QSA pricing

A-LIGN PCI compliance cost 2026: an independent pricing read

A-LIGN is built around the multi-framework buyer. If you need PCI alongside SOC 2 or ISO 27001, one engagement produces evidence once instead of three times, and that overlap is the real argument. Whether A-LIGN prices it better than anyone else is not something we can tell you: no QSA firm publishes rates, so this page carries no figures and no rankings.

Updated July 2026

Positioning

Multi-framework

QSA, ASV, P2PE QSA, 3PAO, HITRUST, ISO CB

Pricing model

Fixed-fee, multi-framework scope

Best fit

Mid-market commercial, combined PCI + SOC 2

The A-LIGN pricing model in plain English

A-LIGN prices PCI engagements as fixed-fee proposals with scope tied to the cardholder data environment inventory, named on-site days, and the deliverable list. The proposal will name the lead assessor and the backup assessor (a useful detail to confirm), the on-site versus remote split of fieldwork, and the inclusion or exclusion of pen testing. Pen testing is sometimes bundled and sometimes priced as an explicit add-on; ask explicitly during scoping.

The multi-framework angle is where A-LIGN's pitch genuinely differs from the comparator firms, and the mechanism is worth understanding even though the saving is not a number anyone publishes. A-LIGN's evidence collection portal cross-maps controls across frameworks, so a single artefact (a logical access policy, a vulnerability management procedure, a vendor management programme) is collected once and applied to every control it satisfies, across every framework in scope. Buy the frameworks separately and that artefact gets requested, produced, reviewed and charged for twice. That is a real efficiency with a real cause. Its size on your engagement depends on how much your scopes overlap, so treat the standalone-versus-bundled quote pair as the measurement rather than trusting any headline saving, ours or a vendor's.

A-LIGN does not publish a day rate, and neither does any QSA firm we can find, so this page does not rank A-LIGN against Coalfire or Trustwave on price. There are no published rates to rank. What is worth asking A-LIGN for in writing is the assumed day count, the day rate behind the fixed fee, and the specific triggers that would open a scope-expansion change-order. Ask whether a multi-year term changes any of those. Those answers are the comparison; a league table of rates nobody publishes is not.

Three engagement shapes

What the engagement contains is knowable before anyone quotes you, and it is what makes two proposals comparable. These are the shapes an A-LIGN commercial engagement tends to take. Use them to write one brief and send it to three firms.

ScenarioWhat is included
Level 2 SaaS (single-region cloud CDE)SAQ D walkthrough or Level 1 ROC, two week fieldwork, external pen test, evidence portal access
Level 1 e-commerce + SOC 2 Type 2 bundleCombined PCI ROC plus SOC 2 Type 2, three week fieldwork, shared evidence collection
Level 1 fintech + SOC 2 + ISO 27001 bundleCombined three-framework engagement, four week fieldwork, single evidence package, three reports

Ask A-LIGN which shape it is assuming, the day count behind it, the day rate behind the fixed fee, and whether remediation and re-testing are included. For the bundled rows, ask for the standalone quote alongside the combined one: the gap between them is the bundle value for your scope, and it is the only version of that figure anyone can stand behind.

What multi-framework efficiency actually buys you

PCI DSS 4.0, SOC 2 Common Criteria, ISO 27001 Annex A and HITRUST CSF ask different questions but lean on a lot of the same underlying evidence: who has access to what, how access is granted and revoked, what gets logged and who reads the logs, how changes reach production, how vulnerabilities are found and fixed. Nobody publishes an authoritative overlap percentage between any two of these, and the honest reason is that the overlap depends on your control implementations, not on the frameworks in the abstract. What holds regardless: the evidence for the second framework is largely evidence you have already produced for the first.

When you engage separate firms for each framework, that overlap is paid for twice. The PCI auditor collects a logical access policy, the SOC 2 auditor collects effectively the same logical access policy, and each charges fieldwork hours to do it. A combined A-LIGN engagement collects it once and applies it to both control sets. How much that saves you is not a number we can hand you, because it depends on how much your two scopes actually share, and because neither the combined fee nor the standalone fee is published by anyone. It is a number you can get in a week: ask for both quotes on the same brief and subtract.

The trade-off is engagement-team breadth. A-LIGN's combined engagements use cross-trained assessors who carry both PCI QSA and AICPA SOC 2 audit credentials. For most commercial mid-market buyers, this works well. For buyers with very specialised regulatory overlay (cardholder data flow patterns unique to airlines, hospitality multi-property structures, healthcare network-segmentation nuances), a specialist-per-framework approach can still produce better assessor questions despite the higher total cost.

When A-LIGN wins and when it does not

A-LIGN wins when the buyer has combined PCI plus SOC 2 obligations, when the buyer wants mid-market commercial economics rather than enterprise pricing, and when the buyer values evidence-portal automation and engagement-team continuity year over year. For Series B through mid-cap commercial buyers with multi-framework obligations, the case for putting A-LIGN on the shortlist is the bundling economics rather than any price advantage we can evidence.

A-LIGN does not win when the buyer needs federal-adjacent depth where Coalfire's FedRAMP bench is materially deeper, when the buyer wants a single-framework Level 4 SAQ attestation, which is a small-merchant product the volume attestation vendors are built for and a named QSA firm is not, or when the buyer needs the largest pure-play QSA brand recognition (Schellman's published ROC volume is genuinely larger, though the practical difference for procurement teams is small).

How to negotiate with A-LIGN

Three tactics that work reliably. First, lead with multi-framework scope even if you are not 100 percent committed to all frameworks in year one. A-LIGN's pricing model rewards multi-framework scope, and proposing a combined engagement up front anchors the conversation at the bundled rate. Second, ask for the day count and day rate assumptions explicitly so the fixed-fee comparison with Coalfire or Schellman is apples to apples. Third, ask what remediation support and re-testing are included versus billed separately, because that single answer moves a proposal more than any negotiated percentage, and it is the most common reason two QSA quotes are not comparable documents.

For combined engagements, ask whether A-LIGN can guarantee a single point-of-contact engagement manager across all frameworks. A single PM is operationally significantly easier than coordinating across multiple framework leads, even though all named-firm QSAs technically offer it. The PM question is also a useful proxy for how serious A-LIGN is about your engagement at the proposed fee.

A-LIGN on the PCI SSC directory

A-LIGN is listed in the official PCI SSC Qualified Security Assessor and Approved Scanning Vendor directories.

Verify on pcisecuritystandards.org

Frequently asked

A-LIGN does not publish PCI pricing, and no QSA firm does, so this page carries no figure for it. What drives an A-LIGN quote is the size of your cardholder data environment, the number of payment channels in scope, and above all whether you are buying PCI alone or bundling it with SOC 2, ISO 27001 or HITRUST. That last one is the real A-LIGN question, because a combined engagement reuses evidence, interviews and control mappings across frameworks, and that overlap is structural rather than a discount. Ask A-LIGN to quote PCI standalone and PCI bundled, side by side, and the value of the bundle becomes a number you can actually see.

Continue reading