Skip to contentSkip to content

Planning Tool

Plan Your PCI Compliance Timeline

Get a personalised week-by-week compliance plan based on your SAQ type, team size, and starting position.

Configure Your Timeline

Frequently Asked Questions

How long does PCI DSS compliance take?

Timeline depends on SAQ type and starting position: SAQ A (2-4 weeks), SAQ B/C (6-10 weeks), SAQ D-Merchant (16-24 weeks), ROC assessment (20-30 weeks). These estimates assume a dedicated team; actual timelines vary based on team size, current security posture, and scope complexity.

What should I do first for PCI compliance?

Start with: (1) Determine your SAQ type, (2) Define your CDE scope, (3) Conduct a gap analysis against applicable requirements, (4) Prioritise remediation by risk, (5) Implement controls in dependency order (network security first, then access controls, then monitoring).

Can I do PCI compliance without a QSA?

Level 2-4 merchants can self-assess using the appropriate SAQ without a QSA. Level 1 merchants (>6M annual transactions) require a QSA-validated Report on Compliance (ROC). However, engaging a QSA for guidance is recommended even for self-assessment to ensure accuracy.