The Short Answer
PCI DSS compliance cost ranges from around $3,000 for a small Level 4 merchant self-assessing, to $100,000 or more for a Level 1 merchant requiring a full QSA-led Report on Compliance. Unlike most frameworks on this site, the number one driver isn't headcount, it's your merchant level, which determines whether you validate for free or pay for a formal audit.
This page assumes you know the basics of PCI DSS. If you need those first, see our PCI DSS compliance guide.
PCI DSS Cost by Merchant Level
Merchant level is set by your payment card brand based on annual transaction volume, and it decides your validation path more than anything else.
| Merchant level | Validation method | Assessment cost | Remediation & scanning | Total |
|---|---|---|---|---|
| Level 4 (<20k e-comm txns/yr) | SAQ, self-validated | $0 – $2,000 | $3,000 – $8,000 | $3,000 – $10,000 |
| Level 3 (20k – 1M e-comm txns/yr) | SAQ, often QSA-assisted | $3,000 – $8,000 | $6,000 – $15,000 | $9,000 – $23,000 |
| Level 2 (1M – 6M txns/yr) | SAQ or ROC | $8,000 – $18,000 | $10,000 – $25,000 | $18,000 – $43,000 |
| Level 1 (6M+ txns/yr) | ROC, QSA required | $20,000 – $45,000 | $20,000 – $55,000 | $40,000 – $100,000 |
The jump from Level 4/3 to Level 1/2 isn't gradual, it's a step change, because the validation method itself changes from a self-completed questionnaire to a mandatory paid audit. Merchants sitting near a level boundary sometimes find it worth actively managing transaction volume or scope to stay in the cheaper tier.
What's Actually in "Remediation & Scanning"
- Quarterly ASV scans. Required for most SAQ types and always for a ROC. A few hundred to a few thousand dollars per year depending on how many external-facing systems are scanned.
- Network segmentation and access control work to isolate the cardholder data environment from the rest of your infrastructure.
- Encryption for cardholder data at rest and in transit, where not already handled by a payment processor.
- Policy and procedure documentation, required at every merchant level regardless of validation method.
The Single Biggest Cost Lever: Scope Reduction
Routing card data through a PCI-validated processor's hosted checkout, iframe, or tokenization service, Stripe Checkout or Shopify Payments, for example, means your own systems never see, store, or transmit the actual card number. That shrinks your cardholder data environment dramatically, which is what determines SAQ type and audit scope. A merchant that tokenizes properly often qualifies for the shortest, cheapest SAQ type available at their level, sometimes skipping most of the remediation column above entirely.
Not sure what merchant level you're at, or what SAQ type applies?
We'll confirm your level and scope before you commit to a QSA engagement you might not need.
Get a Free QuoteSAQ vs ROC: Why the Cost Gap Is So Wide
A Self-Assessment Questionnaire is a checklist most Level 2 to 4 merchants complete themselves, at no direct fee beyond your own remediation work. A Report on Compliance is a formal engagement a Qualified Security Assessor conducts and signs off on, mandatory for Level 1 merchants and most large service providers, and it costs real money because it's a multi-day audit, not a form.
Even merchants who qualify for the free SAQ often choose to hire a QSA anyway for the first assessment, typically $3,000 to $8,000, because catching gaps before an acquiring bank does is cheaper than the fines and remediation pressure that follow a failed validation discovered after the fact.
PCI DSS Costs Recur Every Year, With No Cheap Cycle
Unlike ISO 27001's three-year certification cycle with discounted surveillance years, PCI DSS validation, SAQ or ROC, is required annually, every year, at full scope. Quarterly ASV scans recur four times a year on top of that. Budget PCI DSS as a flat annual operating cost, not a project with a cheaper tail.
Processing cards and not sure where you land?
Tell us your transaction volume and payment flow, we'll tell you your real merchant level and likely cost.
Talk to an Avantcert ExpertFrequently asked questions about PCI DSS compliance cost
Why does PCI DSS cost so much more for Level 1 merchants than Level 4?
Because the validation method itself changes, not just the scope. Level 4 merchants typically self-validate with a free Self-Assessment Questionnaire. Level 1 merchants are required to undergo a formal Report on Compliance conducted by a Qualified Security Assessor, a multi-day paid audit engagement, which is why the cost floor jumps sharply between the two tiers rather than scaling smoothly.
Is the Self-Assessment Questionnaire really free?
The SAQ document itself is free to complete. What costs money is the remediation work to actually pass it, encryption, network segmentation, access controls, and vulnerability scanning, plus the quarterly Approved Scanning Vendor scans most SAQ types require, which typically run a few hundred to a few thousand dollars per year depending on how many systems are scanned.
Can reducing PCI scope actually lower our compliance cost?
Yes, more than almost any other lever. Routing card data through a PCI-validated processor's hosted checkout, iframe, or tokenization service means your own systems never see, store, or transmit the actual card number. That shrinks your cardholder data environment, which is what SAQ type and audit scope are based on, often moving a merchant to a shorter questionnaire entirely.
How much does a Qualified Security Assessor charge for a Report on Compliance?
Typically $20,000 to $45,000 for a Level 1 merchant, depending on the number of locations, systems, and payment channels in scope. This is the audit fee alone; remediation and preparation work to actually be ready for the assessment is budgeted separately and is usually the larger portion of total spend.
Do PCI DSS costs recur every year?
Yes. Validation, whether SAQ or ROC, is an annual requirement, and quarterly ASV scans recur four times a year regardless of merchant level. Unlike ISO 27001's three-year cycle, PCI DSS offers no discounted surveillance years, every year is a fresh validation.
What does PCI DSS v4.0 change about cost compared to v3.2.1?
v4.0 adds new requirements around authentication, encryption, and continuous monitoring that were optional best practices or absent entirely under v3.2.1, so most merchants see a one-time increase in remediation cost during the transition. Once implemented, ongoing annual validation cost is comparable to the previous version.
Does accepting payments through Stripe or Shopify eliminate PCI DSS cost?
It substantially reduces it but doesn't eliminate it. A hosted or tokenized checkout keeps raw card data out of your systems, which typically qualifies you for the shortest SAQ type, but you still complete an annual self-assessment and still need basic security hygiene, patched systems, access controls, and a written information security policy, at minimum.
Is it worth hiring a QSA even if we're only required to do a self-assessment?
Often yes for a first-time SAQ, even though it's not required. A QSA-guided assessment, typically $3,000 to $8,000 for a smaller merchant, catches gaps before a card brand or acquiring bank does, and produces documentation that holds up better if you're ever asked to prove compliance after an incident.
About Avantcert. Avantcert is a compliance consultancy that has guided 3,000+ organisations across 40+ markets through PCI DSS scoping, remediation, and QSA-coordinated assessment. See our PCI DSS compliance service or request a free quote.