2026

PCI in 2026: what changed, and what is actually published

2026 is the first full assessment cycle in which every PCI DSS v4.0 requirement applies, future-dated ones included. This page is the dated, checkable version of the 2026 picture: the current rulebook editions, what the future-dated requirements actually ask for, why Visa and Mastercard no longer agree on how many merchant levels there are, and the short list of prices anybody genuinely publishes.

Updated July 2026

Future-dated reqs mandatory

31 Mar 2025

All 51 of them. 2026 is the first full cycle

Merchant levels: Visa / Mastercard

3 / 4

Visa consolidated 3 and 4 on 25 April 2024. Mastercard did not

PCI DSS v5.0

Not announced. No signalled timeline

The real 2026 story: the first full v4.0 cycle

PCI DSS v4.0 was published in March 2022 and v3.2.1 retired in March 2024, which made v4.0 the only standard anyone could be assessed against. But 51 of its requirements were marked future-dated, meaning best practice rather than obligation, and they became mandatory on 31 March 2025. The 2025 calendar year therefore split down the middle: assessments before that date and assessments after it applied different control sets. 2026 is the first full year with none of that ambiguity, and that is the change worth planning around.

The future-dated requirements are not evenly distributed in what they ask of you. Some are clarifications of things a competent security programme already does. Others are genuinely new. Requirement 6.4.3 asks e-commerce merchants to inventory, authorise and continuously integrity-check every script loaded on the payment page, which is the one that most often needs a capability the merchant did not have. Requirement 8 extends MFA from remote access to all access into the cardholder data environment, and raises minimum password length from 7 characters to 12, or a passphrase of at least 15. Requirement 11.3.1.2 makes internal vulnerability scans authenticated. Requirement 5.4.1 adds an explicit anti-phishing obligation. Requirement 10 requires automated mechanisms to detect and alert on security-relevant events. Requirement 12 introduces the customised approach and targeted risk analysis and strengthens third-party service provider management.

What none of that comes with is a price, and the reason is not that we did not look. It is that the answer is genuinely different for every merchant. A shop already enforcing MFA everywhere into the CDE pays nothing for the Requirement 8 change and a shop that is not pays for an identity project, from identical wording in the same standard. The useful 2026 exercise is to walk the future-dated list against your own environment and sort each entry into already-covered, configuration change, or new work. The third pile is your 2026 budget item, and it is the only version of this that has your inputs in it. The full requirement-by-requirement breakdown is on the v4.0 versus v3.2.1 page.

The documents that govern 2026, and their dates

This is the part of a 2026 outlook that can be checked rather than believed. Each of these is the current edition, published by the body it binds, and each one is downloadable.

DocumentCurrent editionWhat it establishes
Mastercard Security Rules and Procedures, Merchant Edition3 February 2026The current Mastercard rulebook, and the most transparent document in payments on this subject. It publishes all four merchant levels and their thresholds in section 2.2.2, and its SDP non-compliance assessment ceilings in section 2.2.5, Table 2.2.
Visa Core Rules and Visa Product and Service Rules18 April 2026The current Visa rulebook. Rule 12.5.1.2 makes assessments payable by the Member rather than the merchant and requires acquirers to verify merchant compliance status at least every six months. Rule 12.5.1.1 routes the PCI non-compliance schedule to the AIS Program Guide, which Visa does not publish.
Visa, What To Do If Compromised, Supplemental Requirements v10.0Effective 25 June 2026Visa's breach-response rulebook, and the source of the Visa assessments that are published. It carries the merchant level thresholds Visa prints publicly, and the footnote recording the 25 April 2024 level 3 and 4 consolidation.
PCI DSS v4.0.1 and the PCI SSC SAQ documentsv4.0.1; future-dated requirements mandatory 31 March 2025The standard itself, the eligibility criteria printed in the front of each SAQ, and the published control counts. The only place your SAQ type is genuinely decided.
American Express Data Security Operating PolicyApril 2026American Express's own four merchant levels and validation requirements. It publishes no assessment schedule and enforces through the merchant agreement.

Rulebook figures on this site last verified 17 July 2026.

Visa and Mastercard no longer agree on how many levels there are

Effective 25 April 2024, Visa consolidated merchant levels 3 and 4 into a unified Level 3. Visa recorded the change itself, as a footnote to the assessment table in What To Do If Compromised v10.0, and was explicit about what it did not do: "Effective 25 April 2024, Visa consolidated merchant levels 3 and 4 into a unified level 3. This consolidation does not introduce any changes to the existing PCI DSS compliance requirements." The current Visa Core Rules match, speaking of "its level 3 Merchants" as the lowest tier and carrying no Level 4 at all.

