Reference / Trust surface

Which numbers here are facts, and which are our model

Two kinds of number appear on this site. They are not the same kind of thing, and the difference between them is the whole methodology.

A fact is quoted from a named primary document, carries the document's name and the date we checked it, and can be verified without our help. A model figure is our arithmetic over inputs you can see, where you could redo the sum on paper. Nothing in between ships. If we cannot source a number and cannot honestly model one, we write nothing and say why, which on this subject happens a lot.

The facts, and where they come from

Every card brand figure on this site was read off the brand's own published rulebook, not off a summary of it. Rules last checked 17 July 2026.

  • Visa Core Rules and Visa Product and Service Rules, 18 April 2026, published by Visa as a public document. Source for how assessments are levied, and for the fact that Visa routes its PCI DSS non-compliance schedule to a guide it does not publish.
  • Visa, What To Do If Compromised, Supplemental Requirements v10.0, effective 25 June 2026. Source for Visa's published breach-response assessments, its investigation fees, its forensic investigation timelines, and its statement that it consolidated merchant levels 3 and 4 on 25 April 2024.
  • Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026. Source for all four Mastercard merchant levels, their validation requirements, and the SDP noncompliance assessment ceilings in Table 2.2. Mastercard is the most transparent of the four brands and prints its schedule in full.
  • PCI Security Standards Council published guidance. The standard text itself, SAQ types and applicability, and the assessor, ASV and PFI directories.
  • Vendor list prices, read off the listing. Where a vendor genuinely publishes a price, we cite it to the surface it is published on, quote the dimension as published, and carry the date we checked. The compliance automation platforms publish real list prices on AWS Marketplace; those are cited per dimension and never summed into a headline total, because AWS publishes no combined figure.
  • SEC filings, regulator orders and statutes. Breach cost figures come from the company's own filing or the regulator's own order, named in each case. State law liability is cited to the statute.

Why there are no cost ranges on this site

Here is the uncomfortable centre of a PCI cost site: nobody publishes PCI prices. Not one QSA firm publishes a rate card or a day rate. Only one ASV publishes any price at all. No acquirer or processor publishes its PCI fee, because that fee is a term of your individual merchant agreement. The PCI SSC directories list assessors without pricing.

That leaves exactly one honest position, and it is stricter than the one most sites take. A model is our arithmetic over inputs you can see, where you could redo the sum yourself. A guess at a third party's undisclosed price is not a model, whatever we label it. “Our estimate of what a QSA charges” has no checkable inputs, and it lands in your head as “a QSA costs about that much”, which is a fact we do not have. Calling it an estimate does not fix that. It puts a respectable word where a citation should be.

So the test every number here has to pass is simple: can you see the inputs and redo the arithmetic? If yes, it is a model and it ships. If no, we are guessing, and it does not. That is why this site carries no cost band for QSA work, SAQ completion, ASV scanning, pen testing, remediation or tooling. Not a labelled one, not a hedged one, not one behind a disclaimer. A cost site with no invented costs on it is the point, not a compromise.

What you get instead is the part that is real: what each line is priced against, the published control counts that decide how much work you are buying, the frequencies PCI DSS itself fixes, and the handful of prices that genuinely are published, each quoted to its source with the date we checked it. The calculator supplies no rates of its own; it multiplies rates you enter from quotes you hold by quantities either you set or the standard sets, and shows you every one.

The reliable method is the one we give on the QSA cost page: fix your scope, hand two or three firms an identical brief, and ask each for the assumed day count, the day rate behind the fixed fee, and whether remediation and re-testing are included. That produces your number. Nothing we could have printed here would have.

What we refuse to publish

  • A monthly PCI fine schedule. The escalating monthly schedule that circulates widely is not published by any card brand. Mastercard's real published assessments are per violation per calendar year, as ceilings. Visa publishes none for non-compliance itself.
  • QSA day rates, or firm-by-firm price rankings. No firm publishes rates, so a claim that one sits some percentage below another is a statistic computed from inputs that do not exist. We do not publish one in either direction.
  • Per-processor PCI fee amounts. Yours is on your statement, and that is the only place it exists.
  • Aggregator or forum data as pricing provenance. Aggregators of self-reported buyer data are not primary sources, and a forum thread is not a rate card. Neither is cited here.
  • Structured price offers for other companies. We do not emit Offer or priceRange schema for third-party products. We are not the seller, and machine-readable prices are exactly where an error does the most damage.

Update cadence

Facts are re-read against the source document. Triggers:

  • A new edition of the Visa Rules, Visa WTDIC, or the Mastercard Security Rules and Procedures.
  • A change to merchant level definitions by any brand.
  • PCI DSS version transitions and future-dated requirements becoming mandatory.
  • A change to a vendor's published list price on the surface we cite.

When a figure changes, the page, the FAQ, the structured data and llms.txt all change together. A correction that leaves the machine-readable feed stale has not been made. Cosmetic date bumps are not.

Editorial position

This site is operated by Digital Signet, an independent AI-development studio. We do not act as a QSA, do not sell tokenisation or scope-reduction services, and do not run a penetration testing practice, so no assessment or tooling revenue depends on the figures. Where the site carries a disclosed sponsor or affiliate placement, it is labelled and kept out of the cost data, rankings, and conclusions. See /about for the operator and the wider network.

Editorial direction is set by the Digital Signet editorial team. Drafts are produced via Digital Signet's autonomous AI development methodology and reviewed against the editorial framework before publication.

Contact

If a figure here is wrong, or you can point to a primary document we have missed, we want to know: [email protected].