By industry

PCI compliance cost by industry

The standard is the same across sectors. The scope is not. A Stripe-powered e-commerce store and a chain restaurant land on different SAQ types, answer different numbers of controls, and get quoted accordingly. Here is what drives the bill in each one, and the trap each sector falls into.

Updated July 2026

What sets the cost in each sector

IndustryTypical levelCommon SAQWhat drives the bill here
Retail (Brick & Mortar)Level 3-4SAQ B-IP, C, or P2PEPOS terminal security, wifi network segregation, multi-location consistency, seasonal staff training, POS device tampering inspection.
E-commerceLevel 3-4SAQ A or A-EPPayment page script security (Req 6.4.3), JavaScript monitoring, third-party code on checkout pages, SAQ A vs A-EP determination.
Restaurant & HospitalityLevel 4SAQ B-IP or P2PETip adjustment and pre-auth flows, card-present terminals in high-traffic areas, hotel booking systems storing card data, staff turnover.
HealthcareLevel 4SAQ C or DPCI + HIPAA overlap, patient payment portals, legacy systems in clinical environments, network segmentation complexity.
SaaS & Subscription BillingLevel 2-3SAQ D (Service Provider)Recurring card-on-file storage, service provider obligations, multi-tenant environments, API security, higher scope than merchants.
Call CentreLevel 2-4SAQ C-VT or DDTMF masking for phone payments, call recording with card data, agent access controls, clean desk policy, screen capture prevention.

Sector

Retail (Brick & Mortar)

The SAQ below is the one this sector usually lands on. It is the closest thing to a cost signal we can give you honestly, because it fixes how many controls you answer.

Level
Level 3-4
SAQ
SAQ B-IP, C, or P2PE

Where the money goes

POS terminal security, wifi network segregation, multi-location consistency, seasonal staff training, POS device tampering inspection.

Recommended approach

Implement P2PE terminals to minimise scope. Segment wifi from payment network. Standardise configurations across locations.

Sector

E-commerce

The SAQ below is the one this sector usually lands on. It is the closest thing to a cost signal we can give you honestly, because it fixes how many controls you answer.

Level
Level 3-4
SAQ
SAQ A or A-EP

Where the money goes

Payment page script security (Req 6.4.3), JavaScript monitoring, third-party code on checkout pages, SAQ A vs A-EP determination.

Recommended approach

Use hosted payment pages (Stripe Checkout, PayPal) for SAQ A. If custom checkout, implement script monitoring and CSP headers.

Sector

Restaurant & Hospitality

The SAQ below is the one this sector usually lands on. It is the closest thing to a cost signal we can give you honestly, because it fixes how many controls you answer.

Level
Level 4
SAQ
SAQ B-IP or P2PE

Where the money goes

Tip adjustment and pre-auth flows, card-present terminals in high-traffic areas, hotel booking systems storing card data, staff turnover.

Recommended approach

Use P2PE terminals for tableside payment. Avoid storing card data for reservations. Train staff on POS device inspection.

Sector

Healthcare

The SAQ below is the one this sector usually lands on. It is the closest thing to a cost signal we can give you honestly, because it fixes how many controls you answer.

Level
Level 4
SAQ
SAQ C or D

Where the money goes

PCI + HIPAA overlap, patient payment portals, legacy systems in clinical environments, network segmentation complexity.

Recommended approach

Bundle PCI with HIPAA compliance programme. Segment payment systems from clinical network. Use tokenization for patient payment portals.

Sector

SaaS & Subscription Billing

The SAQ below is the one this sector usually lands on. It is the closest thing to a cost signal we can give you honestly, because it fixes how many controls you answer.

Level
Level 2-3
SAQ
SAQ D (Service Provider)

Where the money goes

Recurring card-on-file storage, service provider obligations, multi-tenant environments, API security, higher scope than merchants.

Recommended approach

Tokenize all stored card data via payment gateway. Implement strong API authentication. Consider SOC 2 + PCI combined assessment.

Sector

Call Centre

The SAQ below is the one this sector usually lands on. It is the closest thing to a cost signal we can give you honestly, because it fixes how many controls you answer.

Level
Level 2-4
SAQ
SAQ C-VT or D

Where the money goes

DTMF masking for phone payments, call recording with card data, agent access controls, clean desk policy, screen capture prevention.

Recommended approach

Implement DTMF masking to descope call recordings. Use virtual terminals with auto-clearing. Deploy agent-level access controls.

Need an independent assessment?

Our partner network includes QSAs and ISAs across all merchant levels. Costs vary by scope and QSA fees are quoted independently. We do not endorse a specific firm.

Find a QSA in the PCI SSC directory

Frequently asked

Yes. Every business that accepts, stores, processes, or transmits card data must comply with PCI DSS, regardless of size. The bar is lower for small merchants (typically SAQ A or SAQ B-IP) but it is not zero. A merchant on a fully hosted checkout answering SAQ A faces around 24 controls, against roughly 251 on SAQ D, and that gap is the whole reason the architecture choice matters more than any negotiation. The one published price at this end of the market is SecurityMetrics' small-business bundle at $399 per year (securitymetrics.com, checked July 2026), which covers a single-IP scan and an SAQ portal rather than a general market rate.

Continue reading