There is no honest single answer to what PCI DSS compliance cost is, because the dominant variable is how much of your environment touches cardholder data — and that varies enormously between companies with identical transaction volumes. Anyone who quotes you a number before seeing your scope is quoting someone else's environment.
What you can do is build the estimate yourself. The cost breaks into six categories that behave differently, and once you know what moves each one you can put your own numbers against them more accurately than any benchmark would. Below are the line items, the drivers, and the single lever that matters more than the rest combined.
Why No One Publishes a Cost of PCI DSS Certification
The phrase "cost of PCI DSS certification" contains the first problem: PCI DSS has no certification. What the standard defines is a validation route, set by your acquirer or the card brands from your level and acceptance channel — a Report on Compliance produced by a Qualified Security Assessor, or a Self-Assessment Questionnaire, each concluding in an Attestation of Compliance.
The two routes differ in cost by a wide margin, and you do not choose between them — your acquirer tells you which applies. The first budget question is therefore not "how much" but "which instrument", answered by your merchant or service provider level and your acceptance channels.
The second problem is that the standard says nothing about price. The PCI Security Standards Council publishes requirements, not rate cards. Assessor fees, scanning subscriptions and tooling are set by a competitive market, and your quotes will be shaped by your environment rather than by any list price.
What Drives PCI DSS Compliance Cost
Four things drive PCI DSS compliance cost, and they are not equally weighted.
Scope is first by a long way. Every system that stores, processes or transmits cardholder data — plus everything connected to it or able to affect its security — lands inside the assessment. Scope sets how many systems get sampled, how many interviews happen, how much evidence gets produced, and how much remediation you owe. Halve the scope and most other line items move with it.
Validation instrument is second: a Report on Compliance is an assessor-led engagement with sampling and testing, while a self-assessment where permitted is an internal exercise with a far smaller external fee.
Starting posture is third. A company already running centralised logging, enforced multi-factor authentication and real vulnerability management is paying for validation. A company without them is paying for a security build-out that PCI DSS is merely the forcing function for.
Channel is fourth. Card-present, e-commerce with a redirect, e-commerce with a hosted field, and direct post pull in different requirement sets and different amounts of work for the same revenue.
The Line Items in a PCI DSS Budget
A PCI DSS budget has six line items worth tracking separately, because they behave differently year to year and respond to different levers. One lumped "compliance" number is how teams get surprised in month nine.
Assessment Fees and QSA Audit Cost
Assessment fees are the most visible line and rarely the largest. QSA audit cost is driven by the number of in-scope systems and physical locations, the complexity of your segmentation, and — more than people expect — how clean your evidence is when the assessor arrives.
Assessors price in days, and days go up when evidence arrives as undated screenshots, when control owners cannot be scheduled, and when the first sample pull reveals exceptions needing a second pass. The same environment carries materially different fees depending on how the evidence was kept during the year.
Where self-assessment is permitted the external fee drops to near zero, but the underlying control work does not, and the SAQ type you qualify for sets how much of the standard you still satisfy.
ASV Scanning and Vulnerability Management
External scanning is a subscription, not a project. Where your validation instrument requires them, quarterly external vulnerability scans must be run by an Approved Scanning Vendor, and the subscription scales with the external IP addresses and hostnames in scope.
The subscription is predictable; rescanning is not. A failing scan has to be remediated and rescanned, and engineering time spent chasing a quarterly pass never appears on the vendor invoice. Internal scanning tooling is a separate licence, usually priced per asset. Our guide to ASV scanning requirements covers what the quarterly cycle demands.
Penetration Testing and Segmentation Testing
Penetration testing is required at least annually and after any significant change, so the annual figure is a floor rather than a budget. Segmentation testing — verifying that the controls isolating your cardholder data environment hold — is required at least annually, and more often for service providers.
Price tracks the attack surface and the number of segmentation boundaries to be probed, not revenue. Budget for the significant-change clause separately, because a re-platforming or a new payment flow triggers a test you did not plan for. See PCI DSS penetration testing for how the scope of those tests is set.
Remediation Engineering
Remediation engineering is the largest and least predictable line in the budget, and the one most often left out of it entirely. It is also the only line that is about your company rather than about the standard.
The expensive work is consistent across environments: building or fixing network segmentation, introducing tokenization so systems stop holding card data, standing up key management that satisfies the cryptography requirements, getting logging complete and retained, and rolling out multi-factor authentication across administrative and remote access.
Each of those is a project with dependencies, not a purchase. Teams that under-budget PCI DSS almost always under-budget this line, because the quotes they collected covered assessment and scanning — the two things vendors will price over email.
Want a line-item read on what your PCI scope will actually cost?
Share your work email and we'll walk your acceptance channels and in-scope systems against the six budget lines, and mark where scope reduction would move the number most.
Security Tooling You Have to Own
Security tooling is a recurring licence cost that PCI DSS pushes into the budget whether you planned it or not. The categories are logging and monitoring, file integrity monitoring, vulnerability management and access management — plus, for e-commerce, monitoring the integrity of the scripts loaded by your payment pages.
Most have a free-at-small-scale tier and a steep curve once retention periods and asset counts grow. Log retention is the usual surprise: the requirements expect logs available for a meaningful period, and per-gigabyte storage only grows. Where you own the tool already, the cost is configuration. Where you do not, the licence persists long after the assessment ends.
Internal Time, the Cost Nobody Budgets
Internal time is the cost nobody budgets and often the second-largest real expense after remediation. Engineering and compliance hours go into scoping workshops, data flow mapping, evidence collection, sampling responses and the back-and-forth with the assessor.
