SAQ pricing
PCI SAQ D cost 2026: ~251 controls, and what decides your bill
SAQ D-Merchant is the comprehensive fallback, covering all of PCI DSS at full depth at around 251 controls under v4.0.1. That is roughly ten times what SAQ A asks, and it is the honest measure of the gap. Nobody publishes what it costs to complete, so this page gives you the control counts, the routes down a tier, and the things that actually decide your quote.
Updated July 2026
Controls
~251
v4.0.1; the largest SAQ, full PCI DSS depth
Against SAQ A
~10x more
~251 controls against ~24. That ratio is the cost signal
Qualifies
Any merchant not qualifying for a simpler SAQ
Who actually needs SAQ D
SAQ D-Merchant is the fallback for merchants whose payment environment does not qualify for SAQ A, A-EP, B, B-IP, C, C-VT or P2PE. The defining characteristic is that your environment touches cardholder data in some material way: storing card numbers for recurring billing, running a custom payment application that processes card data, or operating an environment complex enough that no simpler category fits.
The typical cases. A SaaS company storing customer card numbers for subscription renewal on its own infrastructure rather than tokenising them through a payment vendor. A multi-channel retailer running both in-store terminals and an e-commerce checkout where the acquirer requires a single consolidated attestation covering both. A marketplace platform with sub-merchant funds flow where the platform handles card data in transit.
If you provide payment-related services to other merchants rather than accepting cards for your own sales, the questionnaire is SAQ D-Service Provider, not this one. It carries around 269 controls, and the extra ones cover sub-merchant management, multi-tenant access control and customer evidence provision. The SAQ D-SP page covers what makes that heavier and what the Level 1 SP transition involves.
The routes down a tier
For most merchants who land on SAQ D, the first thing to examine is not the engagement but whether the environment has to be in scope at all. Every figure below is a published control count from the SAQ documents in the PCI SSC library, so you can check each one. What each route costs to implement is not published by anyone, because it depends on your estate and your vendor's quote. Get that quote and weigh it against the control delta, which is what any assessor would price against anyway.
| Route | From | To | What it involves |
|---|---|---|---|
| Hosted payment pages | ~251 (SAQ D) | ~24 (SAQ A) | Redirect to a fully hosted payment page so card data never touches your servers. The largest single control reduction available to an online merchant. The trade is UX control, and since v4.0.1 SAQ A eligibility also requires confirming your site is not susceptible to script attacks. |
| Validated P2PE | ~251 (SAQ D) | 33 (SAQ P2PE) | For card-present acceptance. It must be a PCI-validated P2PE solution from the PCI SSC's list, not merely an encrypted terminal. That distinction is the whole benefit and is easy to get wrong. |
| Tokenisation | Removes systems from scope | The tokenisation boundary | Replace stored card numbers with tokens, and the datastore behind them leaves scope entirely. Often already included in what your gateway charges you, so check before you buy it twice. The trade is vendor dependency: tokens are not portable between providers. |
| Right-size the SAQ | ~251 (SAQ D) | Whatever you qualify for | Many merchants complete SAQ D when they already qualify for something simpler. Free to check, and it changes nothing about your architecture. PCI SSC FAQ #1158 covers the route if your processor disagrees: confirm the payment flow in writing, share architecture diagrams, escalate via your acquirer. |
Source: the SAQ documents in the PCI SSC document library, v4.0.1. Counts are approximate and vary with counting method. Older figures still circulate from the retired v3.2.1, where SAQ D-Merchant was 329; v4.0 consolidated many sub-requirements, so current counts are lower.
What actually decides your quote
Fix these seven answers, put them in one scope document, and give the identical document to two or three firms. Different assumed scopes are the reason three quotes for the same environment can differ by a multiple, and handing everyone the same scope is the only reliable way to find out what yours costs. Compare scope for scope, and ask each firm what is included.
