2026 reference / updated July 2026

How much does PCI compliance actually cost?

Nobody publishes the answer. No QSA firm prints a rate card, no acquirer publishes its PCI fee, and only one ASV publishes any price at all, so every confident range you have read for this was somebody's guess. What is published is what drives your quote: the SAQ your checkout puts you on, and the controls that come with it. Start there, then price it with the worksheet below using quotes you actually hold.

SAQ A controls
~24

Fully hosted checkout

SAQ D controls
~251

Card data in your environment

Mastercard 4th violation
Up to $200k

Per violation, per calendar year

ASV scans required
4 / year

Requirement 11.3.2

Cost worksheet

Bring your own quotes. This does the arithmetic.

This worksheet has no rates of its own, because there are none to have: no QSA, ASV, pen test firm or acquirer publishes a price for PCI work. What it does instead is settle the part that is published, which is how often the standard makes you do each thing, and multiply it by the rates you enter from quotes you hold. Enter a rate and the line fills in. Leave it blank and the line stays open, because a total that quietly assumes a number you never gave it is the problem this page exists to avoid.

Your scope

Assessment route

You are a

Changes your segmentation test cadence: Requirement 11.4.6 puts service providers on six months, 11.4.5 puts everyone else on 12.

What is in scope

Staff in scope

Annual total from the rates you entered

$0

0 of 8 applicable lines priced. 8 still need a quote and are counted as zero, so this total is a floor rather than a budget.

LineYour rateQtyLine total
SAQ completion1 per year · Annual validation. Your acquirer sets the deadline.
$
x1Need a quote
ASV external scanning4 passing scans per year · Requirement 11.3.2 sets four passing scans a year as the floor
$
x4Need a quote
External penetration testAt least 1 per year, plus after significant change · Requirement 11.4.3
$
x1Need a quote
Internal penetration testAt least 1 per year, plus after significant change · Requirement 11.4.2
$
x1Need a quote
Application layer penetration testAt least 1 per year, plus after significant change · Requirement 11.4.2 and 11.4.3, at the application layer
$
x1Need a quote
Segmentation validation testNot applicable without segmentationn/a--
Security awareness training5 staff in scope, once per year · Requirement 12.6, role-specific content, at least annually
$
x5Need a quote
Security tooling (annual)Your own annual figure
$
x1Need a quote
Remediation budgetYour own figure. The least predictable line, and often the largest
$
x1Need a quote

If you ignore it

We cannot put a figure hereVisa does not publish a PCI non-compliance schedule. Mastercard publishes ceilings, not monthly fines. What reaches you is set by your acquirer agreement. The published schedules

Every figure above is one you entered, multiplied by a quantity shown next to it. This page supplies no rates and no estimates of its own. The quantities come from PCI DSS v4.0.1, which is published and linked per line; the rates are yours. If a line reads “need a quote”, the honest answer is that nobody, including us, can tell you that number without asking your vendors, so the total is a floor until you do. What to ask them

Scope reduction

Most of your PCI bill is scope. Scope is measured in controls.

Nobody publishes what a PCI programme costs, so this does not pretend to price yours. It shows the thing that is published and that every quote is built on: how many controls your architecture puts you on the hook for. Pick how you take money, then see what changing the architecture does to the count.

How you take payments
The lever for that channel

At a glance

Annual cost by merchant level

Your level sets your assessment route, and the route is what costs money. Visa and Mastercard do not agree on how many levels there are: Visa folded level 4 into level 3 on 25 April 2024, and Mastercard still runs four. So the same merchant can be a Visa level 3 and a Mastercard Level 4 on the same day.

LevelVolume thresholdAssessment routeTimeline
Level 1Over 6 million transactions per year (both brands)Report on Compliance (ROC), signed by a QSA, a certified ISA, or an executive officerMonths, not weeks. Scope drives everythingDetail →
Level 21,000,001 to 6 million transactions per year (both brands)Annual SAQ. Under Mastercard, SAQ A, A-EP or D must also be validated by a QSA or certified ISAWeeks to months, depending on SAQ typeDetail →
Level 3Visa: 1 to 1,000,000 a year, having absorbed the old level 4 on 25 April 2024. Mastercard: 20,000 to 1 million e-commerceSAQ + quarterly ASV scansWeeks, if your SAQ type is a simple oneDetail →
Level 4 (Mastercard only)Any merchant Mastercard does not deem Level 1, 2 or 3. Retired by Visa on 25 April 2024SAQ (type depends on payment acceptance method)Days to weeks for the simplest SAQ typesDetail →

Thresholds quoted from Visa's What To Do If Compromised v10.0 and Mastercard's Security Rules and Procedures, 3 February 2026. There is no annual cost column because no card brand, QSA, ASV or acquirer publishes one. To put real money against your own scope, take your quotes to the worksheet. It has no rates of its own, and every line it shows you is your figure times a quantity you can check.

Where the money goes

Seven cost components

Your PCI bill is seven line items, in roughly the order you meet them. Some are one-off (remediation, policy build); the rest recur every year. There is no price against them here because none of these markets publish one. What is against them is the thing each is priced on, which is what you need in order to go and get a real quote.

Mastercard, published

Up to $200k

The fourth violation ceiling for a Level 1 or Level 2 merchant, per violation per calendar year. Not monthly. Escalates from $25k. Source: SPME, 3 February 2026, section 2.2.5.

Visa, published

$100k / incident

For failing to report a compromise within three calendar days. Per incident. Visa publishes no routine non-compliance schedule at all. Source: Visa Rules 12.5.1.3.

Processor fee

On your statement

Nobody publishes this one. It is a term of the merchant agreement you signed, not a card brand fine, which is why two merchants on the same processor see different numbers. Yours is on your own statement.

Sector view

Cost by industry

Same standard, very different costs. A Stripe-based e-commerce shop and a full-service hotel face different SAQ types, scope boundaries, and tooling requirements.

Automation platforms

What the compliance platforms charge for PCI

Vanta, Drata, Secureframe, and Sprinto all publish list prices on AWS Marketplace, on named 12-month contract dimensions. The figures below are read off those listings (checked July 2026). Each vendor prices a platform fee and its frameworks as separate line items, so add the dimensions your scope needs. They automate the evidence work; they do not replace the QSA or the ASV.

Need an independent assessment?

Our partner network includes QSAs and ISAs across all merchant levels. Costs vary by scope and QSA fees are quoted independently. We do not endorse a specific firm.

Find a QSA in the PCI SSC directory

Frequently asked

Nobody publishes a price for it, and any site giving you a single range is guessing. No QSA firm publishes a rate card or a day rate, no acquirer publishes its PCI fee schedule, and only one ASV publishes any price at all. What decides your number is knowable, though: whether you self-assess or need a QSA-led ROC, which SAQ type your checkout puts you on (SAQ A is around 24 controls, SAQ D around 251), the size of the cardholder data environment, how many payment channels feed it, whether it is segmented, how many locations need fieldwork, and how ready your evidence is. Fix those seven answers, give the same brief to two or three firms, and compare the quotes scope-for-scope. That is the only reliable way to find out what yours costs.

Continue reading

Built by Digital Signet

You're using a tool we built.

Ranks on Google, cited by leading AI assistants

Digital Signet builds custom software and AI automation for compliance teams. Evidence collection, control mapping, audit prep, workflow automation.

See what we build →