There is no published price for PCI DSS compliance, and the body that writes the standard does not set one. The PCI Security Standards Council says that "fees and charges are agreed upon between the entity and the assessor company" and that it "does not set or have any influence over fees and charges for services provided." What the standard and the card brands do fix are the things you pay for. Three drivers decide the bill: the validation route your card brand and acquirer require, from a self-assessment questionnaire to a Report on Compliance by a Qualified Security Assessor; the recurring testing PCI DSS itself mandates, from quarterly external scans by an Approved Scanning Vendor to yearly penetration tests; and your scope, meaning how many of your systems store, process or transmit card data.
Every quote you get is some combination of those three, plus whatever it costs you to close the gaps they reveal. This guide takes each driver in turn and says what a primary source requires, so you can ask assessors and scanning vendors for prices against a known list rather than compare ranges with no inputs behind them. Which questionnaire applies to you is covered in our guide to who must comply and which SAQ applies.
| Cost driver | What it requires | Source |
|---|---|---|
| Validation route | A Report on Compliance by a QSA for a Visa Level 1 merchant; a self-assessment questionnaire for Levels 2 and 3 | Visa account information security programme |
| External scans | At least once every three months, by a PCI SSC Approved Scanning Vendor | PCI DSS requirement 11.3.2 |
| Internal scans | At least once every three months | PCI DSS requirement 11.3.1 |
| Penetration tests | Internal and external, at least once every 12 months and after significant change | PCI DSS requirements 11.4.2 and 11.4.3 |
| Segmentation tests | Every 12 months for merchants, every six months for service providers, if segmentation reduces scope | PCI DSS requirements 11.4.5 and 11.4.6 |
| Scope | Confirmed every 12 months; fewer requirements apply with a PCI listed P2PE solution or a fully outsourced checkout | PCI DSS 12.5.2; PCI SSC on P2PE and SAQ A |
How much does PCI DSS compliance cost?
Whatever your route, your test schedule and your scope add up to. Page one for this query offers dollar ranges for assessments, scans and penetration tests, mostly with no merchant level, no scope and no source behind them. Two companies quoting the same range can be describing a fully outsourced checkout and a payment platform. Build your own figure instead: find out which validation route you are on, list the recurring tests the standard requires of you, and price each with providers from the Council's own lists. The QSA list and the ASV list are published by the Council, which advises that "each time a client engages a QSA, they are advised to check this list to ensure that its advisor has successfully maintained its status as a Qualified Security Assessor."
Who sets the price and who enforces the standard?
Not the Council. Its statement of its role says that "enforcement of compliance with PCI Standards and determination of any non-compliance penalties are carried out by the individual payment brands and not by the PCI SSC", and that the Council "does not receive copies of compliance assessment reports, nor is it involved in and has no information about penalties or fines for non-compliance." In its January 2025 SAQ A update it repeats that "compliance validation requirements are set by brands, acquirers, payment facilitators, etc." So the contract that decides what you must deliver, and what failing costs, is the one with your acquirer.
Which validation route are you on?
The one your card brand and acquirer assign. Visa's global account information security page currently lists three merchant levels. Level 1 covers "merchants processing over 6 million Visa transactions annually across all channels or Global merchants identified as Level 1 by any Visa region", and every year they file a Report on Compliance by a Qualified Security Assessor, or by an internal resource if signed by an officer of the company, and submit an Attestation of Compliance. Level 2 covers "1 to 6 million Visa transactions annually across all channels" and Level 3 "less than 1 million Visa ecommerce transactions annually across all channels"; both complete and submit a self-assessment questionnaire every year.
Service providers have a lower threshold. On the same page, a service provider that stores, processes or transmits over 300,000 Visa transactions a year must complete an annual on-site assessment and submit an Attestation of Compliance signed by both the provider and the QSA. Below that, a signed SAQ D or an AOC with a QSA signature, and QSA validation is required before listing on Visa's Global Registry of Service Providers. Regional pages can differ: Visa's Caribbean page still shows four levels and leaves Level 4 validation requirements to the acquirer. Other card brands run their own programmes, so confirm your level with your acquirer in writing before you price anything.
