PCI DSS Assessment Cost in 2026: What the Fee Actually Covers
Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.
The fee stack
A PCI engagement is never just the QSA’s fee. The full first-year stack for a Level 1 merchant:
| Line item | Planning estimate |
|---|---|
| QSA ROC assessment fee | $30,000–$100,000+ |
| Gap / readiness assessment | $10,000–$30,000 |
| Penetration test (annual, required) | $10,000–$50,000 |
| ASV scans (quarterly) | ~$2,000–$5,000/yr managed |
| Remediation | Often 1–2× the assessment fee |
| Internal staff time | $40,000–$80,000 loaded cost |
| First-year all-in | $75,000–$250,000+ |
All figures are planning estimates (September 2026), not quotes — see the 2026 pricing report for provenance.
What’s usually excluded
Read the engagement letter for what’s not in the fee: re-testing after failed controls, additional locations discovered mid-assessment, remediation labor, and the pen test are the four classic exclusions that turn a fixed fee into a variable one.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesHow to cut the bill
- Shrink the scope. Segmentation and outsourcing card processing (hosted fields, tokenization, P2PE) are the highest-ROI moves in PCI — every system you remove from the cardholder data environment is fee you don’t pay, this year and every year.
- Do gap work before the QSA arrives. Failed fieldwork means re-testing fees and a second engagement window.
- Bundle testing. Many QSAs bundle the required pen test and ASV scans cheaper than buying them separately.
- Get three quotes. Fee dispersion for identical scopes is real — our free quote form exists for exactly this.
What quotes should include
A comparable quote names the validation path, the assumed scope, the named team, the fieldwork window, what’s included vs. excluded, fee-breaker clauses, and renewal-year pricing. Anything less isn’t comparable — it’s a number without a scope.
Keep reading
ROC vs SAQ: Do You Actually Need a QSA On Site?
The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.
How to Choose a PCI QSA Company: 11 Questions Before You Sign
What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.
PCI DSS 4.0: What Changed and What It Means for Your Next Assessment
v3.2.1 is retired. Here’s what’s actually different in v4.0.1, which changes bite first-timers hardest, and how to plan the transition.
Questions
Why do QSA fees vary so much?
Scope, readiness, and brand. Two QSAs can quote the same company 2–3x apart because they assumed different scopes — which is why the engagement letter matters more than the headline fee.
Is the cheapest assessment ever the right call?
Only if the scope and inclusions match. A cheap quote that excludes the pen test, re-testing, and remediation support usually isn’t cheap.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.