QSA pricing
Trustwave PCI compliance cost 2026: a QSA inside an MSSP, now owned by LevelBlue
Two things decide how you should read a Trustwave PCI proposal. LevelBlue completed its acquisition of Trustwave in August 2025, and the assessment is rarely sold cleanly without managed SIEM or managed pen testing in the conversation, which means a Trustwave proposal and a pure-assessment proposal are often not the same product. Trustwave publishes no rates, and no QSA firm does, so this page gives no figure.
Updated July 2026
Positioning
QSA inside an MSSP
Ask for the ROC priced separately from managed services
Ownership
LevelBlue
Acquisition completed 19 August 2025
Published price
None
As with every QSA firm
Check the name before you check the price
LevelBlue completed its acquisition of Trustwave on 19 August 2025. LevelBlue is the managed-security provider formed from AT&T Cybersecurity, and the combination brings two managed security businesses under one owner. The most concrete evidence of where the service lives now is on the web: Trustwave’s own PCI service page 301-redirects to levelblue.com.
For a buyer, that is a practical fact rather than a piece of trivia. Work out who you are contracting with, whose paper the agreement is on, and who supports you day to day, before you get into scope and fees. And if you already hold a Trustwave contract, the acquisition is the thing to raise at renewal. A change of owner is one of the few moments when an incumbent has to re-earn the account, and renewal is when you have the leverage to ask what has changed and what has not.
What has not changed is the credential set, and that you can verify yourself rather than take on trust. Trustwave is a QSA, ASV, PA-QSA, P2PE QSA and PFI (Forensic Investigator), listed on the official PCI SSC directories. Check the listing for the entity actually named on your proposal, since that is the entity whose approval you are relying on.
The Trustwave pricing model
Trustwave prices PCI engagements as part of a security services portfolio rather than as a standalone assessment. The account team will typically propose a tiered engagement: a base ROC, plus a recommended managed pen testing programme, plus a recommended managed SIEM, plus an optional incident response retainer. We cannot tell you what share of the total is the assessment, because none of it is published. You can find out in one question, and it is the question this page exists to make you ask: which line is the ROC, and which lines are recurring annuity you will pay again next year whether or not you are being assessed.
For buyers who want only the assessment, ask for an unbundled proposal explicitly during scoping. One will be produced, but it is rarely the first proposal on the table. Strip the managed-services cross-sell out and what remains is a QSA engagement quoted the way every other firm quotes one, which is the only form in which it can be compared to anybody else’s.
No day rates are published for the QSAs or for the SpiderLabs testing team, and no QSA firm publishes rates, so there is no rate comparison to make here. Two questions are worth putting in writing instead: what day rate and day count sit behind the fixed fee, and if a multi-year term is offered, exactly how scope true-ups in years two and three are triggered and priced. The true-up mechanism is where a multi-year QSA agreement either saves money or quietly stops saving it, and unlike a day rate benchmark, it is something they will actually put in your contract.
Three engagement shapes
| Scenario | What the engagement contains | What to line-item |
|---|---|---|
| Level 2 SaaS (single-region cloud CDE) | SAQ D walkthrough plus ROC-readiness review, roughly three weeks of fieldwork, external pen test in the same proposal | The pen test, separately from the assessment, since it is the part most often assumed rather than specified |
| Level 1 retailer (50 stores, P2PE) | Full ROC plus quarterly ASV scans, segmentation testing, store-sample on-site fieldwork | The recurring scanning, and the travel and sample size behind the on-site days |
| Level 1 fintech (full managed bundle) | Full ROC plus managed SIEM plus quarterly pen testing plus an incident response retainer | Every recurring subscription, one line each, so the one-off assessment can be seen and compared on its own |
No fee column, because no QSA firm publishes fees and we are not going to guess at one. These are the shapes the engagement takes and the lines to insist on seeing separately. Give three firms an identical brief and ask each for the assumed day count, the day rate behind the fixed fee, and whether remediation and re-testing are included. That produces real numbers for your scope, which is the only kind worth having.
SpiderLabs and what the research depth actually buys you
SpiderLabs is the Trustwave offensive security research team. They have published over 100 vulnerability disclosures in widely-deployed software, contribute to the Open Web Application Security Project (OWASP), and run threat intelligence feeds consumed by the managed detection and response service. The annual Trustwave Global Security Report is one of the most-cited threat-landscape products in the security industry alongside the Verizon DBIR.