| Visa level | Who | What you file every year |
|---|---|---|
| Merchant Level 1 | Over 6 million Visa transactions a year, or named Level 1 by a Visa region | Report on Compliance by a QSA (or signed internal resource) and an AOC |
| Merchant Level 2 | 1 to 6 million Visa transactions a year | Self-assessment questionnaire |
| Merchant Level 3 | Less than 1 million Visa ecommerce transactions a year | Self-assessment questionnaire |
| Service provider Level 1 | Over 300,000 Visa transactions a year | On-site assessment and an AOC signed by the provider and the QSA |
| Service provider Level 2 | Less than 300,000 Visa transactions a year | Signed SAQ D, or an AOC with a QSA signature |

What recurring costs does the standard itself create?
A fixed testing calendar, whatever your level. In the wording of the PCI DSS v4.0 SAQ D, which reproduces the requirements, external vulnerability scans are performed "at least once every three months" and "by a PCI SSC Approved Scanning Vendor (ASV)" under requirement 11.3.2, and internal scans at least once every three months under 11.3.1. Scans after any significant change, under 11.3.2.1, are performed by qualified personnel with organisational independence, "not required to be a QSA or ASV". Internal and external penetration tests, under 11.4.2 and 11.4.3, are performed "at least once every 12 months" and "after any significant infrastructure or application upgrade or change", by "a qualified internal resource or qualified external third-party", again with independence and not necessarily a QSA or ASV.
If you use segmentation to shrink scope, it has to be tested: under 11.4.5 penetration tests on the segmentation controls run "at least once every 12 months and after any changes to segmentation controls/methods", and under 11.4.6 service providers do it every six months. Under 12.5.2, PCI DSS scope is "documented and confirmed by the entity at least once every 12 months and upon significant change to the in-scope environment"; service providers do it every six months under 12.5.2.1. The Council's note on v4.0.1 says "there are no additional or deleted requirements in this revision", so these are the current obligations.
| Activity | How often | Who may do it | Requirement |
|---|---|---|---|
| External vulnerability scan | At least every three months | An Approved Scanning Vendor | 11.3.2 |
| External scan after significant change | After each significant change | Qualified, independent personnel; not required to be a QSA or ASV | 11.3.2.1 |
| Internal vulnerability scan | At least every three months | Your team or a provider | 11.3.1 |
| Internal and external penetration test | At least every 12 months and after significant change | Qualified internal resource or external third party, independent | 11.4.2, 11.4.3 |
| Segmentation test | 12 months (merchants), six months (service providers) | As for penetration tests | 11.4.5, 11.4.6 |
| Scope confirmation | 12 months (merchants), six months (service providers) | The entity | 12.5.2, 12.5.2.1 |
What did PCI DSS v4.0 add to the bill?
New controls, now in force. The Council's summary of changes from v3.2.1 to v4.0 counts 64 new requirements: 13 took effect immediately, and the other 51 were best practices until 31 March 2025, after which they became effective. Version 4.0 was retired on 31 December 2024, and v4.0.1 did not change that 31 March 2025 date. If your last assessment was planned on the old requirement set, expect the first assessment against the full v4.0.1 set to need more evidence, and budget for the remediation the new requirements imply before you budget for the assessor.
How does scope change the cost?
More than any other lever. The Council says that "merchants using PCI-listed P2PE solutions also have fewer applicable PCI Data Security Standard (PCI DSS) requirements", and its guidance on point to point encryption adds that such merchants "may be eligible to use Self-Assessment Questionnaire (SAQ) P2PE" and that P2PE "doesn't remove the need for all PCI DSS controls, but it does greatly reduce the number of controls that have to be validated." For ecommerce, the January 2025 SAQ A update removed requirements 6.4.3 and 11.6.1 on payment page security, and 12.3.1 for the related targeted risk analysis, from SAQ A, and added an eligibility criterion that merchants "confirm their site is not susceptible to attacks from scripts that could affect the merchant's e-commerce system(s)." The Council adds that the changes "do not remove or diminish the underlying requirements within PCI DSS."
Visa offers one more route for eligible merchants. Its Technology Innovation Program, on the same Visa page, removes "the requirement to verify compliance with the PCI DSS when at least 75% of yearly transactions originate through EMV chip-enabled terminals, a validated point-to-point encryption solution or integrated industry-standard tokenization solution". Ask your acquirer whether you qualify before you buy a ROC.
