SAQ pricing
PCI SAQ A cost 2026: the smallest SAQ, and what decides your bill
SAQ A carries around 24 controls under v4.0.1, roughly a tenth of SAQ D-Merchant. It is the least work of any questionnaire, and for an e-commerce merchant who genuinely qualifies it is the cheapest legitimate route to compliance. Nobody publishes what it costs to complete, so this page gives you the eligibility criteria, the control counts, and the things that actually decide your quote.
Updated July 2026
Controls
~24
v4.0.1; the smallest SAQ there is
Against SAQ D
~10x fewer
~24 controls against ~251 for SAQ D-Merchant
Qualifies
Fully outsourced card data functions
The control count is the cost signal
Every count below is published, in the SAQ document itself in the PCI SSC library, under v4.0.1. Counts are approximate and shift slightly with how sub-requirements are counted, so confirm yours in the document. This is the comparison that matters, because the number of things you have to evidence is the closest thing PCI has to a unit of work, and it is what any firm quoting you will price against.
| SAQ | Controls (v4.0.1) | What it means |
|---|---|---|
| SAQ A | ~24 | Fully outsourced card data functions. The smallest set there is. |
| SAQ A-EP | ~139 | Your site affects the security of the payment page. Roughly 6x SAQ A. |
| SAQ D (Merchant) | ~251 | All 12 requirements at full depth. Roughly 10x SAQ A. |
Source: the SAQ A, SAQ A-EP and SAQ D-Merchant documents, PCI SSC document library, v4.0.1. Under the retired v3.2.1 the SAQ D-Merchant count was 329; v4.0 consolidated many sub-requirements, so the v4.0.1 counts are lower.
The SAQ A qualification decision
SAQ A applies to card-not-present merchants who have fully outsourced all cardholder data functions to PCI DSS validated third parties, where the merchant's own systems neither store, process nor transmit cardholder data. The formal criteria are printed at the front of the SAQ A document, and that is the text your acquirer will hold you to. Read it before you complete anything, because it is the cheapest scoping work available to you and it is free.
The thing most often got wrong is treating the gateway's brand name as the answer. It is not. What decides your SAQ is where the card data collection actually happens against the criteria in the document, read alongside your processor's own published position on the specific integration you have deployed. Major processors publish per-integration SAQ guidance in their developer documentation. If your integration has been customised, or you have added your own fields around it, that is the part to examine, and it is worth getting your processor's answer in writing for your exact setup rather than reasoning by analogy from someone else's.
Stripe's published position is a useful worked example, because it is unusually explicit. Stripe states that SAQ A applies to merchants using Checkout, Payment Links, or Stripe.js and Elements, on the basis that those products "host all card data collection inputs within an iframe served from Stripe's domain (not yours), so your customers' card information never touches your servers". Stripe also states it "is certified annually by an independent PCI Qualified Security Assessor (QSA) as a PCI Level 1 Service Provider". Both quotes are from docs.stripe.com/security/guide and stripe.com/guides/pci-compliance, checked July 2026. Where a processor publishes a position that specific, it is worth more than any third party's summary of it.
What actually decides your quote
Fix these six answers, put them in one written brief, and give the identical brief to two or three firms. Different assumed scopes are why quotes for the same business can differ by a multiple, and handing everyone the same brief is the only reliable way to find out what yours costs. Ask each what is included, and specifically whether scanning and any remediation help are inside the fee or billed on top.
Which SAQ you actually qualify for
The largest fork by a distance, and it is decided by how your checkout is built rather than by preference. Around 24 controls or around 139 is not a negotiation, it is an architecture question. Settle it first, because everything else is priced off the answer.
Whether eligibility is provable
SAQ A rests on nothing of yours touching cardholder data. If that has never been written down, someone has to establish it: a data flow diagram, the integration mode in writing from your processor, and an inventory of what loads on the checkout page.
Your script inventory
Since v4.0.1, SAQ A eligibility requires confirming your site is not susceptible to script attacks. A checkout page carrying marketing tags, analytics and chat widgets makes that confirmation real work. A minimal one makes it short.
How many payment channels you have
A single hosted checkout is one conversation. Add phone orders, a virtual terminal, an in-person terminal or a marketplace payout flow and each brings its own control set, which is the classic way a merchant who expected SAQ A ends up somewhere else.
