Cost by level
Level 1 PCI compliance cost: what actually sets the bill
Level 1 is the tier where an annual Report on Compliance is genuinely required, and nobody publishes a price for producing one. So this page gives you what is published: who may sign the ROC, why a confirmed compromise can make any merchant Level 1 whatever its volume, the frequencies the standard fixes, and the seven things a quote is priced against. Then it tells you how to get a real number from the only people who have one.
Updated July 2026
Volume threshold
6M+ tx/yr
Visa, Mastercard and Discover. American Express sets 2.5M
Or any volume at all
By designation
Mastercard may deem any merchant Level 1, expressly including after a confirmed compromise
Validation
Annual assessment producing a ROC Attestation of Compliance
Who may sign it
A QSA, a certified ISA, or an executive officer of the merchant
What defines Level 1, across brands that do not agree
Level 1 thresholds are set per network, and each network counts only its own transactions. Mastercard sets it at more than six million total combined Mastercard and Maestro transactions annually, and additionally deems any merchant meeting Visa's Level 1 criteria to be a Mastercard Level 1 merchant, which is a cross-reference worth noticing: the brands are not independent of each other in the direction you might assume. Visa sets it at more than six million Visa transactions a year. Discover publishes six million or more on Discover Network. American Express sets it lower, at 2.5 million or more American Express transactions a year, per its Data Security Operating Policy dated April 2026. JCB is the exception worth knowing about, because it does not operate merchant levels at all, so nothing about your JCB volume makes you Level 1 and no JCB row belongs in a level table however often you see one.
The practical consequence is that a merchant exceeding any single brand's threshold is Level 1 for that brand, and in practice that tends to set the shape of the whole compliance programme rather than one brand's corner of it. The American Express threshold is the one that arrives first and surprises people, because it sits at well under half the Visa and Mastercard bar. Acquirers vary in how aggressively they apply the upgrade trigger for a merchant hovering at a threshold, some acting at the quarter and some at the annual review, so confirm your designation in writing with yours before you plan anything. The step from Level 2 to Level 1 is not a step in fee, it is a step in kind: an SAQ becomes a Report on Compliance.
Who may actually sign the ROC
This part is published, in Mastercard's own rulebook, and it is more permissive than the market assumes. A Level 1 merchant needs an annual assessment producing a ROC Attestation of Compliance signed by a QSA, a PCI SSC-certified Internal Security Assessor, or an executive officer of the merchant. Three routes, printed in section 2.2.2 of the 3 February 2026 Security Rules and Procedures. Most Level 1 merchants engage a QSA, and most Level 1 pages assume that is the only option, but the ISA route is a real PCI SSC programme rather than a loophole, and it is worth pricing against the QSA quote you actually hold rather than dismissing.
What the ISA route costs is not something this page can tell you, and nor can anyone else who is not the PCI SSC: the Council publishes its ISA programme fees on its own site, so read the current year's figure there. What can be said is the shape of the decision. It is a standing headcount commitment weighed against a recurring external fee, so it turns on your own two numbers rather than on a rule of thumb. It only works where you have staff who can hold the qualification and stay independent of the systems they assess, which is the constraint that rules it out for most organisations that ask about it. And your acquirer can require more than the brand rules do, because what it accepts is a term of your merchant agreement rather than a card brand rule. Confirm the route it will accept before you invest in either one.
The seven things a Level 1 assessment is priced against
There are no dollar figures against these, because a QSA engagement is bought from a market that publishes no price and a range here would be a guess at somebody else's undisclosed fee. What is knowable, and more useful, is what the work is metered on. Notice that your transaction count is not on this list. It decides that you are Level 1; it does not decide what Level 1 costs you.
1
SAQ or full ROC
The largest single fork. Driven by your level and your acquirer, not by preference.
2
Which SAQ type
SAQ A and SAQ D are different orders of magnitude of work. How your checkout is built decides which you get.
3
Size of the cardholder data environment
In-scope systems, applications and data stores. The count of things a QSA must test is the closest thing to a unit of assessment work.