Size of the cardholder data environment
The count of in-scope systems, applications and data stores. This is the closest thing PCI has to a unit of assessment work, and on SAQ D it is the number that matters most, because around 251 controls get asked of every one of them.
Number of payment channels
E-commerce, card-present, phone, recurring billing and marketplace payouts each bring their own control set. Missed channels are the classic mid-engagement change order, and multi-channel is one of the commonest reasons a merchant lands on SAQ D at all.
Segmentation
Good segmentation removes systems from scope, which is the cheapest lever you have. It also brings a segmentation validation test at least every 12 months under 11.4.5. The saving and the recurring bill arrive together, and the saving is usually larger.
Whether card data is stored at all
Requirement 3 is the heaviest family in the standard, and it only fully applies if you store account data. Tokenisation is how most merchants stop, and the question of whether you genuinely need to store it is worth asking before you assess it.
Locations and travel
Multi-site fieldwork multiplies days. Standardised configurations across sites make it one conversation repeated; bespoke ones make it several separate ones.
Evidence maturity
The one variable you fully control, and on a questionnaire this long it compounds. Evidence re-requested is billable time, and the annual scramble is where remediation cost actually comes from.
Remediation state
The least predictable line and often the largest. It ranges from a configuration change to a segmentation or encryption project. Gaps you find and close yourself before fieldwork are not billed as change orders.
When SAQ D is unavoidable
For some merchants it is. Marketplace platforms operating sub-merchant funds flow are often structurally SAQ D regardless of tokenisation. Custom payment applications built around a high-touch B2B sales process sometimes cannot be migrated to a hosted page without breaking the way the business actually sells. And some acquirers simply require SAQ D under the merchant agreement, which is a contract term rather than a scoping question.
For those merchants the focus moves from cutting scope to running the engagement well, and three things do that work. Multi-year terms with a partner are worth pricing against the single-year alternative, so the commitment has a visible cost rather than an assumed benefit. Evidence collection tooling reduces consulting hours by taking the fetching and formatting of evidence off people who bill by the day: whether it pays back depends on how much evidence you have and how manual your current process is, which is exactly why we quote no saving for it. And keeping compliance posture continuously rather than reconstructing it every year is the one that compounds, because the annual scramble is where remediation cost actually comes from.
One line worth reading before you budget anything: the indemnity clause of your acquirer agreement. That clause, not any card brand schedule, is what sets your exposure if you are breached, and a merchant on SAQ D is by definition one whose environment touches card data. It is the cheapest document to read and the most expensive one to have not read.
Read the official PCI SAQ D document
The PCI SSC publishes SAQ D-Merchant and SAQ D-Service Provider v4.0.1 in the official document library. Every control is listed in full, with the eligibility criteria at the front.
Frequently asked
There is no published price for it, so we carry no figure and no range. No QSA, consultant or acquirer publishes a fee schedule for SAQ D completion, and any specific figure you find traces back to somebody's estimate rather than to a published rate. What decides your cost is which of two very different routes you take. SAQ D is a self-assessment, so completing it yourself costs internal time rather than fees, plus the quarterly ASV scan you buy regardless. Most merchants on SAQ D bring in help for at least the scoping and the evidence review, because SAQ D is the long one at around 251 controls and getting the scope wrong is the expensive mistake. That work is quoted per engagement, against your environment. Renewals cost less than the first year for a structural reason rather than a discount: the scoping is done and the evidence templates exist, so there are fewer hours to buy.
Continue reading
SAQ A cost
~24 controls, and the target of the biggest scope reduction.
SAQ C cost
160 controls, for POS-on-internet merchants.
SAQ D-SP cost
~269 controls, the heaviest SAQ, for payment gateways and hosting providers.
Reduce PCI costs
Scope reduction, expressed in controls rather than guesses.
Level 2 PCI cost
Where a QSA or ISA must validate an SAQ D under Mastercard's rules.
ASV + pen test cost
The Requirement 11 testing set, its frequencies and its drivers.