2026 reference / updated July 2026
How much does PCI compliance actually cost?
Nobody publishes the answer. No QSA firm prints a rate card, no acquirer publishes its PCI fee, and only one ASV publishes any price at all, so every confident range you have read for this was somebody's guess. What is published is what drives your quote: the SAQ your checkout puts you on, and the controls that come with it. Start there, then price it with the worksheet below using quotes you actually hold.
- SAQ A controls
- ~24
- SAQ D controls
- ~251
- Mastercard 4th violation
- Up to $200k
- ASV scans required
- 4 / year
Fully hosted checkout
Card data in your environment
Per violation, per calendar year
Requirement 11.3.2
Cost worksheet
Bring your own quotes. This does the arithmetic.
This worksheet has no rates of its own, because there are none to have: no QSA, ASV, pen test firm or acquirer publishes a price for PCI work. What it does instead is settle the part that is published, which is how often the standard makes you do each thing, and multiply it by the rates you enter from quotes you hold. Enter a rate and the line fills in. Leave it blank and the line stays open, because a total that quietly assumes a number you never gave it is the problem this page exists to avoid.
Your scope
Assessment route
You are a
Changes your segmentation test cadence: Requirement 11.4.6 puts service providers on six months, 11.4.5 puts everyone else on 12.
What is in scope
Staff in scope
Annual total from the rates you entered
$0
0 of 8 applicable lines priced. 8 still need a quote and are counted as zero, so this total is a floor rather than a budget.
| Line | Your rate | Qty | Line total |
|---|---|---|---|
| SAQ completion1 per year · Annual validation. Your acquirer sets the deadline. | $ | x1 | Need a quote |
| ASV external scanning4 passing scans per year · Requirement 11.3.2 sets four passing scans a year as the floor | $ | x4 | Need a quote |
| External penetration testAt least 1 per year, plus after significant change · Requirement 11.4.3 | $ | x1 | Need a quote |
| Internal penetration testAt least 1 per year, plus after significant change · Requirement 11.4.2 | $ | x1 | Need a quote |
| Application layer penetration testAt least 1 per year, plus after significant change · Requirement 11.4.2 and 11.4.3, at the application layer | $ | x1 | Need a quote |
| Segmentation validation testNot applicable without segmentation | n/a | - | - |
| Security awareness training5 staff in scope, once per year · Requirement 12.6, role-specific content, at least annually | $ | x5 | Need a quote |
| Security tooling (annual)Your own annual figure | $ | x1 | Need a quote |
| Remediation budgetYour own figure. The least predictable line, and often the largest | $ | x1 | Need a quote |
If you ignore it
We cannot put a figure hereVisa does not publish a PCI non-compliance schedule. Mastercard publishes ceilings, not monthly fines. What reaches you is set by your acquirer agreement. The published schedules
Every figure above is one you entered, multiplied by a quantity shown next to it. This page supplies no rates and no estimates of its own. The quantities come from PCI DSS v4.0.1, which is published and linked per line; the rates are yours. If a line reads “need a quote”, the honest answer is that nobody, including us, can tell you that number without asking your vendors, so the total is a floor until you do. What to ask them
Most of your PCI bill is scope. Scope is measured in controls.
Nobody publishes what a PCI programme costs, so this does not pretend to price yours. It shows the thing that is published and that every quote is built on: how many controls your architecture puts you on the hook for. Pick how you take money, then see what changing the architecture does to the count.
