more than six million card transactions a year, or when an acquiring bank or card brand requires it. A QSA performs an on-site assessment and issues a Report on Compliance, which commonly costs from about US$15,000 to over US$50,000 depending on environment size and complexity. Smaller merchants almost never need a QSA and should not budget for one unless told otherwise.
To keep PCI DSS cost down, reduce your scope first: use a validated payment provider so card data never touches your systems, which can drop you to a much shorter Self-Assessment Questionnaire. Then run your ASV scans on schedule, fix findings promptly, and organise your evidence once so each annual revalidation is fast. A flat, published platform price like CertAssist's keeps the tooling line predictable while you focus spend on scanning and remediation.
Merchant level is the single biggest factor in PCI DSS cost, and it is set by the card brands based on your annual transaction volume, not by your revenue. Level 4, the smallest, and Levels 3 and 2 generally validate with a Self-Assessment Questionnaire and quarterly scans, so their hard costs are modest. Level 1, the largest, must have a Qualified Security Assessor produce a Report on Compliance each year, which is where costs jump into five figures. Two businesses following the same standard can therefore pay very different amounts purely because of volume. Confirm your level with your acquiring bank before you budget, because assuming the wrong one either overspends or leaves you non-compliant.
The hidden costs of PCI DSS usually come from scope and remediation rather than the assessment. If cardholder data flows through systems it did not need to, your scope balloons and every system in it must be secured, scanned and evidenced. Network segmentation to shrink that scope has an upfront cost but pays back every year. Remediation of scan findings, staff time to keep policies and evidence current, and the quiet cost of a lapsed certification all add up. Reducing scope with a validated provider and keeping evidence organised year round is what turns PCI DSS from a recurring scramble into a predictable annual task.
PCI DSS is an ongoing cost, because compliance must be validated every year and maintained continuously in between. You revalidate annually, whether through a Self-Assessment Questionnaire or a Qualified Security Assessor, and you run Approved Scanning Vendor scans quarterly all year. So the recurring lines are the yearly validation, the quarterly scans, any tooling you use to keep evidence organised, and the staff time to keep controls in place. The good news is that once your scope is reduced and your evidence is organised, each year's revalidation is far lighter than the first. Treating PCI DSS as a standing process rather than an annual event, with a flat and predictable tooling cost like CertAssist's, is what keeps the ongoing spend low and stops a lapse that could put your ability to take card payments at risk.
PCI DSS costs from under US$1,000 a year for a small merchant that self-assesses to over US$50,000 for a Level 1 merchant that needs a Qualified Security Assessor. Your merchant level, set by annual card transaction volume, and whether you use a Self-Assessment Questionnaire or a Report on Compliance are the main drivers.
Usually not. Most small businesses are Level 2 to 4 merchants and validate with a Self-Assessment Questionnaire rather than a paid audit. The main costs are quarterly ASV scans of roughly US$500 to US$3,000 a year, any remediation, and your time. Using a validated payment provider can shrink scope and cost further.
Only Level 1 merchants, generally those processing more than six million transactions a year, or merchants told to by their bank or card brand, need a Qualified Security Assessor. A QSA-led Report on Compliance commonly costs US$15,000 to US$50,000 or more. Smaller merchants self-assess and do not pay for a QSA.
The current standard is PCI DSS v4.0.1, released as a limited update to v4.0. Its requirements apply to all merchants and service providers that store, process or transmit cardholder data, though how you validate depends on your merchant level. CertAssist maps PCI DSS v4.0.1 control by control.
Reduce scope first by using a validated payment provider so cardholder data never touches your systems, which can move you to a shorter Self-Assessment Questionnaire. Then run ASV scans on time, remediate quickly, and organise evidence once so revalidation is fast. Keeping the platform cost flat and low, as CertAssist does, makes the yearly budget predictable.
CertAssist lays out every PCI DSS v4.0.1 requirement with editable evidence templates, for a published $225 a month during the launch.
See pricing FrameworksFlat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.