QSA pricing

ControlScan PCI compliance cost 2026: an independent pricing read

ControlScan is the mid-market QSA. After the Sysnet acquisition and the VikingCloud rebrand, it leans hard into acquirer portal partnerships at the SMB end, which means many merchants meet it through their processor rather than by choosing it. It publishes no rates, and no QSA firm does, so this page ranks nobody on price.

Updated July 2026

Positioning

SMB to mid-market

Often reaches merchants via the acquirer's portal

Pricing model

Portal + mid-market QSA consulting

Best fit

Mid-market commercial, compact Level 1

The ControlScan pricing model in plain English

ControlScan operates two product lines that behave very differently, and the distinction matters more than any price. The first is the SMB compliance portal: SAQ attestation with bundled ASV scanning, sold direct or through acquirer-bank partnerships as an annual subscription. The second is the mid-market QSA consulting practice, where Level 2 and compact Level 1 ROC engagements are quoted as fixed-fee proposals scoped to your environment. Neither line has a published price, so we carry no figure for either. The practical consequence of the split: the first is a product you subscribe to, the second is an engagement you scope, and they are not comparable purchases even though the same brand sits on both.

ControlScan does not publish day rates, and neither do the named firms it competes with, so the claim that it sits some percentage below them is not one anybody can actually make. There are no published rates on either side of that comparison. What can be said is that its positioning targets the mid-market rather than multi-region enterprise scope, and that the way to test any such pitch is to give ControlScan and one named firm an identical brief, then compare the assumed day count, the day rate behind each fixed fee, and what each excludes. On a compact single-region engagement that exercise is cheap to run and it produces real numbers instead of borrowed ones.

Multi-year terms are available and we put no discount figure on them, for the same reason we put none on the fee itself. Do insist that scope-expansion triggers are documented in the contract rather than left to the renewal conversation. The VikingCloud parent context, following the December 2020 Sysnet acquisition, means ControlScan also cross-sells VikingCloud's adjacent compliance and scanning products into its customer base. That is a useful integration for some buyers and noise for others, and it is worth deciding which you are before the account team decides for you.

Three engagement shapes

What a proposal contains is more useful to you than a guess at what it costs, because the contents are what you can compare across firms and negotiate. These are the three shapes a ControlScan brief most often takes, and the first two are products rather than engagements.

ScenarioWhat the engagement contains
Level 3 multi-store retailer (20 IP terminals)SAQ B-IP attestation, quarterly ASV scanning, multi-location scope, compliance portal access, sold as an annual subscription
Level 2 SaaS (SAQ D with assist)SAQ D self-completion with consultant assist, evidence review, quarterly ASV scanning
Compact Level 1 ROC (single-region commercial)Full ROC, two to three week fieldwork, external pen test bundled, ASV scanning bundled

At the top two rows, check your merchant statement and your processor's portal before you shop. Your acquirer has often already picked an attestation vendor and bundled it into your agreement, so the first question is whether you are buying this at all rather than what it costs. For the ROC row, give three firms an identical brief and ask each for the assumed day count, the day rate behind the fixed fee, and whether pen testing, remediation and re-testing sit inside the fee or beside it.

The Sysnet acquisition and VikingCloud context

ControlScan's commercial positioning shifted through M&A. In December 2020 Sysnet Global Solutions acquired ControlScan's Managed Compliance Solutions division, pulling the compliance business toward the SMB-via-acquirer-portal channel that is Sysnet's commercial strength. Sysnet then unified its acquired brands (Sysnet, SecureTrust, NuArx, and ControlScan) under the VikingCloud name, bringing the ControlScan products into VikingCloud's broader compliance and scanning portfolio. The QSA practice itself remained intact through the transition and continues to be listed on the PCI SSC directory.

For buyers, the practical effect is a wider product surface available through the ControlScan relationship and a stronger pull toward acquirer-led SAQ workflows. What we cannot tell you is what the acquisitions did to the price, in either direction. QSA fees were not published before Sysnet and are not published now, so there is no before-and-after to compare and nobody is in a position to claim one. The change you can actually observe is in the channel and the product surface, not the invoice.

Buyers who want pure QSA work without the VikingCloud adjacent-product cross-sell should signal that clearly during scoping. The engagement team will scope the consulting work cleanly without bundle pressure, but the account team may continue to surface the wider VikingCloud product portfolio in renewal conversations. For buyers who do want integrated compliance-monitoring and scanning products beyond the QSA work, the VikingCloud portfolio is a genuine differentiator versus pure-play QSAs.

When ControlScan wins and when it does not

ControlScan is a good fit for SMB SAQ attestation reached through an acquirer-portal relationship, for mid-market SAQ D with-assist engagements where a consulting bench helps but enterprise scope is not in play, and for compact Level 1 ROC engagements whose complexity does not exceed what a mid-market bench is sized for. Note what those three have in common: they are scopes where the extra capability of a named firm would go unused. That is the argument for the mid-market tier, and it stands without knowing what anybody charges.

ControlScan is the wrong fit for multi-region Level 1 ROC engagements, where Coalfire, A-LIGN and Schellman are better equipped; for federal-adjacent PCI work, where Coalfire's FedRAMP bench is genuinely deeper; for engagements stacking PCI with SOC 2 and ISO 27001, where A-LIGN and Schellman are credentialed across the whole set and can run them as one engagement; and for buyers who want their assessor independent of VikingCloud's adjacent product portfolio. Each of those is a capability or independence judgement, not a price one.

How to negotiate with ControlScan

For SAQ-tier products, negotiation room is similar to SecurityMetrics: minimal on direct-buyer pricing, more available on multi-year commitments and volume purchases. For mid-market QSA engagements, the negotiation room is wider. Bring a comparison quote from SecurityMetrics (for compact ROCs) or from a regional boutique (for engagements where ControlScan and the boutique are at parity capability), and ask ControlScan to respond to it. A competing quote on an identical brief is the only leverage that reliably works, and it works because it is specific to your scope rather than to any published benchmark.

For engagements where the buyer wants the VikingCloud adjacent-product cross-sell (continuous compliance monitoring, ASV scanning, breach response retainer), bundling these explicitly during contract negotiation produces materially better pricing than buying them post-engagement. The integrated proposal is where ControlScan's commercial advantage from the VikingCloud platform genuinely lands.

ControlScan on the PCI SSC directory

ControlScan is listed in the official PCI SSC Qualified Security Assessor directory and the PCI SSC Approved Scanning Vendor directory.

Verify on pcisecuritystandards.org

Frequently asked

ControlScan does not publish PCI pricing, and neither do the named firms it is usually compared against, so this page gives no figures and no percentage gap between them. What is real is the positioning: ControlScan targets the SMB to mid-market range, from SAQ attestation products up to compact ROC engagements, rather than multi-region enterprise scope. For a large or multi-region Level 1 assessment the named firms are better equipped, and that is a capability judgement rather than a pricing one. If ControlScan is on your shortlist, put it and one named firm on an identical brief and compare the assumed day count, the day rate behind each fixed fee, and what each excludes.

Continue reading