QSA engagements
What a PCI QSA assessment costs
No QSA firm publishes a rate card, a day rate, or a sample fee. So this page does not print one either. What it does instead is tell you exactly what a QSA prices against, so you can go and get the number from the only people who have it.
Updated July 2026
Who actually needs a QSA
This part is published, in Mastercard's own rulebook, and it is more permissive than most people assume.
| Level | What the rules require |
|---|---|
| Level 1 | An annual assessment producing a ROC Attestation of Compliance, signed by a QSA, a PCI SSC-certified ISA, or an executive officer of the merchant. The ISA route is real and is often overlooked. |
| Level 2 | An annual SAQ. But merchants completing SAQ A, SAQ A-EP or SAQ D must additionally engage a QSA or a certified ISA for validation. This is the rule most Level 2 merchants have not read. |
| Level 3 and Level 4 | An SAQ. A QSA-led ROC is available by choice, not by requirement. |
Source: Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026, section 2.2.2. Your acquirer can require more than this under your merchant agreement, and some do.
The seven things a QSA prices against
Answer these seven, hand the identical set to three firms, and you get three comparable quotes. That is the whole method, and it works better than any benchmark because it produces your number rather than someone else's.
1
SAQ or full ROC
The largest single fork. Driven by your level and your acquirer, not by preference.
2
Which SAQ type
SAQ A and SAQ D are different orders of magnitude of work. How your checkout is built decides which you get.
3
Size of the cardholder data environment
In-scope systems, applications and data stores. The count of things a QSA must test is the closest thing to a unit of assessment work.
4
Number of payment channels
E-commerce, card-present, phone, recurring billing and marketplace payouts each bring their own control set. Missed channels are the classic mid-engagement change order.
5
Segmentation
Good segmentation removes systems from scope, which is the cheapest lever you have. It also adds segmentation testing.
6
Locations and travel
Multi-site fieldwork multiplies days.
7
Evidence readiness
The one variable you control. A QSA re-requesting evidence is billable time.
What an engagement contains
Four phases. No percentages attached, because any split we printed would be invented, and the split varies enormously with how ready your evidence is.
Scoping and planning
Define the cardholder data environment and its boundaries. This is where your fee is really set, because everything downstream is priced off the scope agreed here.
Evidence collection and testing
Control testing, document review, interviews, technical validation, on-site or remote. The longest phase, and the one your own preparation shortens most.
Report writing
Drafting the ROC, compiling evidence, writing the executive summary.
Remediation and re-testing
Closing gaps found during fieldwork and re-testing them. Often billed separately. Ask which, before you sign.
Costs that are not in the proposal
The line that most often blows a PCI budget is not the assessment fee. It is one of these.
- Remediation after gaps are found, which is often the largest line and is not always in the headline fee
- Your own staff's time collecting evidence, which never appears in the proposal
- Re-assessment if you fail and need a re-test
- Travel and on-site fieldwork for multi-location operations
- Scope expansion mid-engagement when undocumented systems surface
- Tooling bought to satisfy a specific control, such as SIEM, FIM or MFA
The authoritative list of QSAs
The PCI Security Standards Council maintains the only official QSA directory. Filter by region and scheme. Pricing is quoted per engagement, direct from the firm; the directory carries none, because no firm publishes any.
Frequently asked
Nobody publishes this, and that is the honest answer rather than an evasion. No QSA firm publishes a rate card, a day rate or a sample fee, and the PCI SSC directory lists assessors without pricing. Any specific figure you find, including ones attributed to named firms, traces back to somebody's estimate rather than to a published rate. What we can tell you is what a QSA prices against: SAQ or full ROC, which SAQ type, the size of your cardholder data environment, how many payment channels feed it, whether it is segmented, how many locations need fieldwork, and how ready your evidence is. Fix those seven answers, give the same set to three firms, and you will get comparable quotes. That is the only reliable way to find out what your assessment costs.
Continue reading