PCI DSS compliance cost is one of the hardest things to pin down before you start, because it depends almost entirely on how you handle card data and which validation level applies to you. A small business that outsources payments and a large enterprise handling millions of card transactions are worlds apart. This guide explains what drives PCI compliance cost so you can budget for your situation rather than someone else's.
The Payment Card Industry Data Security Standard, maintained by the PCI Security Standards Council, applies to any organisation that stores, processes, or transmits payment card data. The card industry data security standard exists to protect cardholders, and meeting PCI standards carries real costs that vary widely. Merchants processing more than 6 million transactions per year face Level 1 requirements; those below that threshold face lighter validation. The cost of PCI compliance varies significantly across the merchant spectrum, and understanding what affects the cost is the first step toward a realistic budget.
The biggest driver: your merchant level and SAQ type
PCI DSS classifies merchants into levels based on transaction volume, and that, combined with how you handle card data, determines how you validate compliance and therefore what it costs.
- Smaller merchants typically validate with a Self-Assessment Questionnaire (SAQ). The specific SAQ type, driven by how you accept payments, hugely affects the effort and cost of PCI compliance. A merchant that fully outsources payments to a PCI compliant provider may qualify for a short SAQ; one that touches card data directly faces a much longer one.
- The largest merchants (Level 1) must validate through an annual QSA-led assessment, which can be conducted remotely, on-site, or as a hybrid, resulting in a Report on Compliance, which is a far bigger undertaking. The acquiring bank typically enforces this requirement.
Reducing your scope, by outsourcing payment handling through a compliant service provider so card data never touches your systems, is the single most powerful way to lower PCI cost and maintain compliance more easily.
PCI merchant levels at a glance
The four merchant levels are set by the major card brands and are based on annual card transactions. While exact thresholds can vary slightly by card brand, the general framework is:
| Merchant level | Annual transaction volume | Primary validation method |
|---|---|---|
| Level 1 | Over 6 million transactions, or any merchant designated Level 1 by a card brand | QSA-led assessment + Report on Compliance |
| Level 2 | 1 million to 6 million transactions | SAQ or QSA assessment (card brand may require QSA) |
| Level 3 | 20,000 to 1 million e-commerce transactions | SAQ |
| Level 4 | Fewer than 20,000 e-commerce or up to 1 million other | SAQ (requirements set by acquiring bank) |
Service providers also have their own tiering. The larger Level 1 service provider category faces requirements similar in rigor to Level 1 merchants. Your acquiring bank may impose stricter requirements than the minimums above, so confirm with them what they require at your volume.
Not sure what your PCI obligations actually are?
Run the free security self-assessment and get an instant picture of where you stand.
What goes into the total cost
PCI compliance cost generally comes from these components:
| Cost component | What drives it |
|---|---|
| Validation | SAQ type and complexity, or QSA fees for Level 1 Report on Compliance |
| Vulnerability scanning | Quarterly external ASV scans; number of in-scope IP addresses and domains |
| Penetration testing | Annual requirement; scope and complexity of your cardholder data environment |
| Remediation | Gap between your current controls and PCI DSS requirements: encryption, access control, logging, segmentation |
| Ongoing maintenance | Staff time, policy reviews, quarterly scans, annual reassessment cycle |
| Non-compliance fees | Acquiring bank charges if you fail to submit your attestation on time |
Data security standards set the baseline, but your actual PCI DSS compliance costs depend on your environment. Avoiding the PCI fee your acquiring bank charges for non-compliance, and avoiding the PCI non-compliance fee that results from late attestation submission, are themselves financial reasons to invest in the process. PCI DSS compliance level determines how your costs are structured; a Level 1 merchant faces a fundamentally different cost profile from a Level 4 merchant.
What drives it up or down
The cost rises with the amount of cardholder data you handle, the size and complexity of your data environment, the number of systems in scope, and the validation level. A large enterprise with complex infrastructure and in-scope systems will spend far more than a small business that outsources everything.
PCI non-compliance carries its own cost in potential fines and breach liability. Become PCI compliant to avoid the larger costs of a data breach and card brand penalties. A data breach at scale can result in significant fines imposed by card brands, plus forensic investigation costs, card replacement costs, and reputational damage.
It falls dramatically when you reduce scope through outsourcing and segmentation, so that fewer systems handle cardholder data and a simpler SAQ applies. Level 1 merchant requirements cost significantly more than Level 2 or lower because of the mandatory QSA assessment.
