PCI Compliance Cost 2026
Full cost breakdown of PCI DSS compliance by SAQ type and organisation size — QSA fees, penetration testing, scanning, tooling, and staffing.
Cost by SAQ Type (2026)
| SAQ Type | Profile | QSA / SAQ | Pen Test | Scanning | Tooling | Staffing | Total / Year |
|---|---|---|---|---|---|---|---|
| SAQ-A | Small (e-comm, outsourced) | $2k–$8k | $3k–$8k | $1k–$3k | $5k–$15k | $20k–$40k | $31k–$74k |
| SAQ-D (Merchant) | Mid-market | $8k–$25k | $8k–$20k | $3k–$8k | $20k–$60k | $80k–$150k | $119k–$263k |
| SAQ-D (SP) | Mid-market SP | $15k–$40k | $12k–$30k | $5k–$12k | $30k–$80k | $100k–$200k | $162k–$362k |
| Level 1 ROC | Enterprise | $40k–$200k | $20k–$60k | $8k–$25k | $60k–$200k | $200k–$500k | $328k–$985k |
FAQ
Get Your Personalised Cost Estimate
Our benchmark calculator factors your SAQ type, industry, and maturity level.
Get Cost Estimate →