Whether it is bundled with your acquirer
Many acquirers route SAQ completion through a compliance portal that is already a line on your statement. Read the statement before you buy the same thing twice. That fee is a contract term, and it is charged whether or not you have completed anything.
Evidence maturity
The one variable you fully control. Answering from documentation that already exists is fast. Reconstructing it in the fortnight before submission is where the hours go, and if you are paying someone by the day, that is where the money goes too.
The one published price in this corner of the market
SecurityMetrics publishes a list price of $399 per year for the product it calls "PCI for small businesses" (securitymetrics.com/pci-small-business-pricing, checked July 2026). It is worth knowing about precisely because it is real and published, which almost nothing else here is. Its published feature list at that price: an External Vulnerability Scan for one IP, an online SAQ, a compliance reporting portal, compliance reporting to your merchant processor, PANscan card-discovery software for one machine, and one seat of security awareness training.
Read the caveats before you treat it as a benchmark, because it is not one. It is a bundle for a single IP, not an SAQ completion rate and not a general market rate. SecurityMetrics' own page carries an asterisk saying "Price discounts available depending on merchant processor", and its general pricing page says "SMB pricing varies based on packages from your acquiring bank". So it is a real anchor for the smallest merchant, it may not be the price you are offered even by SecurityMetrics, and it is not a quote for anyone larger. It is one vendor's list price for one product, which is exactly as much as it should be taken for.
What goes wrong with SAQ A
The most common failure is misclassification: attesting to SAQ A when the integration does not meet the eligibility criteria. It tends to surface at the worst possible moment, during an acquirer compliance review or a post-incident investigation, when the merchant is dealing with both the underlying problem and the fact that its attestation was inaccurate. Acquirers have grown more willing to challenge SAQ A attestations during routine review, and the defence is a written record: your data flow, your processor's confirmation of your integration mode, and your script inventory.
The second is forgetting the checkout page's third-party scripts. Under v4.0.1 the SAQ A eligibility criteria ask you to confirm your site is not susceptible to script attacks, and a checkout page that loads marketing tags, analytics and chat widgets makes that confirmation harder to stand behind. Keeping checkout pages minimal is a compliance control, not just a performance one.
The third is paying twice. A PCI programme fee on your monthly processing statement often already bundles a compliance portal and an SAQ tool, and it is charged whether or not you use them. Before buying SAQ support, read the fee schedule on your last statement rather than the summary total, and find out what you are already paying for. If what you see is a non-compliance fee, completing the SAQ through the portal your processor names is what removes it.
Read the official PCI SAQ A document
The PCI SSC publishes SAQ A v4.0.1 in the official document library. The eligibility criteria are at the front and every control is listed in full. Reading it before you complete it is the cheapest scoping work you will ever do.
Frequently asked
Nobody publishes a price for completing an SAQ, and we are not going to invent one. No QSA, consultant or acquirer publishes a fee schedule for SAQ A completion, so any specific figure you find traces back to somebody's estimate rather than to a published rate. What can be said is what makes SAQ A the cheapest questionnaire to satisfy: it carries around 24 controls under v4.0.1, the smallest set of any SAQ, against around 139 for SAQ A-EP and around 251 for SAQ D-Merchant. That ratio is the honest cost signal, and it is published in the SAQ documents themselves. One real published price does exist nearby: SecurityMetrics lists $399 per year for a small-business bundle that includes an online SAQ, a single-IP external scan and a portal (securitymetrics.com/pci-small-business-pricing, checked July 2026). That is a bundle for one IP, not an SAQ completion rate and not a market rate, and SecurityMetrics' own page says pricing varies by acquiring bank.
Continue reading
SAQ D cost
The full-scope questionnaire at around 251 controls.
SAQ C cost
160 controls for POS-on-internet merchants.
SAQ P2PE cost
33 controls, for validated P2PE terminal merchants.
Level 3 PCI cost
Where most SAQ A merchants sit in the level taxonomy.
SecurityMetrics PCI cost
The published $399/yr small-business bundle, and its caveats.
Reduce PCI costs
Scope reduction, expressed in controls rather than guesses.