Mastercard kept all four. Levels 1 to 4 are each defined in section 2.2.2 of its 3 February 2026 rulebook, and Level 4 is not a legacy artefact there; it is the current classification for any merchant Mastercard does not deem Level 1, 2 or 3. So through 2026 the same small merchant is a Visa Level 3 and a Mastercard Level 4 at the same time. That is not a contradiction, it does not need resolving, and it changes nothing about what PCI DSS asks of you. It is a useful test of your sources, though. Anyone still sorting merchants by Visa Level 4 is working from material that predates April 2024, and it is worth wondering what else on their page is that old. The other networks are different again: American Express runs four levels under its April 2026 Data Security Operating Policy, Discover runs three and has no Level 4, and JCB publishes no merchant levels at all, so a JCB row does not belong in a level table however often you see one. The full picture is on the merchant levels page.

What is actually published on price

The honest 2026 price list is short, and knowing precisely what is on it is more useful than any market estimate, because each of these is a real number you can go and read for yourself. What matters as much as the figures is what each one is a price for, because none of them is a market rate.

  • SecurityMetrics, $399 per year for the product it calls "PCI for small businesses" (securitymetrics.com/pci-small-business-pricing, checked July 2026). SecurityMetrics is an ASV and the only one publishing any price. The bundle is built around an external vulnerability scan of a single IP, plus an online SAQ tool and a reporting portal. Its own page carries an asterisk: "Price discounts available depending on merchant processor." This is an anchor for the smallest single-IP merchant, not a rate for anyone larger.
  • Intruder, penetration testing from $3,500 per test (intruder.io/pricing, checked July 2026). A starting price for one scoped product. Intruder is not an ASV and says so plainly, pointing at Tenable as the ASV behind its scanner.
  • Four compliance-automation platforms publish AWS Marketplace list prices on named 12-month dimensions, checked July 2026. Read the dimensions separately, in the table below.
  • Mastercard's SDP assessment ceilings, in its own published rulebook. These are the fines, and they are further down this page.

That is the list. QSA fees, SAQ completion, ASV scanning generally, pen testing generally, remediation and script-monitoring tooling are all quoted per engagement by firms that publish nothing at all, which is why this site prints no bands for them.

PlatformPCI supportAWS Marketplace list price, checked July 2026Best for
VantaPCI DSS SAQ + ROC framework supportEssentials from $14,000/yr (1-20 employees)SaaS and startup teams already on Vanta for SOC 2
DrataPCI DSS SAQ + ROC framework supportPCI DSS framework $7,500/yr, platform fee $25,000/yrMulti-framework teams sharing one evidence base
SecureframePCI DSS supported as a frameworkPlatform $7,500/yr, first framework $7,500/yrTech companies wanting managed onboarding
SprintoPCI DSS SAQ + ROC via partner QSA networkStarter platform $7,500/yr, frameworks from $2,000Cloud-native SMB and mid-market companies

These are list prices read directly off each vendor's AWS Marketplace listing on named 12-month contract dimensions, attributed to the listing rather than to the company, checked July 2026. AWS shows no price-effective date, so the check date is the provenance. Read each dimension on its own and do not add them together: a platform fee and a framework fee are separately listed dimensions, and summing them produces a headline neither vendor published. What you actually pay is a negotiated contract, and the platform does not replace your QSA or your ASV. It automates the evidence work that surrounds them.

A real, dated 2026 market change

LevelBlue completed its acquisition of Trustwave on 19 August 2025, and Trustwave's PCI service page now redirects to levelblue.com. Trustwave was an ASV and its PCI scanning ran on the TrustKeeper portal. That is a genuine, dateable change in the assessor and scanning market, and if you hold a Trustwave contract it is the thing to raise at renewal.

On market pricing more broadly there is nothing to report, and reporting nothing is the accurate thing to do. Ranking firms or tiers by price would require firms to publish prices, and not one of them does, in any tier. What we can tell you is that they are not all the same thing, and the difference that matters is not on a rate card. Qualys and Tenable are ASVs and neither publishes a price for the ASV service. Trustwave, now LevelBlue, is an ASV and publishes no price. Rapid7 and Intruder are not ASVs, and both say so themselves, pointing at MegaplanIT and Tenable respectively for the attestation. That is the fact to act on when buying scanning in 2026: confirm the company signing your report is on the PCI SSC's ASV list, because a very good vulnerability scanner is not the same product as an ASV attestation. Detail is on the scanning and pen test page.