4
Number of payment channels
E-commerce, card-present, phone, recurring billing and marketplace payouts each bring their own control set. Missed channels are the classic mid-engagement change order.
5
Segmentation
Good segmentation removes systems from scope, which is the cheapest lever you have. It also adds segmentation testing.
6
Locations and travel
Multi-site fieldwork multiplies days.
7
Evidence readiness
The one variable you control. A QSA re-requesting evidence is billable time.
The gap between a compact Level 1 engagement and an enterprise one is almost entirely the third and sixth of these, scope and locations, rather than vendor choice. That is the useful part: scope is the thing you can change, and a system that is out of scope is not assessed, not evidenced and not argued about. Vendor choice is where most merchants spend their negotiating energy instead. More on what a QSA prices against.
What the standard fixes, and what it leaves to your scope
PCI DSS sets the test set and the frequency. It does not price either, and no firm that sells the testing publishes a rate. So the honest way to read this table is as the quantity side of your quote: the standard fixes how often, your scope fixes how much, and the multiplication happens in a proposal rather than on this page.
| Activity | Frequency | Requirement | What it is priced against |
|---|---|---|---|
| External ASV vulnerability scanning | Four passing scans a year | Requirement 11.3.2 | The quantity is fixed by the standard, so the only variable left in the quote is your external target count. |
| External penetration test | At least annually, and after significant change | Requirement 11.4.3 | Priced in tester days, which follow the count of external IPs and exposed services, applications and APIs. |
| Internal penetration test | At least annually, and after significant change | Requirement 11.4.2 | Priced against the size of the internal estate in scope and the number of segments in it. |
| Segmentation validation test | At least every 12 months for merchants, and after any change to segmentation controls | Requirement 11.4.5 | The six-month cadence in Requirement 11.4.6 applies to service providers, not to merchants. If you are being quoted twice a year as a merchant, ask which requirement it is being quoted against. |
| Wireless access point detection | At least quarterly | Requirement 11.2.1 | Priced against the number of physical sites, and whether detection is automated or a walkthrough. |
Frequencies are read off PCI DSS v4.0.1. The segmentation row is the one most often misquoted: Requirement 11.4.5 sets at least every 12 months for all entities, and the six-month cadence in Requirement 11.4.6 applies to service providers only. If you are a merchant being quoted for twice-yearly segmentation testing, ask which requirement it is being quoted against before you pay for it.
The lines that are not in the proposal
The line that most often blows a Level 1 budget is not the assessment fee. It is one of these, and the first is frequently larger than the fee itself.
- Remediation after gaps are found, which is often the largest line and is not always in the headline fee
- Your own staff's time collecting evidence, which never appears in the proposal
- Re-assessment if you fail and need a re-test
- Travel and on-site fieldwork for multi-location operations
- Scope expansion mid-engagement when undocumented systems surface
- Tooling bought to satisfy a specific control, such as SIEM, FIM or MFA
Remediation deserves its own sentence, because it is the line that makes Level 1 budgets look wrong in retrospect. It is not really an assessment cost at all: it is the cost of the gap between how your environment is and how it needs to be, and it runs from a configuration change to an encryption or segmentation project. Nobody can quote it before fieldwork, including the firm that will bill it. The only thing that reduces it is finding the gaps before an assessor does, because gaps closed before fieldwork are not billed as change orders. That is also why a renewal costs less than a first ROC for a structural reason rather than as a discount: the scoping is done and the evidence templates carry forward.
