Pricing

How much does PCI DSS compliance cost in 2026?

11 August 2026 · 8 min read · CertAssist

PCI DSS ranges from under US$1,000 for a small self-assessing merchant to US$50,000+ for a Level 1 QSA audit. Here is what sets your number.

PCI DSS compliance costs anywhere from under US$1,000 a year for a small merchant that self-assesses to well over US$50,000 for a large Level 1 merchant that needs a Qualified Security Assessor. What you pay depends almost entirely on your merchant level, which is set by how many card transactions you process each year, and on whether you can validate with a Self-Assessment Questionnaire or need a formal Report on Compliance. A compliance platform such as CertAssist, at US$3,999 per year, organises the work; the larger costs are scans, remediation and, for the biggest merchants, the QSA. Here is the breakdown.

Bar chart of PCI DSS cost drivers from SAQ self-assessment up to a Level 1 QSA audit

What drives the cost of PCI DSS compliance?

The cost of PCI DSS compliance is driven by your merchant level and validation route, not by the standard itself. A small merchant that qualifies for a Self-Assessment Questionnaire can validate for very little, mostly time plus quarterly scans. A large Level 1 merchant must engage a Qualified Security Assessor for an on-site assessment and a Report on Compliance, which is where the five figure fees appear. The version in force is PCI DSS v4.0.1, and its requirements apply regardless of level.

Cost driverTypical range (USD)Applies to
SAQ self-assessment$0 to a few thousandLevels 2 to 4, most merchants
ASV quarterly scans$500 to $3,000/yrAnyone with external-facing systems
Compliance platform$3,999/yr (CertAssist)Any merchant organising evidence
QSA Report on Compliance$15,000 to $50,000+Level 1 merchants
RemediationHighly variableAny gaps found

Merchant levels are set by annual card transaction volume defined by the card brands. Most small businesses fall into Levels 2 to 4 and self-assess.

How much is PCI DSS for a small business?

For a small business, PCI DSS is usually inexpensive because most small merchants fall into Levels 2 to 4 and validate with a Self-Assessment Questionnaire rather than a paid audit. The real costs are quarterly Approved Scanning Vendor scans, from roughly US$500 to US$3,000 a year, any remediation the scans surface, and your time. Using a platform to organise the questionnaire and evidence keeps that time down; CertAssist covers PCI DSS v4.0.1 for US$225 per month during its launch.

When do you need a QSA, and what does it cost?

You need a Qualified Security Assessor when you are a Level 1 merchant, generally those processing more than six million card transactions a year, or when an acquiring bank or card brand requires it. A QSA performs an on-site assessment and issues a Report on Compliance, which commonly costs from about US$15,000 to over US$50,000 depending on environment size and complexity. Smaller merchants almost never need a QSA and should not budget for one unless told otherwise.

How do you keep PCI DSS cost down?

To keep PCI DSS cost down, reduce your scope first: use a validated payment provider so card data never touches your systems, which can drop you to a much shorter Self-Assessment Questionnaire. Then run your ASV scans on schedule, fix findings promptly, and organise your evidence once so each annual revalidation is fast. A flat, published platform price like CertAssist's keeps the tooling line predictable while you focus spend on scanning and remediation.

How does merchant level change what you pay?

Merchant level is the single biggest factor in PCI DSS cost, and it is set by the card brands based on your annual transaction volume, not by your revenue. Level 4, the smallest, and Levels 3 and 2 generally validate with a Self-Assessment Questionnaire and quarterly scans, so their hard costs are modest. Level 1, the largest, must have a Qualified Security Assessor produce a Report on Compliance each year, which is where costs jump into five figures. Two businesses following the same standard can therefore pay very different amounts purely because of volume. Confirm your level with your acquiring bank before you budget, because assuming the wrong one either overspends or leaves you non-compliant.

What are the hidden costs of PCI DSS?

The hidden costs of PCI DSS usually come from scope and remediation rather than the assessment. If cardholder data flows through systems it did not need to, your scope balloons and every system in it must be secured, scanned and evidenced. Network segmentation to shrink that scope has an upfront cost but pays back every year. Remediation of scan findings, staff time to keep policies and evidence current, and the quiet cost of a lapsed certification all add up. Reducing scope with a validated provider and keeping evidence organised year round is what turns PCI DSS from a recurring scramble into a predictable annual task.

Is PCI DSS a one-time or an ongoing cost?

PCI DSS is an ongoing cost, because compliance must be validated every year and maintained continuously in between. You revalidate annually, whether through a Self-Assessment Questionnaire or a Qualified Security Assessor, and you run Approved Scanning Vendor scans quarterly all year. So the recurring lines are the yearly validation, the quarterly scans, any tooling you use to keep evidence organised, and the staff time to keep controls in place. The good news is that once your scope is reduced and your evidence is organised, each year's revalidation is far lighter than the first. Treating PCI DSS as a standing process rather than an annual event, with a flat and predictable tooling cost like CertAssist's, is what keeps the ongoing spend low and stops a lapse that could put your ability to take card payments at risk.

Frequently asked questions

How much does PCI DSS compliance cost?

PCI DSS costs from under US$1,000 a year for a small merchant that self-assesses to over US$50,000 for a Level 1 merchant that needs a Qualified Security Assessor. Your merchant level, set by annual card transaction volume, and whether you use a Self-Assessment Questionnaire or a Report on Compliance are the main drivers.

Is PCI DSS expensive for a small business?

Usually not. Most small businesses are Level 2 to 4 merchants and validate with a Self-Assessment Questionnaire rather than a paid audit. The main costs are quarterly ASV scans of roughly US$500 to US$3,000 a year, any remediation, and your time. Using a validated payment provider can shrink scope and cost further.

Do I need a QSA for PCI DSS?

Only Level 1 merchants, generally those processing more than six million transactions a year, or merchants told to by their bank or card brand, need a Qualified Security Assessor. A QSA-led Report on Compliance commonly costs US$15,000 to US$50,000 or more. Smaller merchants self-assess and do not pay for a QSA.

What is the current PCI DSS version?

The current standard is PCI DSS v4.0.1, released as a limited update to v4.0. Its requirements apply to all merchants and service providers that store, process or transmit cardholder data, though how you validate depends on your merchant level. CertAssist maps PCI DSS v4.0.1 control by control.

How can I reduce PCI DSS cost?

Reduce scope first by using a validated payment provider so cardholder data never touches your systems, which can move you to a shorter Self-Assessment Questionnaire. Then run ASV scans on time, remediate quickly, and organise evidence once so revalidation is fast. Keeping the platform cost flat and low, as CertAssist does, makes the yearly budget predictable.

Related guides

Work through PCI DSS v4.0.1 without the guesswork

CertAssist lays out every PCI DSS v4.0.1 requirement with editable evidence templates, for a published $225 a month during the launch.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat $225 a month during the launch, normally $375, or $3,999 a year (12 months for the price of 11). All prices in USD.