What non-compliance exposes you to, with the published figures

This is the corner of the cost question that does have published numbers behind it, and they do not work the way most pages claim. Card brand assessments are levied on your acquirer, not on you. Visa's Rule 12.5.1.2 is explicit that where a merchant has been deficient in securely maintaining account information, Visa may impose the assessment on the Member. Neither brand has a contract with you. What actually reaches you is set by the indemnity clause of your own merchant agreement, which is a private contract and the only document in which your number exists.

Mastercard SDP assessment1st violation2nd3rd4th
Level 1 and Level 2 merchantsUp to USD 25,000Up to USD 50,000Up to USD 100,000Up to USD 200,000
Level 3 merchantsUp to USD 10,000Up to USD 20,000Up to USD 40,000Up to USD 80,000

Source: Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026, section 2.2.5, Table 2.2. Read the column heading carefully, because it is where most write-ups go wrong: these are ceilings, per violation, per calendar year, and Mastercard's own wording is "up to". They are not monthly, they are not ranges, and they are assessed on the Customer, meaning your acquirer. Mastercard also states that noncompliance "also may result in Merchant termination", which is the tail risk that appears on no fee schedule. Figures last verified 17 July 2026.

Visa publishes no equivalent. Rule 12.5.1.1 routes its PCI DSS non-compliance assessments to the Account Information Security Program Guide, and Visa does not publish that guide, so anyone quoting you a Visa PCI fine schedule is quoting something Visa has not printed. What Visa does publish is breach-response assessments, in What To Do If Compromised v10.0 section 9, and an assessment of up to USD 100,000 per incident under Rule 12.5.1.3 for failing to report a suspected or confirmed compromise within three calendar days. That is the one Visa penalty with a published ceiling, it is charged per incident, and three days is short enough that the plan has to exist before the incident does. Full detail on the penalties page.

How to build a 2026 PCI budget

Start from your own last invoice rather than from anybody's market percentage, ours included. You hold one real data point about what your assessment costs, and no published rate exists to adjust it by, so an adjustment factor from a page like this one would be fiction applied to a fact. Then add the things that are genuinely new for you, which you find by walking the future-dated requirement list against your own environment rather than by reading a forecast.

For any e-commerce merchant on SAQ A-EP, put a discrete Requirement 6.4.3 line in the budget and go and get the quote rather than a placeholder, because it prices against your page count and script volume and nobody can size it from a distance. If your scope stacks PCI with SOC 2 or ISO 27001, evaluate the evidence-automation path explicitly, and evaluate it against the evidence hours it can actually displace rather than against your whole consulting fee. Four vendors publish list prices, which makes one side of that sum checkable; the other side is on your own invoice. If either of those two numbers is missing, you are not doing arithmetic yet.

If you are approaching a tier transition, build 12 to 18 months of runway. The obligation steps rather than sliding: crossing into Mastercard Level 2 means an SAQ A, A-EP or D must additionally be validated by a QSA or a certified ISA, which is a change in who does the work rather than a change in volume. And if you suspect you are overspending, 2026 is the year to run the scope-reduction review, because three questions are answerable from your own environment without any benchmark at all. Are you completing SAQ D when your card data flows would qualify you for something shorter? Are you buying named-firm capability your scope never calls on? Are you running separate framework engagements that could be scoped once? Each compounds, because scope you remove this year is scope you do not assess in any future year either.

Get the official PCI DSS v4.0.1 documentation

The PCI SSC document library carries the full standard, the Summary of Changes, the SAQ templates with their eligibility criteria and control counts, and the reporting templates. Everything on this page is checkable against it and the card brands' own published rulebooks.

PCI SSC document library

Frequently asked

We cannot answer that honestly, so here is why rather than a number. Measuring a year-over-year change in what PCI work costs would need a published 2025 price and a published 2026 price to compare, and neither exists: no QSA firm publishes a rate card or a day rate, no acquirer publishes its PCI fee schedule, no pen test firm publishes rates, and only one ASV publishes any price at all. Any percentage you see for PCI cost inflation is therefore derived from inputs nobody released, which makes it a guess with a decimal point on it. What is real and dated for 2026 is the obligation change. The 51 future-dated PCI DSS v4.0 requirements became mandatory on 31 March 2025, so 2026 is the first full assessment cycle in which all of them apply to every assessment. For e-commerce merchants, Requirement 6.4.3 payment page script management is genuinely new work rather than expanded work, because it needs an ongoing integrity-assurance capability most merchants did not previously own. That is the thing to budget for, and you price it against your own script inventory.

Continue reading