What does non-compliance cost?
Visa answers that on the same page: if a merchant or service provider does not comply with the PCI DSS or fails to rectify a security issue, "Visa may assess a non-compliance assessment to the issuer or acquirer. The issuer or acquirer is responsible for paying all assessments and must not represent that Visa has imposed any assessment on the service provider or merchant." Visa adds that "assessments may be waived if there is no evidence of PCI DSS non-compliance prior to, and at the time of a data breach". No public schedule of amounts exists, so whether and how any of it reaches you is a question for your merchant agreement. Read that clause before you decide a gap can wait.

What the other results get wrong
Page one is vendor and consultancy pages. Four errors recur. The first is the price range with no inputs: an assessment figure means nothing without the level, the scope and the number of locations behind it, and the Council itself sets no fees. The second is four Visa merchant levels presented as current; Visa's global page lists three, and regional pages differ, so ask your acquirer. The third is treating every external scan as an ASV job; the quarterly scan must be by an ASV, but a scan after a significant change, under 11.3.2.1, need not be. The fourth is calling the outcome a certification from the Council. Validation requirements are set by brands and acquirers, and the Council does not even receive the reports.
Estimate your own cost
Fill this in before you ask anyone for a quote. Each row is a line on the invoice or a reason to shrink one.
| Question | Your answer | Why it matters |
|---|---|---|
| Which level has your acquirer assigned you, in writing, for each card brand? | Sets ROC or SAQ; card brands and acquirers decide. | |
| Which SAQ, if any, are you eligible for? | SAQ A, P2PE and D carry very different requirement sets. | |
| Which systems store, process or transmit card data, and where? | Requirement 12.5.2 scope; every system in it is tested. | |
| Do you use segmentation to reduce scope? | Requirement 11.4.5 adds a yearly segmentation test. | |
| Who runs your quarterly external scans, and is it a listed ASV? | Requirement 11.3.2; check the Council's ASV list. | |
| When were the last internal and external penetration tests? | Requirements 11.4.2 and 11.4.3: every 12 months. | |
| Could more than 75% of transactions run through EMV chip, P2PE or tokenization? | Visa's Technology Innovation Program may remove validation. |
Start with the PCI DSS compliance checklist, or take the free compliance check. Venvera's PCI DSS module tracks the requirements and the evidence behind each one, and maps controls you already run for ISO 27001 or SOC 2 so the same evidence is not collected twice. Venvera is not a QSA or an ASV and does not replace either. The same cost logic for another standard is in our guide to ISO 27001 certification cost.
Frequently asked questions
Does the PCI Security Standards Council charge for compliance?
It does not set assessment prices. Fees are agreed between you and the assessor company, and the Council says it has no influence over them.
Does a Level 1 merchant always need a QSA?
Visa's global page requires a Report on Compliance by a QSA, or by an internal resource if signed by an officer of the company, plus an Attestation of Compliance every year. Confirm with your acquirer which it will accept.
Must penetration testing be done by a QSA or ASV?
No. Requirements 11.4.2 and 11.4.3 allow a qualified internal resource or a qualified external third party with organisational independence, and state it is not required to be a QSA or ASV. Only the quarterly external scan under 11.3.2 must be done by an ASV.
Who fines a business for PCI DSS non-compliance?
Not the Council. Card brands enforce compliance; Visa, for example, may assess a non-compliance assessment to the issuer or acquirer, which is responsible for paying it.
Did PCI DSS v4.0.1 add new requirements?
No. The Council states there are no additional or deleted requirements in v4.0.1. The requirements that became effective on 31 March 2025 came from v4.0.
Primary sources
The Council's role, fees and enforcement are from its At a Glance statement. Requirement wording is from the PCI DSS v4.0 SAQ D for service providers; the v4.0.1 status from the Council's v4.0.1 announcement; the 64 new requirements from the summary of changes; SAQ A changes from the Council's January 2025 update; P2PE from the Council's P2PE page and blog. Merchant and service provider levels, non-compliance assessments and the Technology Innovation Program are from Visa's account information security page, with the Caribbean regional page for comparison. Other card brands set their own levels; confirm yours with your acquirer.





