Median (P50)SaaS
PCI DSS Median (P50) Performance — SaaS
Based on 920 SaaS compliance programmes · Updated 2026
65
Maturity Score
out of 100
650h
Avg Audit Hours
per year
$98k
Avg Cost
per year
74%
Automation Rate
of controls
5.4d
Remediation Days
average
What It Takes to Reach Median (P50)
1Established compliance programme with documented control ownership and annual evidence reviews
2Mix of automated and manual evidence collection, with tooling for at least the highest-risk controls
3Defined remediation process with tracked issues and quarterly reporting to management
4Dedicated compliance resource (or equivalent fraction of shared security/IT staff)
Is your programme at Median (P50) level?
Run your benchmark in 3 minutes and find out exactly where you stand against the SaaS distribution.
Run Your Free Benchmark →