How scope reduction lowers compliance cost
Scope is the single biggest lever in PCI compliance cost. Every system that stores, processes, or transmits cardholder data, or that is connected to such a system, is in scope for PCI DSS. The larger that scope, the more controls you need to implement and evidence, and the more expensive your assessment becomes.
Two strategies reduce scope most effectively:
Outsource payment processing to a PCI DSS validated third-party service provider. If card data never enters your systems because your hosted payment page or payment terminal handles everything, your cardholder data environment shrinks dramatically. Many e-commerce merchants qualify for SAQ A, the shortest SAQ, this way.
Network segmentation. Even if you handle some card data, segmenting your network so that cardholder data systems are isolated from the rest of your infrastructure limits the systems in scope. Proper segmentation needs to be verified, typically through the annual penetration test, but when done correctly it keeps the PCI DSS assessment from expanding across your entire network.
Both strategies require upfront investment, but they repay it through lower ongoing compliance costs for every subsequent year.
The 12 PCI DSS requirements and where cost concentrates
PCI DSS is built around 12 high-level requirements. Understanding them shows where remediation effort and cost tend to concentrate:
- Install and maintain network security controls
- Apply secure configurations to all system components
- Protect stored account data
- Protect cardholder data with strong cryptography during transmission over open public networks
- Protect all systems and networks from malicious software
- Develop and maintain secure systems and software
- Restrict access to system components and cardholder data by business need to know
- Identify users and authenticate access to system components
- Restrict physical access to cardholder data
- Log and monitor all access to system components and cardholder data
- Test security of systems and networks regularly
- Support information security with organisational policies and programs
Requirements 3, 4, 10, and 11 tend to drive the most remediation cost for businesses new to PCI compliance, because they require data discovery, encryption implementations, centralised logging, and regular testing programs that may not already be in place. Requirement 11 covers both the quarterly ASV scans and the annual penetration testing that are recurring line items. Compliance requirements across all 12 domains need to be met, but audits by qualified security assessors at Level 1 will pay particular attention to whether controls are genuinely operating rather than merely documented. Security training for staff handling cardholder data is another compliance requirement that generates ongoing cost, particularly in larger organisations. Sensitive data discovery, to confirm exactly where cardholder data is stored, is a foundational step that organisations often underestimate when scoping their first assessment. Security upgrades to bring legacy systems into compliance with PCI standards are frequently among the largest remediation line items.
How to control PCI cost
The most effective lever is scope reduction: use a PCI compliant payment provider so card data never enters your systems, and segment your network so your cardholder data environment is as small as possible. This can qualify a small business for a much shorter SAQ, making the annual PCI audit far lighter.
Beyond that, fix issues before assessment, keep your quarterly scans and annual penetration test on schedule, and get help scoping correctly so you validate against the right SAQ rather than over-complying. Maintaining compliance levels year-round is cheaper than scrambling at assessment time. Some organisations explore compliance automation tools to reduce the manual effort of evidence collection and control monitoring; these can lower the ongoing annual compliance cost, though they do not replace the scanning, penetration testing, or QSA assessment obligations.
The actual cost of achieving PCI compliance is something you can only pin down once you understand your environment. Discover the true cost by scoping your cardholder data environment first, then matching that to your PCI DSS level and the validation path it requires. What much PCI compliance costs will typically depend most on the PCI level that applies and whether you can reduce scope enough to avoid the more expensive validation paths.
A PCI audit by a qualified security assessor is required at Level 1; at lower levels you can use the SAQ process if PCI DSS standards are met and your setup qualifies. PCI requires the same underlying data security at all levels; the difference is how you prove it and the scope of your cardholder data environment. The PCI SSC provides guidance on what meeting PCI requirements looks like across all 12 requirement domains. There is no PCI certificate issued. Compliance is validated annually through the appropriate path: an SAQ and Attestation of Compliance for lower-level merchants, or a QSA-led Report on Compliance and Attestation of Compliance at Level 1. The validation demonstrates that your security baseline meets PCI DSS requirements and that controls operated throughout the year. The cost of non-compliance, both in non-compliance fees and in breach liability, is a strong argument for keeping the compliance process on schedule. Security best practices under PCI DSS also build a security culture that benefits the organisation beyond just passing the annual assessment.
