Updated: 4 July 2026
How much does PCI DSS certification cost? PCI DSS certification cost is not fixed and cannot be read from a price list – it depends on merchant or service provider level, CDE scope width, environment complexity (cloud, on-premises, containers), number of locations, and the scope reduction methods deployed. Organisations certifying for the first time via SAQ (self-assessment questionnaire) may complete the project for a relatively modest sum. A full ROC assessment by an accredited QSA for a large service provider can cost considerably more. The key to cost optimisation is a scope assessment conducted before the formal audit.
PCI DSS certification cost – at a glance:
- Level 1 Merchants (more than 6 million transactions per year) require a ROC issued by an accredited QSA – the most expensive certification format
- Level 2 to 4 Merchants may use SAQs – from approximately 20 questions (SAQ A) to more than 300 (SAQ D) – a significantly less expensive format
- CDE scope is the primary cost driver: every additional system in the CDE requires separate QSA assessment; wider scope means more time and therefore higher cost
- Tokenisation and P2PE can dramatically reduce scope and lower certification cost by 40 to 60%
- A fixed-price model following scope assessment is more favourable for the client than Time and Materials – it eliminates the risk of budget overrun
- Patronusec as an accredited QSA always conducts a scope assessment before pricing – the client receives a fixed price, not a budget with a question mark
Table of Contents
What determines PCI DSS certification cost?
PCI DSS certification cost is the product of several independent factors. Understanding each enables informed budget management.
Factor 1: Merchant or service provider level
PCI DSS defines 4 levels for merchants and 2 for Service Providers based on annual card transaction volumes. The level determines the required compliance document (SAQ versus ROC) and therefore the cost bracket.
| Level | Criterion | Document | Indicative assessment cost |
|---|---|---|---|
| Merchant Level 1 | >6M transactions/year or post-incident | ROC required (QSA) | £120,000 to £500,000 |
| Merchant Level 2 | 1 to 6M transactions/year | SAQ plus ASV scans | £15,000 to £65,000 |
| Merchant Level 3 | 20,000 to 1M e-commerce transactions/year | SAQ plus ASV scans | £8,000 to £35,000 |
| Merchant Level 4 | <20,000 e-commerce or <1M other | SAQ (simplified) | £4,000 to £18,000 |
| Service Provider Level 1 | >300,000 transactions/year | ROC required (QSA) | £160,000 to £650,000 |
| Service Provider Level 2 | <300,000 transactions/year | SAQ or ROC | £25,000 to £85,000 |
Indicative ranges for the UK and EU market, excluding remediation costs and internal client resources.
Factor 2: CDE scope width
This is the largest variable cost driver. Every system in the CDE requires individual QSA assessment – more systems means more auditor time. An organisation with a CDE limited to 3 servers (through tokenisation and P2PE) will pay several times less for an assessment than one with a CDE spanning 50 systems across 3 locations.
Factor 3: Environment complexity
Hybrid environments (cloud plus on-premises), containers (Kubernetes, Docker), CI/CD pipelines, and legacy systems all require deeper technical analysis from the QSA. Each carries specific PCI DSS v4.0.1 documentation and configuration requirements.
Factor 4: Number of locations
For merchants with physical locations (shops, restaurants, hotels), each location with POS terminals potentially requires individual assessment or at minimum representative sampling. Multi-site retailers certifying hundreds of POS locations measure costs in tens of thousands.
Factor 5: Organisational readiness
An organisation that arrives with current documentation, implemented controls, and a trained team pays for the assessment itself. An organisation requiring a year-long remediation project first pays for the assessment plus the implementation project.
Patronusec Insight: The most expensive PCI DSS assessment is not the one with the highest QSA invoice – it is the one that ends with 40 findings and a 6-month remediation project before the certificate can be issued. From our project experience, organisations that invest in a gap analysis and pre-audit 3 to 4 months ahead of the formal assessment shorten the assessment period by 30 to 50% and eliminate costly remediation iterations. We conduct PCI DSS gap analysis as a separate preparatory project.
What is the cost difference between an SAQ and a ROC – and when is each required?
This distinction directly determines the budget class.
An SAQ (Self-Assessment Questionnaire) is a self-assessment that the merchant completes independently (or with a consultant’s assistance), without requiring a QSA to conduct a full audit. SAQ has 9 variants differing in the number of questions and requirements.
A ROC (Report on Compliance) is a full audit report produced by an accredited QSA. Required for Level 1 Merchants and Level 1 Service Providers.
| Document | Who completes it | When required | External cost |
|---|---|---|---|
| SAQ A | Merchant independently | Level 2-4, full e-commerce outsourcing | £0 to £12,000 (consultant) |
| SAQ D Merchant | Merchant or with consultant | Level 2-4, full CDE | £12,000 to £35,000 (support) |
| ROC plus AOC | Accredited QSA | Level 1 Merchant and SP | £120,000 to £650,000 |
When it makes sense to involve a QSA even for an SAQ:
Many Level 2 organisations choose to engage a QSA for SAQ support – particularly when the bank or card scheme requires a ROC rather than an SAQ, when the organisation is planning growth to Level 1, or when business partners require a higher standard of compliance confirmation.
Unsure which merchant level applies to your organisation or whether you need a ROC or SAQ?
Patronusec conducts a free initial call during which we determine your PCI DSS level based on transaction data and business model. You leave knowing what document is required, what satisfies it, and what budget to plan.
