QSA pricing
SecurityMetrics PCI compliance cost 2026: what is published, what is quoted
SecurityMetrics is both a QSA and one of the highest-volume ASVs, and it is the rare firm in this market that publishes any price at all. Exactly one product has one: $399 a year, one IP, with an asterisk pointing at your processor. Everything above that is a quote, including every engagement its QSA practice runs.
Updated July 2026
Published list price
$399 / year
Single-IP small-business bundle, checked July 2026
Everything else
Scope evaluated, quote issued
Credentials
On the PCI SSC QSA and ASV directories
The one published price, and what it covers
SecurityMetrics publishes a list price of $399 per year for the product it calls "PCI for small businesses", checked July 2026. Its published feature list at that price runs: "External Vulnerability Scan (1 IP)", "Online PCI Self Assessment Questionnaire (SAQ)", "Online compliance reporting portal", "Non-compliance notification", "Compliance reporting to merchant processor", "Compliance certificate", "PANscan® (Card discovery software for 1 machine)", "Service warranty (Up to $100,000 reimbursement in case of a breach)", and "Security Awareness Training (1 seat)". One asterisk: "Price discounts available depending on merchant processor."
That is the only published PCI price we can find from any assessor firm, and it is worth more than a page of estimates precisely because you can go and check it. Read its shape before you anchor on it. It is a bundle rather than an assessment fee, it covers a single IP, and it sits at the smallest end of the market. SecurityMetrics' own general pricing page says "SMB pricing varies based on packages from your acquiring bank", and its scanning material says your scope is evaluated to give you a custom quote. Above one IP, there is no published ladder to climb.
The QSA practice is a separate matter and publishes nothing. No fee for SAQ assistance, no fee for a Level 1 ROC, no day rate. That is not unusual: no QSA firm publishes any of those, and the PCI SSC directory lists assessors without pricing. It does mean that any specific SecurityMetrics assessment fee you find quoted anywhere traces back to somebody's estimate rather than to SecurityMetrics, and we are not going to add another one.
Two different purchases wearing one brand
The most useful thing to understand about SecurityMetrics is that it sells two things that are not economically alike. The portal product is a productised subscription: you complete a questionnaire, you get quarterly scans, and the business works on volume across a very large number of small merchants. The QSA practice is people scoping your specific environment and signing a report about it, priced per engagement like every other assessor.
That is why only one of them has a published price. A templated attestation running at volume can carry a list price. A scoping conversation about your particular cardholder data environment cannot, because the work is not known until the scoping is done. When you see SecurityMetrics described as the transparent one in this market, this is the narrow sense in which that is true, and it stops at the portal.
It also sets where each fits. The portal tier suits Level 4 and much of Level 3, where engagements really are mostly the same shape and there is little to bespoke. The named-firm tier suits multi-region Level 1, federal-adjacent work, and multi-framework engagements where you want PCI alongside SOC 2 or ISO 27001 from one firm. Nobody in either tier publishes an engagement fee, so that decision gets made on fit and on comparable proposals rather than on price discovery.
How to get a number out of them
For portal-tier products, expect very little negotiation room. That is not a posture, it is the economics: a subscription sold at volume to many small merchants has no per-account margin to give away, and the account team has no authority to reprice it. Where room exists is at the two ends. Multi-year prepay is worth asking about. Volume buyers, meaning franchise networks, multi-location retailers, and payment facilitators with downstream sub-merchants, are a genuinely different conversation, because one contract covering many merchants is the shape this business is built to win. We attach no discount figure to either, because none is published. Ask, and compare what comes back against one alternative vendor on the same merchant count.
For a ROC quote, negotiation works the way it does everywhere else in this market: a credible competing proposal on identical scope is the lever, and nothing else reliably is. We make no claim about how far a quote moves, since that would mean quantifying a discount against a fee nobody publishes. What is worth your procurement team's time is making two proposals comparable in the first place, by pinning the assumed day count, the seniority of the people on those days, what is excluded, and whether remediation retesting sits inside the fee or gets billed after.
SecurityMetrics on the PCI SSC directories
SecurityMetrics is listed in the official PCI SSC Qualified Security Assessor directory and the Approved Scanning Vendor directory. Both list firms and publish no pricing.
Frequently asked
One product has a published price. SecurityMetrics publishes a list price of $399 per year for what it calls "PCI for small businesses", checked July 2026, and its published feature list at that price includes an external vulnerability scan for one IP, an online SAQ, a compliance reporting portal, non-compliance notification, compliance reporting to your merchant processor, a compliance certificate, PANscan card-discovery software for one machine, a service warranty, and one seat of security awareness training. The page carries an asterisk: "Price discounts available depending on merchant processor." Everything else is quoted. SecurityMetrics' general pricing page says "SMB pricing varies based on packages from your acquiring bank" and routes larger work to sales, and its QSA practice publishes no fee for SAQ assistance or for a Level 1 ROC. So there is no fee ladder by SAQ type to give you here, because SecurityMetrics does not publish one.
Continue reading
SecurityMetrics ASV cost
The $399 bundle, read line by line.
ControlScan PCI cost
The other SMB-and-processor-channel assessor.
QSA assessment cost
What a QSA prices against, since none publish rates.
SAQ A cost
The simplest SAQ, for hosted-checkout e-commerce.
ASV + pen test cost
Every ASV, and which two are not ASVs.
Processor PCI fees
The charge on your statement, explained.