Enquire Us

PCI DSS Certification Cost

PCI DSS is validated rather than certified, and the cost depends on your validation route, your merchant or service provider level and the size of your cardholder data environment. Fees are quoted per engagement, so this page explains the drivers rather than quoting prices.

Start with the terminology, because it changes the cost

PCI DSS is the Payment Card Industry Data Security Standard, developed and maintained by the PCI Security Standards Council. The Council was founded by American Express, Discover, JCB International, Mastercard and Visa. It writes the standard, qualifies assessors and scanning vendors, and publishes the validation documents.

What the Council does not do is enforce compliance or certify anyone. It states that whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of the organisations that manage compliance programmes, such as a payment brand or an acquirer. This matters commercially: your acquirer or payment brand determines your level and your validation route, and that determination sets the cost more than any other single factor.

The current version of the standard is PCI DSS v4.0.1, published on 11 June 2024, which superseded v4.0. The requirements that v4.0 introduced as future dated became effective on 31 March 2025.

The validation routes and what each one costs you

  • Report on Compliance produced by a Qualified Security Assessor. A QSA company is qualified and trained by the PCI Security Standards Council to perform assessments. This is the most involved route and applies where a payment brand or acquirer requires it. The fee is quoted per engagement by the QSA company.
  • Self Assessment Questionnaire. A set of questionnaires, each matched to a particular payment acceptance model. There is no assessor fee for the questionnaire itself, but the underlying requirements, scanning and testing obligations do not go away.
  • Attestation of Compliance. The signed statement of compliance that accompanies either route and is what your acquirer or payment brand actually receives.
  • Internal Security Assessor. Staff trained by the Council to perform internal assessments for their own organisation. A training and time investment rather than an external fee.

Choosing the correct questionnaire is itself a cost decision. The questionnaires differ enormously in length depending on whether card data is fully outsourced, handled through a hosted payment page, taken through a payment terminal, taken over the telephone or handled directly.

The cost drivers

  • Your level, set by the payment brands or your acquirer. This determines whether a QSA assessment is required or whether self assessment is acceptable, which is the largest single fork in the cost.
  • Size of the cardholder data environment. The number of in scope system components, applications, databases and network devices. Assessment effort tracks this closely.
  • Segmentation. Whether the cardholder data environment is isolated from the rest of the network, and whether segmentation is tested. Poor segmentation puts the entire corporate network in scope.
  • Payment channels. Ecommerce, card present, telephone order and mail order each bring different requirements, and running several at once multiplies the work.
  • Whether card data is stored at all. Storage brings encryption, key management, retention and secure deletion obligations that organisations using tokenisation or a hosted payment page can avoid.
  • Number of locations. Retail estates and branch networks add sampling, travel and evidence collection.
  • Use of third party service providers. Every provider that could affect the security of account data has to be identified, contractually bound and monitored, and their own compliance status obtained.
  • Approved Scanning Vendor scanning. External vulnerability scanning has to be carried out by an ASV qualified by the Council, on a quarterly basis and after significant change. Priced by the number of external IP addresses in scope.
  • Penetration testing. Internal and external testing, plus segmentation testing where segmentation is used to reduce scope. Priced per engagement by the testing provider.
  • Remediation. The largest variable. Multi factor authentication, logging and monitoring, file integrity monitoring, change detection, secure development practices and encryption may all need work.
  • Internal time. Evidence gathering, policy work and coordination across network, application, operations and HR teams.

Why an assessment fee alone is a misleading budget

Organisations often ask what a QSA charges and treat that as the cost of PCI DSS. In practice the assessment fee is frequently one of the smaller lines. The assessment measures whether the requirements are met. Meeting them is what costs money, and that spend lands in infrastructure, tooling, testing and staff time rather than in the assessor invoice.

The second budgeting error is treating it as a one off project. Validation is annual, ASV scanning is quarterly and after significant change, penetration testing and internal scanning recur, and the operational requirements such as log review, access review, policy review and awareness training run continuously.

