PCI DSS Benchmark Dataset v2026.1
Cross-industry benchmark data from 4,721 PCI DSS compliance programmes
Data Preview (All 7 Industry Cohorts)
Aggregated cohort-level data. Individual records are k-anonymised (k≥5). Values represent cohort medians.
| industry | maturity_score | audit_hours | cost_usd | automation_rate | remediation_days | sample_size |
|---|---|---|---|---|---|---|
| fintech | 68 | 780 | $120,000 | 72% | 6.2d | 810 |
| saas | 65 | 650 | $98,000 | 74% | 5.4d | 920 |
| financial_services | 63 | 1,380 | $280,000 | 62% | 8.3d | 480 |
| healthcare | 58 | 1,050 | $195,000 | 42% | 8.8d | 560 |
| ecommerce | 55 | 890 | $145,000 | 55% | 7.8d | 620 |
| retail | 52 | 980 | $168,000 | 48% | 9.1d | 540 |
| hospitality | 47 | 1,120 | $178,000 | 35% | 10.4d | 310 |
Download & Access
Download CSV
Full dataset as a flat CSV file. Includes all 14 metric columns and 4,721 anonymised records.
Download CSVAccess via API
Programmatic access with industry filtering, metric selection, and JSON responses via the Intelligence API.
View API EndpointMethodology
Frequently Asked Questions
How is the PCI DSS benchmark dataset collected?
Data is collected via voluntary submissions from compliance programmes participating in the GRCTrack Benchmark Network. Each submission is anonymised and k-anonymity (k≥5) is applied before publication to prevent re-identification of individual organisations.
What industries are covered in the dataset?
Seven industries: FinTech, SaaS, Financial Services, Healthcare, eCommerce, Retail, and Hospitality. Sample sizes range from 310 (Hospitality) to 920 (SaaS) programmes per industry cohort.
How often is the dataset updated?
Monthly refresh cycle. Each update incorporates new voluntary submissions, recalculates industry percentiles, and re-applies k-anonymity checks. The dataset version reflects the publication month (e.g., v2026.1 = January 2026).