It generates no invoice, and it is large because it is spread across people with other jobs: the platform engineer pulling firewall configurations, the IT lead chasing access reviews, the compliance lead assembling policies. Count it in person-weeks and plan it, or it gets paid out of the delivery roadmap — a more expensive currency.
First-Year Cost Versus the Ongoing Run Rate
First-year cost is materially higher than the ongoing run rate, and the gap is almost entirely remediation: year one carries the segmentation work, the tokenization project, the tooling you had to buy, and the scoping exercise you will never do from scratch again.
From year two the shape changes. Assessment fees recur but usually fall, because the evidence exists and the assessor is no longer discovering your environment. Scanning, testing and tooling licences recur at roughly the same level. Internal time drops sharply if — and only if — evidence collection became routine rather than an annual scramble.
The failure mode is presenting year one's number as the run rate and then being unable to explain why year two is cheaper — or presenting year two's as the whole programme and having no funding for the next significant change. Model both, and work through the first-year and run-rate numbers before you take either to a board.
Scope Reduction Beats Negotiating the QSA Fee
Scope reduction is the strongest lever on the whole budget, and negotiating the QSA fee is one of the weakest. A discount on an assessment fee is worth far less than taking systems out of the cardholder data environment, because removing them takes testing days, remediation projects, tooling seats and evidence collection out at the same time.
Tokenization and point-to-point encryption do this structurally: both reduce what is in scope, and so reduce assessment and remediation cost together. A payment page that never lets card data reach your servers removes whole requirement areas from your obligation rather than making them cheaper to satisfy.
The inverse is the cost of staying in scope unnecessarily — systems holding card data because a feature once needed it, flat networks where segmentation was never finished, a retention default nobody revisited. Each is paid for every year, in every line item. Our guide to PCI DSS scope reduction covers the mechanics.
What v4.0.1 Added to the Bill
The current version of the standard is v4.0.1, and the full v4 requirement set has applied since 31 March 2025. Several of its themes carry real cost rather than paperwork.
Script integrity management for payment pages is the clearest example: it implies a monitoring capability most e-commerce teams did not own. Broader multi-factor authentication expectations extend MFA past the narrow administrative case many environments had covered. Targeted risk analyses add a documented, recurring exercise for requirements whose frequency you set yourself.
None is a large purchase alone. Together they shift the run rate up and add internal time in the first cycle. If you budgeted against a pre-v4 programme, read what changed in v4 before reusing last cycle's numbers.
Assembling Your Own Estimate
Assembling your own estimate takes four passes, and the order matters because each changes the one after it.
- Fix the scope. Map every flow where card data is stored, processed or transmitted, then mark connected and security-impacting systems. This is the number everything else multiplies against.
- Confirm the instrument. Ask your acquirer which validation route applies. Do not assume a self-assessment until it is in writing.
- Gap the controls. Walk the twelve requirement areas against what you run, and separate "needs evidence" from "needs building". The second list is your remediation line.
- Price the recurring lines. Scanning, testing, tooling and assessment fees are quotable once scope is fixed. Add internal time in person-weeks against each pass above.
That gives you two numbers with the assumptions visible, which is more useful to a CFO than a benchmark: when scope changes, you can show which line moved and why.
What Non-Compliance Costs Instead
The cost of not complying is set contractually by the card brands and passed through by your acquirer, so it is not reliably published anywhere. Any article quoting a precise fine should be read with suspicion.
What the consequences are, rather than what they amount to, is well established. Acquirers pass through monthly non-compliance assessments. Transaction costs can rise. Liability shifts after an incident in ways far more expensive than the programme you declined to fund. In severe cases card acceptance is withdrawn, which is not a cost line but an existential one. The downside is contractual, unpublished and asymmetric: you cannot price it, which is exactly why you cannot discount it.
PCI Compliance Pricing Questions Teams Ask
These are the PCI compliance pricing questions teams ask most often once they start assembling a real budget.
The external fee is much lower, sometimes zero. The underlying work often is not: a Self-Assessment Questionnaire still requires the controls in its scope to be in place and evidenced, and the Attestation of Compliance is a signed statement about your environment. Self-assessment saves assessor days, sampling and on-site coordination. It saves nothing on remediation, scanning, testing or tooling — and you do not choose it anyway.
Remediation engineering, then internal time. Both are invisible when you collect quotes: vendors price assessment, scanning and testing, and nobody invoices you for your own engineers. If your budget has a precise assessment fee and a vague remediation allowance, it is the wrong way round.
Enough to be worth modelling separately, and the drop comes almost entirely from remediation ending. Scanning, testing and tooling licences recur at similar levels; assessment fees typically fall because the evidence already exists. Internal time falls only if evidence collection became routine — if it stayed an annual scramble, year two costs as much in hours as year one.
Volume drives your level, and your level influences which validation instrument applies, so it matters indirectly. But two companies at the same volume differ enormously if one holds card data across a flat network and the other pushes everything to a tokenization provider. Scope, not volume, is what the assessment prices.
See what your PCI scope is costing you before the assessor does
Book a demo and we'll show how Konfirmity maps your cardholder data flows to the twelve requirement areas, tracks evidence through the year, and flags the systems that are in scope for no reason.
Book a demo
Budget the Scope, Not the Audit
The budget that holds is built from scope outward. Fix what is in the cardholder data environment, confirm the validation instrument with your acquirer, gap the controls against the twelve requirement areas, and only then price the recurring lines. In that order, the estimate survives contact with the assessor.
Built the other way — a quote, a placeholder, and a hope that remediation is small — it does not, and the gap surfaces as an unfunded segmentation project halfway through the year.
Start the scoping pass this week, then work the control gap. The PCI DSS compliance checklist turns that gap into a list of funded items rather than a list of worries.