Reducing cost legitimately

  • Take card data out of your environment. Redirects, hosted payment pages, tokenisation and validated point to point encryption solutions remove system components from scope. This is the highest leverage action available.
  • Segment properly and test the segmentation. A well isolated cardholder data environment shrinks the assessment, the scanning surface and the testing effort together.
  • Confirm your level and validation route before buying anything. Ask your acquirer in writing. Organisations regularly commission a full assessment when their acquirer would have accepted a self assessment questionnaire.
  • Scope before you quote. A QSA cannot price sensibly without a data flow diagram and a system component inventory, and neither can you compare quotations without them.
  • Fix the known gaps first. Discovering basic issues during fieldwork extends the engagement and often requires the assessor to return.

How Univate supports PCI DSS

Univate works on the readiness and remediation side: mapping account data flows, defining and reducing the cardholder data environment, choosing the correct validation route with your acquirer, gap assessment against PCI DSS v4.0.1, remediation planning with your technical teams, evidence preparation, and support through the assessment or the self assessment questionnaire.

We quote per engagement after seeing the data flows and the system component inventory, because those are what determine effort. We are not the Council, we do not set your level and we do not issue attestations. Where a Report on Compliance is required, the assessment has to be performed by a Qualified Security Assessor company and external scanning by an Approved Scanning Vendor, both engaged separately by you.

PCI DSS cost questions we are asked most often

Is PCI DSS a certification?

Not in the ISO sense. PCI DSS is a payment industry standard maintained by the PCI Security Standards Council, and compliance is validated rather than certified. Depending on your level and payment channels you either complete a Self Assessment Questionnaire or engage a Qualified Security Assessor to produce a Report on Compliance. Either route ends in an Attestation of Compliance. There is no accreditation body, no ISO style Stage 1 and Stage 2 audit and no three year certificate.

Which version of PCI DSS applies?

PCI DSS v4.0.1, published on 11 June 2024. It is a limited revision of v4.0 that corrects errors and clarifies intent without adding or removing requirements. PCI DSS v4.0 was retired at the end of 2024, leaving v4.0.1 as the active version supported by the Council. The requirements that were future dated in v4.0 became effective on 31 March 2025.

Who decides whether we need a QSA assessment or a self assessment?

Not the PCI Security Standards Council. The Council states that whether an entity is required to comply with or validate compliance is at the discretion of the organisations that manage compliance programmes, such as a payment brand or an acquirer. Your acquirer or the relevant payment brand sets your level and tells you which validation route applies, so that is the first conversation to have before you seek any quotation.

What are the main cost components?

Assessment fees paid to a QSA company where a Report on Compliance is required, Approved Scanning Vendor fees for external vulnerability scanning, penetration testing, remediation of gaps found, tooling and infrastructure changes such as segmentation, logging and file integrity monitoring, and internal staff time. Where you complete a Self Assessment Questionnaire there is no assessor fee, but scanning, testing and remediation costs remain.

Does reducing scope reduce cost?

Scope reduction is the single most effective cost control in PCI DSS. Every system component that stores, processes or transmits account data, and every component connected to or that could affect the security of the cardholder data environment, is in scope. Network segmentation, tokenisation, redirect or hosted payment pages and point to point encryption solutions all reduce the number of in scope components, which reduces assessment effort, scanning volume and testing effort at the same time.

What recurs every year?

PCI DSS validation is an annual exercise, so the assessment or self assessment repeats. External vulnerability scanning by an Approved Scanning Vendor is performed on a quarterly basis and after significant change. Penetration testing, internal scanning, log review, policy review and awareness training also recur. Budget PCI DSS as an operating cost rather than a project.

Need help achieving this certification? Univate Global delivers end-to-end implementation in 9 markets. Book a free consultation today.

Univate Global delivers ISO certifications, data privacy compliance, and cybersecurity frameworks across 9 markets.