For PCI buyers, the SpiderLabs association translates to three things in the engagement. First, pen testers running PCI Requirement 11 work who have actually written exploits, not just run scans. Second, threat intelligence that informs the assessor’s questions about what attackers are actually doing against payment environments today. Third, a higher-quality finding output, because the testing team thinks in terms of business impact rather than CVSS scores alone.
The alternative route to that depth is to engage a specialist offensive security boutique on top of your QSA’s own pen test, which is a second engagement and a second fee. Whether the in-house depth is worth more than the specialist is a judgement about your environment, not an arithmetic exercise, because nobody in this market publishes what either costs. What you can do is make the comparison a like-for-like one: ask for the pen test as its own line item, with its own scope and day count, and put that next to a boutique’s quote for the same scope.
When Trustwave wins and when it does not
Trustwave wins when the buyer genuinely wants a single vendor for assessment plus ongoing managed security services. The integration between the managed detection service, SpiderLabs threat intelligence and the QSA practice is genuinely tight, and for a Level 1 merchant with no internal security operations function the bundle solves the “who is watching the SIEM at 3am” problem in one purchasing decision. Whether it is cheaper than buying the two separately is not something anyone can tell you from published prices, so make the call on whether you actually want the managed service, and get it quoted separately either way.
Trustwave does not win when the buyer already has an MSSP relationship they intend to keep, because then the bundle is paying twice for one capability. Nor when procurement requires the assessor to be independent of the operational security tooling being assessed, which some risk-averse enterprises do insist on and which is a coherent position: a firm that sells you the SIEM has an awkward relationship with the question of whether the SIEM is adequate. And it is not the natural pick for a buyer whose only goal is the leanest possible unbundled ROC, where a boutique QSA with no portfolio to cross-sell is aimed squarely at that job.
Negotiating with Trustwave
Three tactics. First, ask for an unbundled proposal in writing during scoping. One can and will be produced, but you have to ask explicitly, and until you do you are not holding a document you can compare with anyone else’s. Second, if you do want managed services, name the specific tier (managed SIEM, managed pen testing, IR retainer) rather than accepting a “managed security” line item, because an unspecified line is scoped by the seller. Third, separate the one-off from the recurring in your own evaluation before you negotiate either. An assessment fee and an annual subscription are different commitments, and a proposal that blends them is asking you to approve the second while thinking about the first.
For multi-year deals, lock in the scope-expansion triggers explicitly. Multi-year QSA contracts generally allow scope adjustments at renewal driven by transaction growth, new payment channels or new geographies, which is reasonable in principle: the assessor is assessing a bigger environment. The problem is that an adjustment with no defined trigger is a number set by one party after you have lost the ability to shop. Define what counts as an expansion, and what it costs, while you still have alternatives. And at renewal, raise the LevelBlue acquisition: ask who holds the paper, who staffs your engagement, and what that means for the years you are about to commit to.
Trustwave on the PCI SSC directory
Trustwave is listed in the official PCI SSC Qualified Security Assessor, Approved Scanning Vendor, P2PE QSA, and PFI directories.
Frequently asked
Trustwave publishes no PCI pricing, and no QSA firm does, so this page gives no figure for it. The structural point is worth more than a number anyway: the QSA practice sits inside a managed security services business, so the assessment is often quoted alongside managed SIEM, managed pen testing or SOC coverage. That means a Trustwave proposal and a pure-assessment proposal from another firm are frequently not the same product, and comparing their totals is meaningless. Ask for the ROC priced standalone and the managed services priced separately, as line items, so you can see which part of the fee is the assessment and which part is a recurring subscription.
Continue reading
Coalfire PCI cost
Federal-adjacent QSA positioning for combined PCI and FedRAMP work.
A-LIGN PCI cost
Multi-framework efficiency for SOC 2 plus PCI plus ISO 27001 buyers.
SecurityMetrics PCI cost
The one assessor that publishes any price at all.
QSA assessment cost
What a QSA prices against, since none publish rates.
ASV + pen test cost
The two recurring scanning line items.
Level 1 PCI cost
What the 6M+ transactions per year tier actually demands.