How do you reduce PCI DSS certification cost without compromising audit quality?
Cost optimisation in PCI DSS is a legitimate and standard practice – the key is reducing CDE scope and increasing readiness before the assessment.
Strategy 1: Payment tokenisation
If your back-office systems (CRM, ERP, helpdesk) operate only on payment tokens (never on full card numbers), they exit the CDE. Tokenisation costs – typically borne by the processor or payment gateway – are far lower than the cost of certifying a wide CDE.
Strategy 2: P2PE (Point-to-Point Encryption)
A PCI SSC-validated P2PE solution eliminates the terminal and the entire payment path from PCI DSS scope for merchants. A merchant with P2PE may qualify for SAQ P2PE (33 questions) rather than SAQ D (300+ questions).
Strategy 3: Network segmentation
Correct segmentation through firewalls and VLANs separates the CDE from the rest of the infrastructure. Non-CDE systems do not require assessment. Segmentation is a one-time investment; the benefit is annual.
Strategy 4: Gap analysis before the assessment
Investing £10,000 to £25,000 in a gap analysis before the formal assessment can save £40,000 to £120,000 in post-assessment remediation. A gap analysis identifies gaps and provides time to address them before the QSA issues findings.
Strategy 5: Fixed-price model rather than Time and Materials
A QSA billing on a Time and Materials basis has no financial incentive to be efficient. Fixed-price following scope assessment guarantees the budget without surprises.
Patronusec Insight: Clients who come to us after a failed assessment with another QSA almost universally share the same problem: nobody conducted a scope assessment before the project, and nobody helped implement tokenisation or segmentation before the assessment began. The result: wide CDE, lengthy assessment, many findings, high remediation costs. At Patronusec, scope assessment and gap analysis are the standard first step of every certification engagement – the client gets no surprises partway through. See our PCI DSS certification offering.
What is included in QSA assessment costs – and what is additional?
Understanding what a QSA proposal covers allows like-for-like comparison.
Typically included in the ROC price:
- Scope assessment and CDE scope agreement
- Stage 1 (documentation review) and Stage 2 (technical testing and interviews)
- ROC in the final PCI SSC format
- AOC signed by the QSA
- 1 to 2 rounds of report comments
Typically outside the ROC price (additional):
- Penetration tests and ASV scans (may be a separate service)
- Remediation project – addressing findings after the assessment
- Marketing Certificate
- Re-review following remediation of significant findings
- Policy and procedure documentation management
- Staff training
Good questions to ask a QSA before signing:
- Does the price include penetration tests and ASV scans, or only the assessment itself?
- What happens if the assessment identifies gaps requiring remediation – is the re-review included in the price?
- Is the price fixed or Time and Materials?
- How does post-assessment communication work if the acquirer has questions about the report?
FAQ – PCI DSS certification cost
Why might two firms with similar profiles receive quotes differing by a factor of three?
CDE scope is the key variable. Firm A may have a CDE limited to 5 servers through tokenisation; Firm B may have 40 systems without segmentation. Additionally, the pricing model (fixed versus T&M), the QSA’s experience in the specific environment, and the services included (assessment only versus assessment plus penetration tests plus scans) all create significant price differences.
Is SAQ certification sufficient for my acquirer?
This depends on the acquirer contract and card scheme requirements. Most Level 2 to 4 merchants may use SAQs, but some acquirers require a ROC even for Level 2. Check your acquirer contract and ask your account manager about their compliance requirements.
Can PCI DSS certification costs be spread over a monthly subscription?
Yes – a Compliance-as-a-Service model allows certification costs to be spread over monthly payments while providing ongoing QSA support throughout the year. This model works particularly well for organisations that want to maintain continuous compliance between annual assessments.
Is PCI DSS certification required for every organisation that accepts card payments?
Yes, if the organisation accepts Visa, Mastercard, American Express, or JCB cards. The certification requirement derives from the merchant agreement with the acquirer. Absence of certification does not mean a regulator imposes fines directly – but the acquirer can impose penalties or withdraw the right to accept card payments.
How much does PCI DSS certification with Patronusec cost?
Cost depends on scope, level, and environment. After a free 30-minute initial call, we conduct a scope assessment and provide a fixed quotation with a guaranteed timeline and scope. For clients combining PCI DSS assessment with penetration tests and ASV scans, we offer preferential package pricing. We do not work on a T&M basis for certification engagements.
How long does PCI DSS certification take from first contact to AOC?
For a well-prepared organisation (documentation and controls in place): 2 to 4 months from kick-off to AOC. For an organisation requiring remediation: 6 to 12 months. Scope assessment plus gap analysis conducted 3 to 4 months before the audit start shortens the overall cycle and eliminates delays. Patronusec delivers a timeline with guaranteed milestones following the scope assessment.
PCI DSS certification cost – free consultation
Patronusec as an accredited QSA works with merchants, fintechs, and payment service providers across the UK and EU. We specialise in CDE scope optimisation before the assessment – clients save on certification while maintaining full compliance with card scheme requirements.
In a free 30-minute consultation we will help you:
- Determine your PCI DSS level and the required document (SAQ versus ROC) for your business model
- Provide an initial assessment of the CDE scope and optimisation potential (tokenisation, segmentation)
- Explain what is and is not included in our assessment price
- Plan a certification timeline and budget for the coming year
Free consultation | PCI DSS certification | Gap analysis PCI DSS | Penetration testing | Vulnerability scans ASV