QSA engagements

What a PCI QSA assessment costs

No QSA firm publishes a rate card, a day rate, or a sample fee. So this page does not print one either. What it does instead is tell you exactly what a QSA prices against, so you can go and get the number from the only people who have it.

Updated July 2026

Who actually needs a QSA

This part is published, in Mastercard's own rulebook, and it is more permissive than most people assume.

LevelWhat the rules require
Level 1An annual assessment producing a ROC Attestation of Compliance, signed by a QSA, a PCI SSC-certified ISA, or an executive officer of the merchant. The ISA route is real and is often overlooked.
Level 2An annual SAQ. But merchants completing SAQ A, SAQ A-EP or SAQ D must additionally engage a QSA or a certified ISA for validation. This is the rule most Level 2 merchants have not read.
Level 3 and Level 4An SAQ. A QSA-led ROC is available by choice, not by requirement.

Source: Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026, section 2.2.2. Your acquirer can require more than this under your merchant agreement, and some do.

The seven things a QSA prices against

Answer these seven, hand the identical set to three firms, and you get three comparable quotes. That is the whole method, and it works better than any benchmark because it produces your number rather than someone else's.

1

SAQ or full ROC

The largest single fork. Driven by your level and your acquirer, not by preference.

2

Which SAQ type

SAQ A and SAQ D are different orders of magnitude of work. How your checkout is built decides which you get.

3

Size of the cardholder data environment

In-scope systems, applications and data stores. The count of things a QSA must test is the closest thing to a unit of assessment work.

4

Number of payment channels

E-commerce, card-present, phone, recurring billing and marketplace payouts each bring their own control set. Missed channels are the classic mid-engagement change order.

5

Segmentation

Good segmentation removes systems from scope, which is the cheapest lever you have. It also adds segmentation testing.

6

Locations and travel

Multi-site fieldwork multiplies days.

7

Evidence readiness

The one variable you control. A QSA re-requesting evidence is billable time.

What an engagement contains

Four phases. No percentages attached, because any split we printed would be invented, and the split varies enormously with how ready your evidence is.

Scoping and planning

Define the cardholder data environment and its boundaries. This is where your fee is really set, because everything downstream is priced off the scope agreed here.

Evidence collection and testing

Control testing, document review, interviews, technical validation, on-site or remote. The longest phase, and the one your own preparation shortens most.

Report writing

Drafting the ROC, compiling evidence, writing the executive summary.

Remediation and re-testing

Closing gaps found during fieldwork and re-testing them. Often billed separately. Ask which, before you sign.

Costs that are not in the proposal

The line that most often blows a PCI budget is not the assessment fee. It is one of these.

  • Remediation after gaps are found, which is often the largest line and is not always in the headline fee
  • Your own staff's time collecting evidence, which never appears in the proposal
  • Re-assessment if you fail and need a re-test
  • Travel and on-site fieldwork for multi-location operations
  • Scope expansion mid-engagement when undocumented systems surface
  • Tooling bought to satisfy a specific control, such as SIEM, FIM or MFA

The authoritative list of QSAs

The PCI Security Standards Council maintains the only official QSA directory. Filter by region and scheme. Pricing is quoted per engagement, direct from the firm; the directory carries none, because no firm publishes any.

Open the QSA directory

Frequently asked

Nobody publishes this, and that is the honest answer rather than an evasion. No QSA firm publishes a rate card, a day rate or a sample fee, and the PCI SSC directory lists assessors without pricing. Any specific figure you find, including ones attributed to named firms, traces back to somebody's estimate rather than to a published rate. What we can tell you is what a QSA prices against: SAQ or full ROC, which SAQ type, the size of your cardholder data environment, how many payment channels feed it, whether it is segmented, how many locations need fieldwork, and how ready your evidence is. Fix those seven answers, give the same set to three firms, and you will get comparable quotes. That is the only reliable way to find out what your assessment costs.

Continue reading