What non-compliance actually exposes a Level 1 merchant to
This is the part of the cost question with published figures behind it, and they do not work the way most pages claim. Card brand assessments are levied on your acquirer, not on you. Visa's rule is explicit that where a merchant has been deficient in securely maintaining account information, Visa may impose a non-compliance assessment on the Member. Mastercard's Table 2.2 assesses the Customer. Neither brand has a contract with you. What reaches you is set by the indemnity clause of your own merchant agreement, which is a private contract and the only document where your number exists. At Level 1 that clause is usually negotiable and almost never negotiated.
| Mastercard SDP assessment, Level 1 and Level 2 merchants | 1st violation | 2nd | 3rd | 4th |
|---|---|---|---|---|
| Ceiling per violation, per calendar year | Up to USD 25,000 | Up to USD 50,000 | Up to USD 100,000 | Up to USD 200,000 |
Source: Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026, section 2.2.5, Table 2.2. Read the column heading carefully: these are ceilings, per violation, per calendar year, and Mastercard's own wording is "up to". They are not monthly, they are not ranges, and they are assessed on the Customer, meaning your acquirer. Mastercard sets Level 1 and Level 2 merchants in the same band, at a higher one than Level 3. Mastercard also states that noncompliance may result in merchant termination, which is the tail risk that appears on no fee schedule and is the one that matters at this volume.
Visa publishes no routine schedule for PCI DSS non-compliance at all. Rule 12.5.1.1 routes that to the Account Information Security Program Guide, which Visa does not publish, so anyone quoting you a Visa PCI fine schedule is quoting something Visa has not printed. What Visa does publish is its breach-response assessments:
| Visa breach-response assessment | Threshold | Assessment |
|---|---|---|
| Level 1 merchants | > 6,000,000 annual transactions | USD $100K |
| Investigation fee, Level 1 and Level 2 merchants, VisaNet Processors, Members, Agents | PFI open past the four-month grace period | USD $10,000 per month until the investigation is properly completed |
Sources: Visa, What To Do If Compromised, Visa Supplemental Requirements v10.0, effective 25 June 2026, section 9 for the assessment and section 8 for the investigation fee. These attach to the WTDIC breach-response requirements rather than to PCI DSS non-compliance generally. Visa sets the same USD 100,000 figure for issuers, acquirers and VisaNet processors as for Level 1 and Level 2 merchants. Separately, Rule 12.5.1.3 provides for an assessment of up to USD 100,000 per incident for failing to report a suspected or confirmed compromise to Visa within three calendar days. That is the one Visa penalty with a published ceiling, it is charged per incident, and the clock is short enough that the plan has to exist before the incident does. Figures last verified 17 July 2026; full detail on the penalties page.
Get the official PCI SSC Reporting Guide
The PCI SSC publishes the ROC template, the Reporting Instructions and the SAQ documents in its official document library, and its ISA programme fees on its own site. Reading the ROC template before you scope the engagement is free, and it is the fastest way to see what your evidence burden actually looks like.
Frequently asked
Nobody publishes this, and that is the honest answer rather than an evasion. No QSA firm publishes a rate card or a day rate, no penetration testing firm publishes a rate, no acquirer publishes its PCI fee schedule, and only one ASV publishes any price at all. Every specific Level 1 total in circulation, including the ones attributed to named firms, traces back to somebody's estimate rather than to a published rate. What can be given honestly is the checklist, which is the part people actually get wrong. A Level 1 year one is the assessment fee for the Report on Compliance, external and internal penetration testing, segmentation validation testing if you rely on segmentation to keep scope down, quarterly ASV scanning, whatever tooling the control set requires that you do not already run, and remediation of whatever the assessment finds. That last line is the wildcard and is often the largest, because it is not really an assessment cost at all: it is the cost of the gap between how your environment is and how it needs to be. Renewals cost less than a first ROC for a structural reason rather than a discount, since the scoping is done and the evidence templates carry forward. Price it by giving two or three QSA firms an identical written brief and asking each for the assumed assessor day count, the day rate behind the fixed fee, and whether remediation and re-testing are included.
Continue reading
Level 2 PCI cost
Where Mastercard's rules pull a QSA or ISA into a self-assessment.
Level 3 PCI cost
The tier Visa and Mastercard no longer define the same way.
QSA assessment cost
Why no firm publishes a rate, and the seven things a quote is priced against.
Reduce PCI costs
Scope reduction, sized in controls rather than guesses.
PCI penalties
What Visa and Mastercard actually publish, and what they do not.
2026 outlook
What changes in PCI this year.