Guides

PCI DSS guides & explainers

Practical, source-backed guides to PCI costs, timelines, QSA selection, and assessment prep — written for the person who has to get it done.

Fundamentals

ROC vs SAQ: Do You Actually Need a QSA On Site?

The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.

September 2026
Buying guide

How to Choose a PCI QSA Company: 11 Questions Before You Sign

What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.

September 2026
Money

PCI DSS Assessment Cost in 2026: What the Fee Actually Covers

Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.

September 2026
Standards

PCI DSS 4.0: What Changed and What It Means for Your Next Assessment

v3.2.1 is retired. Here’s what’s actually different in v4.0.1, which changes bite first-timers hardest, and how to plan the transition.

September 2026
Fundamentals

PCI Merchant Levels 1–4 (and Service Provider Levels) Explained

The transaction thresholds that decide whether you need a QSA on site — and why your acquirer can override all of it.

September 2026
Operations

How to Share Your PCI AoC (and ROC) With Customers

What to share, what to never share, and how mature companies handle the 47th ‘please send your PCI docs’ request of the quarter.

September 2026

PCI DSS by industry

Scope, cost drivers, and first-timer traps differ by industry:

SaaS  ·  E-commerce & retail  ·  Fintech  ·  Healthcare

Reading is step one. Quotes are step two.

When you're ready, get scoped quotes from accredited QSA companies matched to your environment.

Get a free quote