QSA pricing

Coalfire PCI compliance cost 2026: an independent pricing read

Coalfire is the federal-adjacent QSA, and for buyers carrying both PCI and FedRAMP obligations that overlap is the whole argument. What we will not do is tell you what it costs: Coalfire publishes no rates, no QSA firm does, and a number invented here is a number you would budget against. Here is what actually drives the quote instead.

Updated July 2026

Positioning

Federal-adjacent

One of the most active FedRAMP 3PAO firms

Pricing model

Fixed-fee per ROC, day-rate add-ons

Best fit

Level 1, FedRAMP-adjacent, multi-framework

The Coalfire pricing model in plain English

Coalfire prices PCI engagements as fixed-fee proposals scoped to the cardholder data environment (CDE) inventory and the assessment depth required. A Coalfire proposal will name the in-scope systems, the on-site days, the named lead assessor, and the deliverable list (typically the Report on Compliance, the Attestation of Compliance, and a remediation roadmap). Day-rate add-ons cover scope expansions during fieldwork (new acquisitions, new payment channels, environments missed in scoping).

Coalfire does not publish a day rate, and neither does any other QSA firm. No rate card exists on Coalfire's own material, and the PCI SSC directory lists assessors without pricing, so any specific day rate you find attributed to Coalfire traces back to somebody's estimate rather than to Coalfire. We are not going to add another one. What is worth doing is asking Coalfire directly for the assumed day count and the day rate, in writing, because Coalfire prices engagements end-to-end and the rate is rarely visible in the headline proposal even though it governs every change-order you will later be billed for. Ask A-LIGN and Schellman the same question and the three fixed-fee proposals become comparable documents. That question is the leverage; a benchmark you cannot source is not.

Fees are usually billed against milestones rather than in one lump, so ask what triggers each payment and make sure the last one sits at ROC sign-off rather than at the close of fieldwork. Renewals cost less than a first assessment, and that is structural rather than a discount anyone grants you: the scoping is done, the evidence templates exist, and the control mappings carry forward, so there are simply fewer days to buy. How much less is not something we can put a percentage on, because neither the first-year fee nor the renewal is published. Coalfire engagement managers will often propose multi-year terms with year one visible and the later years priced off it, which makes the renewal saving something you can see rather than assume.

Three engagement shapes

What an engagement contains is the part you can pin down before anyone quotes you, and it is the part that decides whether two proposals are comparable. These are the shapes a Coalfire-tier PCI engagement tends to take. Use them to write the brief you send to three firms.

ScenarioEngagement shape
Level 2 retailer (200 stores, P2PE)Three week fieldwork, four named assessors, central-office scoping plus a 5-store sample
Level 1 e-commerce SaaS (single CDE)Three week fieldwork, single-region cloud CDE, Req 6.4.3 script management deep dive
Level 1 fintech (multi-region, FedRAMP overlay)Six week fieldwork, three regional sites, combined PCI ROC plus FedRAMP 3PAO scope assessed as one evidence exercise

The bundling saving in the third row is real: PCI and FedRAMP overlap on evidence, so one firm scoping both collects it once. We cannot size it, because Coalfire publishes no fee for either engagement and neither does anyone else. Ask for the day count assumed behind each shape, the day rate behind the fixed fee, and whether remediation and re-testing are included, then put the identical brief to two other firms.

What makes Coalfire different in the PCI market

Three things, in priority order. First, the federal-adjacent capability. Coalfire Federal is one of the most active FedRAMP Third Party Assessment Organizations, and that bench writes the same security narrative across PCI ROC and FedRAMP SSP work. For SaaS or fintech firms with both a PCI Level 1 obligation and a federal customer pipeline, buying both from Coalfire saves materially on duplicate evidence collection.

Second, the research depth. Coalfire Labs publishes the Coalfire Penetration Risk Report annually, which is one of the most-cited offensive security research products in the industry. Buyers who care about the technical credibility of the assessor (not just the checkbox completion) pay the premium for the Labs association.

Third, the cross-framework engagement model. Coalfire routinely runs combined PCI plus HITRUST plus SOC 2 plus FedRAMP engagements where evidence collection happens once and the four reports are written from the same control implementations. For multi-regulated firms (healthcare SaaS handling payments, fintech with federal customers, payment processors with European PSD2 exposure) this is the cheapest way to buy the stack.

When Coalfire wins and when it does not

Coalfire wins when the buyer needs federal-adjacent PCI work, when the brand recognition matters to enterprise customer procurement teams, and when the engagement requires technical depth beyond the standard QSA control-checkbox exercise. The combined PCI plus FedRAMP path is the single clearest economic win.

Coalfire does not win for Level 4 SAQ attestation, which is a small-merchant product that volume attestation vendors such as SecurityMetrics and ControlScan are built for and a named enterprise QSA firm is not. Nor is it the obvious pick for buyers who want mid-tier commercial scope with no federal dimension, where boutique firms and A-LIGN's mid-market practice are aimed squarely at that work. These are fit judgements rather than price rankings: none of these firms publishes a rate, so we do not claim to know which is cheaper.

How to negotiate a Coalfire PCI engagement

Three tactics, none of which require knowing anyone's rate. First, bring at least one credible comparison proposal from another named-firm QSA on identical scope. The named-firm tier is competitive, and in a market with no published prices a real alternative quote is the only leverage that exists. Second, negotiate the assumptions rather than the headline: the fee is day count multiplied by seniority, and both of those are estimates someone made about your environment, which means both are arguable. Third, put the boundaries in writing. What opens a change-order, what a scope expansion is billed at, whether remediation re-testing is included, and what the renewal is quoted against. Those clauses decide the final invoice more reliably than any discount does.

For combined PCI plus FedRAMP engagements, the negotiation lever is the FedRAMP timeline. If the FedRAMP authorisation is on a flexible timeline, Coalfire will price the combined engagement aggressively to secure the multi-year FedRAMP annuity. Decoupling the two engagements removes that leverage.

Get the official Coalfire QSA listing

Coalfire is listed in the PCI SSC's official Qualified Security Assessor directory. The directory is the canonical source for QSA verification and contact information.

Coalfire on the PCI SSC directory

Frequently asked

Coalfire does not publish PCI pricing, and no QSA firm does, so there is no published figure to give you and we are not going to invent one. What decides a Coalfire quote is documented and worth more than a number: the size of your cardholder data environment, the number of sites needing fieldwork, how many payment channels are in scope, and whether the engagement bundles FedRAMP or HITRUST work alongside PCI. Renewals cost less than a first ROC because the scope is already documented, which is a structural feature of assessments rather than a Coalfire discount. To get your actual number, ask Coalfire for the assumed day count, the day rate behind the fixed fee, and whether remediation and re-testing are included, then put the identical brief to A-LIGN and Schellman.

Continue reading