At a glance
Annual cost by merchant level
Your level sets your assessment route, and the route is what costs money. Visa and Mastercard do not agree on how many levels there are: Visa folded level 4 into level 3 on 25 April 2024, and Mastercard still runs four. So the same merchant can be a Visa level 3 and a Mastercard Level 4 on the same day.
| Level | Volume threshold | Assessment route | Timeline | |
|---|---|---|---|---|
| Level 1 | Over 6 million transactions per year (both brands) | Report on Compliance (ROC), signed by a QSA, a certified ISA, or an executive officer | Months, not weeks. Scope drives everything | Detail → |
| Level 2 | 1,000,001 to 6 million transactions per year (both brands) | Annual SAQ. Under Mastercard, SAQ A, A-EP or D must also be validated by a QSA or certified ISA | Weeks to months, depending on SAQ type | Detail → |
| Level 3 | Visa: 1 to 1,000,000 a year, having absorbed the old level 4 on 25 April 2024. Mastercard: 20,000 to 1 million e-commerce | SAQ + quarterly ASV scans | Weeks, if your SAQ type is a simple one | Detail → |
| Level 4 (Mastercard only) | Any merchant Mastercard does not deem Level 1, 2 or 3. Retired by Visa on 25 April 2024 | SAQ (type depends on payment acceptance method) | Days to weeks for the simplest SAQ types | Detail → |
Thresholds quoted from Visa's What To Do If Compromised v10.0 and Mastercard's Security Rules and Procedures, 3 February 2026. There is no annual cost column because no card brand, QSA, ASV or acquirer publishes one. To put real money against your own scope, take your quotes to the worksheet. It has no rates of its own, and every line it shows you is your figure times a quantity you can check.
Where the money goes
Seven cost components
Your PCI bill is seven line items, in roughly the order you meet them. Some are one-off (remediation, policy build); the rest recur every year. There is no price against them here because none of these markets publish one. What is against them is the thing each is priced on, which is what you need in order to go and get a real quote.
QSA / SAQ assessment
Route, SAQ type, size of the cardholder data environment
ASV vulnerability scanning
Count of external IPs, hostnames or domains in scope
Penetration testing
Tester days: external IPs, internal segments, apps, APIs, roles
Remediation & gap closure
What the assessment finds. The least predictable line
Policy & documentation
How much already exists in writing
Security awareness training
Headcount in scope, per person per year
Tools & technology
The controls you cannot meet with what you already own
Mastercard, published
Up to $200k
The fourth violation ceiling for a Level 1 or Level 2 merchant, per violation per calendar year. Not monthly. Escalates from $25k. Source: SPME, 3 February 2026, section 2.2.5.
Visa, published
$100k / incident
For failing to report a compromise within three calendar days. Per incident. Visa publishes no routine non-compliance schedule at all. Source: Visa Rules 12.5.1.3.
Processor fee
On your statement
Nobody publishes this one. It is a term of the merchant agreement you signed, not a card brand fine, which is why two merchants on the same processor see different numbers. Yours is on your own statement.
Sector view
Cost by industry
Same standard, very different costs. A Stripe-based e-commerce shop and a full-service hotel face different SAQ types, scope boundaries, and tooling requirements.
Automation platforms
What the compliance platforms charge for PCI
Vanta, Drata, Secureframe, and Sprinto all publish list prices on AWS Marketplace, on named 12-month contract dimensions. The figures below are read off those listings (checked July 2026). Each vendor prices a platform fee and its frameworks as separate line items, so add the dimensions your scope needs. They automate the evidence work; they do not replace the QSA or the ASV.
Need an independent assessment?
Our partner network includes QSAs and ISAs across all merchant levels. Costs vary by scope and QSA fees are quoted independently. We do not endorse a specific firm.
Frequently asked
Nobody publishes a price for it, and any site giving you a single range is guessing. No QSA firm publishes a rate card or a day rate, no acquirer publishes its PCI fee schedule, and only one ASV publishes any price at all. What decides your number is knowable, though: whether you self-assess or need a QSA-led ROC, which SAQ type your checkout puts you on (SAQ A is around 24 controls, SAQ D around 251), the size of the cardholder data environment, how many payment channels feed it, whether it is segmented, how many locations need fieldwork, and how ready your evidence is. Fix those seven answers, give the same brief to two or three firms, and compare the quotes scope-for-scope. That is the only reliable way to find out what yours costs.
Continue reading
You're using a tool we built.
Digital Signet builds custom software and AI automation for compliance teams. Evidence collection, control mapping, audit prep, workflow automation.
See what we build →