SAQ pricing
SAQ D Service Provider cost 2026: the drivers, not a price
SAQ D-SP applies to payment gateways, payment-page hosting services, fraud screening services and similar payment-adjacent providers handling cardholder data for merchant customers, below the Level 1 service provider threshold. At around 269 controls under v4.0.1 it is the heaviest SAQ there is. Nobody publishes what it costs to complete, so this page gives you the things that decide it instead.
Updated July 2026
Controls
~269
v4.0.1; ~18 more than SAQ D-Merchant
First-time effort
3-6 months
Remediation is the least predictable phase
Upgrade trigger
Level 1 SP threshold → full ROC
Who qualifies as a service provider for PCI
The PCI service provider definition is broader than many organisations realise. Service providers include any organisation that stores, processes or transmits cardholder data on behalf of another entity, or that could impact the security of cardholder data even without directly handling it. Common SAQ D-SP organisations: payment gateways, payment-page hosting services, fraud screening services that receive raw cardholder data for pattern matching, recurring billing providers managing card-on-file, marketplace platforms operating sub-merchant funds flow, white-label payment processing platforms, and payment terminal management services.
Less obvious ones include hosting providers whose customers run payment applications on the hosted infrastructure, managed service providers operating customer payment environments, cloud service providers offering PCI-in-scope services, and SaaS products whose features touch cardholder data handling even tangentially. AWS, Azure and GCP all maintain their own AOCs that customers reference for scope inheritance, which is the model to copy rather than the exception to rely on.
The designation is contractual: it is established through the agreement between you and your merchant customer. SPs whose contracts explicitly disclaim handling cardholder data may not require PCI compliance, though acquirers increasingly require SP compliance evidence from any organisation whose service could plausibly affect cardholder data security. When in doubt, treat the obligation as applicable rather than risk an acquirer challenge in the middle of a customer's own assessment.
What actually decides your SAQ D-SP cost
Fix these seven answers, put them in one scope document, and give the identical document to two or three firms. Different assumed scopes are the reason three quotes for the same environment can differ by a multiple, and handing everyone the same scope is the only reliable way to find out what yours costs.
Multi-tenancy
The single largest structural difference from a merchant scope. Where several customers share infrastructure, access control, segmentation and logging all have to be evidenced per tenant boundary rather than once. This is what makes the scoping phase longer than the merchant equivalent, and scoping is what everything downstream is priced off.
Customer evidence provision
No merchant equivalent exists. You must produce an AOC, a responsibility matrix mapping every in-scope control to you or to your customer, and a security brief. For complex shared-responsibility surfaces the matrix alone can run to tens of pages, and it has to stay current.
Evidence request volume
The count of customers who will ask, and whether they self-serve. An SP with hundreds of customers handling requests through sales email is buying a labour cost it did not budget. A trust portal turns it into a fixed one.
Segmentation, and testing it twice a year
Segmentation removes systems from scope and is the cheapest lever you have. For service providers it also brings segmentation validation every six months rather than annually, so the saving and the recurring bill arrive together.
Sub-merchant funds flow
Marketplace and payment facilitator models pull sub-merchant onboarding and management into scope. If you move money on behalf of parties you also onboard, say so during scoping rather than during fieldwork.
Regions and cloud footprint
Multi-region deployment multiplies the estate a tester and an assessor must cover. Cloud provider AOCs let you inherit some scope, but inheritance has to be documented, not assumed.
Distance from the threshold
If you are close to the Level 1 SP transaction threshold, the cheapest decision is often to engage a QSA for the SAQ now rather than a non-QSA consultant, so the firm that scoped your environment carries into the ROC. Scoping is one of the more expensive parts of a first engagement, and a fresh firm pays for that discovery again.
The customer evidence provision workload
The single operational difference that distinguishes SAQ D-SP from SAQ D-Merchant is customer evidence provision. You must give merchant customers evidence that your environment is PCI compliant, in a form they can use to support their own attestation. The typical package: your Attestation of Compliance, a responsibility matrix mapping each in-scope control to either you or the customer, and a customer security brief covering your security posture and incident response capability.
For SPs with hundreds or thousands of merchant customers this is not a document, it is a standing function. SPs that publish the AOC, responsibility matrix and security brief on a customer-facing trust portal let customers self-serve. SPs without one field individual requests through sales or compliance email, which is a labour cost that does not appear in anyone's compliance budget because it lands on other teams. That is the real trade, and it is why the trust portal question is worth deciding deliberately rather than by default.
The responsibility matrix in particular absorbs more effort than expected. For complex SP services with significant shared-responsibility surface, meaning hosting providers, cloud service providers and full-stack payment platforms, it can run to tens of pages of control-by-control mapping. Building it once and keeping it current is materially cheaper than answering the same question reactively for every customer that asks.
The questions that make two proposals comparable
- Ask for the assumed number of consultant or assessor days behind the fixed fee. A firm that will not say is not comparable to one that will
- Ask whether remediation and retesting are inside the fee or billed afterwards. This is the line that most often turns an on-budget engagement into an over-budget one
- Ask what happens if scope moves mid-engagement, and get the change-order mechanism written down before you sign
- Ask whether the customer evidence package, meaning the AOC, responsibility matrix and security brief, is in scope or is your own team's work
- Ask what the renewal is quoted against, in the first conversation rather than eleven months later
- Ask whether the same firm can carry into a Level 1 SP ROC, and what it would not have to rescope if it did
Read the official PCI SAQ D-SP document
The PCI SSC publishes SAQ D-Service Provider v4.0.1 in the official document library. Every control and the service-provider-specific requirements are listed in full, and reading it is the cheapest scoping work you will do.
Frequently asked
Nobody publishes a price for it, and we are not going to invent one. No QSA, consultant or acquirer publishes a fee schedule for SAQ D-SP completion, and any specific figure you find traces back to somebody's estimate rather than to a published rate. What can be said with confidence is what makes it the most expensive SAQ to complete. It carries around 269 controls under v4.0.1, roughly 18 more than SAQ D-Merchant, and those extra controls are the service-provider-specific ones: sub-merchant management, multi-tenant access control where several customers share your infrastructure, customer-facing incident notification, and customer evidence provision. On top of the control count sits a workload that has no merchant equivalent: producing the AOC, responsibility matrix and security brief your own customers need for their attestations. To get a real number, fix your scope and give the same scope document to two or three firms.
Continue reading
SAQ D-Merchant cost
The merchant-side equivalent, around 251 controls.
SAQ A cost
The simplest SAQ, for context on the tier difference.
Level 1 PCI cost
Where the Level 1 SP ROC transition lands.
QSA assessment cost
What a QSA prices against, since none publish rates.
ASV + pen test cost
The Requirement 11 testing set and its drivers.
Reduce PCI costs
Scope reduction strategies for SP environments.