2026 market benchmarks
PCI DSS Cost Calculator
Two businesses that both say they are PCI compliant can be spending amounts that differ by a factor of fifty. What separates them is how card data flows through their systems, which validation route their acquirer accepts, and how much of the underlying security work was already done. Set your situation below to see an itemised annual range.
Your situation
Your acquiring bank or the card brands decide which route applies to you. Level 1 merchants and most large service providers need a QSA led report on compliance.
Volume drives merchant level, which drives how much evidence anyone asks you for.
Required whenever you have any public facing system component in scope.
Required annually for most scopes, and again whenever you rely on segmentation to keep systems out of scope.
Estimated cost
Estimated annual PCI DSS cost
$11,450 – $74,500
SAQ self assessment · 20,000 to 1 million a year
| Cost line | Low | High |
|---|---|---|
| Self assessment questionnaire and consulting helpA short SAQ A completed in house can cost almost nothing. A wider SAQ D with an advisor writing the evidence pack sits at the top of the band. | $50 | $4,500 |
| Approved scanning vendor scansFour quarterly external scans at roughly $100 to $500 each. Rescans after a failed scan are extra. | $400 | $2,000 |
| Penetration testingAnnual external testing is required, and segmentation testing is required separately where you rely on network segmentation to cut scope. | $5,000 | $30,000 |
| Remediation, tooling and ongoing operationsLogging, file integrity monitoring, key management, vulnerability management and the internal hours to run them. This line, not the validation fee, is usually the biggest number in a real PCI budget. | $6,000 | $38,000 |
| Total estimated first-year cost | $11,450 | $74,500 |
The validation fee is rarely the big number
Most people search for the price of a PCI assessment and stop there. The assessment is the cheapest part of the programme for the majority of businesses. What actually costs money is closing the gaps the assessment finds: centralised logging you did not have, key management for stored card data, quarterly access reviews, patch cadence, network segmentation that has to be designed and then proven. Budget for the remediation and operations line first and treat the validation fee as the receipt at the end.
The single largest saving available to most businesses is scope reduction. Moving to a hosted payment page, an iframe checkout or a tokenizing gateway can take a company from a long SAQ D to a short SAQ A. That change is usually worth more than every discount you could negotiate on assessor fees.
The 2026 figures behind this model
- Self assessment route: $50 to $10,000 a year, depending on which questionnaire applies and how much outside help you buy to complete it.
- QSA led report on compliance: $15,000 to $100,000 and above for large or multi entity environments with several sites and acquirers.
- Approved scanning vendor scans: $100 to $500 per quarterly scan, so roughly $400 to $2,000 a year before rescans.
- Penetration testing: $5,000 to $30,000 per test, with segmentation testing often priced as a second, smaller engagement.
Worked scenarios
| Scenario | Typical annual range |
|---|---|
| Small ecommerce shop on a hosted checkoutSAQ A or SAQ A EP, quarterly scans, light remediation. | $1,000 to $15,000 |
| SaaS platform with tokenized paymentsNarrow scope through tokenization, but real logging and access control work. | $10,000 to $40,000 |
| Mid size merchant with in house systemsWider SAQ D or a first ROC, segmentation testing and tooling spend. | $25,000 to $90,000 |
| Large merchant or service providerQSA led ROC across several entities. The top of this band is open ended. | $60,000 to $250,000 and above |
What pushes a PCI budget to the top of its band
- Storing card numbers. Storage brings encryption, key rotation and key custodian duties that nothing else in the standard demands.
- Call centre and paper channels. Voice recordings and mail order forms drag physical processes into scope.
- Several legal entities. Each entity may need its own validation, and assessors price per environment rather than per company.
- Flat networks. Without segmentation, every server your staff can reach is in scope, and so is every control that applies to it.
If PCI is landing at the same time as an enterprise security questionnaire, price the other frameworks too. Our SOC 2 calculator and ISO 27001 calculator use the same approach, and the order in which you tackle frameworks changes the total more than most teams expect. Read the methodology for how these bands are built.