Common mistakes that inflate cost
There is no single average cost for PCI compliance, because the factors that affect PCI compliance cost vary so widely across merchant environments. However, several avoidable mistakes consistently drive PCI DSS compliance costs higher than they need to be. Understanding the factors that affect cost helps you avoid them:
Scoping too broadly. Including systems in your cardholder data environment that are genuinely out of scope inflates the assessment. A segmentation review, confirmed by penetration testing, can shrink the scope and reduce remediation and assessment cost.
Choosing the wrong SAQ. Completing a more comprehensive SAQ than your setup requires wastes time and money. Equally, completing a simpler SAQ than your setup warrants creates compliance gaps. Get the scoping right first.
Remediating at assessment time only. Running vulnerability scans and penetration tests only when your annual assessment is due, rather than as ongoing practice, means you encounter issues under time pressure and remediation costs spike. Quarterly scans exist precisely to keep you in front of vulnerabilities continuously.
Treating PCI compliance as a one-time project. PCI compliance is validated annually, and the controls need to operate throughout the year. Budget for ongoing effort, not just an initial implementation.
The bottom line
PCI compliance cost is driven by your merchant level, how you handle cardholder data, and the validation path that results, plus the required scanning, penetration testing, remediation, and ongoing annual effort. The biggest savings come from reducing scope so card data never touches your systems. Scope your environment to get a real figure for the cost of PCI compliance for your business.
How Onyx helps
Onyx works with merchants and service providers at every compliance level, from helping smaller merchants identify the right SAQ and scope down their cardholder data environment, through to preparing organisations for a Level 1 QSA-led assessment. Our PCI DSS compliance services cover gap assessment, remediation support, quarterly ASV scanning, and annual penetration testing as a coordinated programme so you are not stitching together different vendors for each obligation.
Because scope is the biggest cost lever, we start there: reviewing how card data moves through your environment, confirming the right SAQ or validation path, and identifying whether segmentation or outsourcing can simplify it. That scoping work is done on a short call, with no obligation.
See also: PCI DSS SAQ types explained, what is an Approved Scanning Vendor, PCI DSS Level 1: what it takes, and our PCI DSS SAQ compliance service.
Facing an audit deadline or a new compliance obligation?
We scope your PCI DSS obligations and build a realistic budget on a 30-minute call. No pressure, no obligation.
FAQ
How much does PCI compliance cost?
It depends on your merchant level and how you handle card data, which determine your validation path. Smaller merchants validate with a Self-Assessment Questionnaire; the largest need a QSA-led Report on Compliance. PCI DSS compliance at higher levels involves qualified security assessor fees, scanning, penetration testing, and remediation. Add required quarterly scans, annual penetration testing, remediation, and ongoing annual effort. The cost of PCI compliance for a small business is far lower than for a large enterprise. Scope your environment for a real figure.
What is the biggest factor in PCI compliance cost?
Your scope: how much cardholder data touches your systems and the compliance level that results. Outsourcing payment handling so card data never enters your environment, and segmenting your network to reduce your cardholder data environment, are the most powerful ways to reduce cost by qualifying for a simpler validation path.
Does PCI compliance require penetration testing and scanning?
Yes. PCI DSS requires quarterly external vulnerability scanning by an Approved Scanning Vendor for many merchants, and penetration testing at least annually and after significant changes. Both are recurring costs to budget for as part of your annual PCI compliance programme.
Is PCI compliance a one-time cost?
No. PCI compliance is validated annually, and you must maintain controls, run quarterly scans, and complete an annual penetration test throughout the year. PCI non-compliance during the year creates risk even if you pass the annual assessment. Budget for ongoing cost, not just an initial project.
How can I reduce my PCI compliance cost?
Reduce scope: use a PCI compliant payment provider so card data never touches your systems, and segment your network so your cardholder data environment is as small as possible. This can qualify you for a much simpler SAQ and dramatically lower the total compliance cost. Transactions per year determine your merchant level, so lower volume or outsourced processing can shift you to a lighter compliance tier.
What are PCI non-compliance fees?
Non-compliance fees are charges imposed by your acquiring bank when you fail to demonstrate PCI compliance by submitting your attestation of compliance on time. These fees are separate from the cost of actually achieving compliance and are entirely avoidable by maintaining your PCI programme on schedule.
