
PCI DSS Cost Guide for Small Merchants
PCI DSS Compliance Cost for Small Businesses:
What You Actually Need to Budget
PCI DSS compliance does not come with one official price tag. A small business using an outsourced checkout may spend only a few hundred dollars a year on compliance tooling, while a merchant with custom payment systems can face substantially more internal work, remediation, scanning, and professional-assessment costs.
The most important cost variable is not revenue or employee count. It is how payment-card data moves through your business. Every system you remove from PCI scope can reduce the controls, evidence, testing, and staff time you must maintain.
This guide separates the inexpensive validation work from the hidden operational costs, shows what changes a quote, and gives you a practical way to decide whether you can handle PCI internally or should pay for software or specialist help.
Cost rule: shrink the cardholder-data environment before shopping for more compliance products. 💳
Snapshot
For small US and UK merchants accepting payment cards. You will learn what PCI DSS can cost, which variables increase the bill, how to estimate your own annual budget, and when outside help is worth paying for.
Table of Contents
Before You Act
This guide is for budgeting and procurement planning, not a determination of your individual PCI DSS obligations. Your acquirer, payment processor, payment brands, contracts, payment architecture, and assessment scope can change what you must validate. Confirm the required validation method before signing a consulting or software contract.

How much does PCI DSS compliance cost a small business?
The short answer is that a very small, tightly scoped merchant can buy basic PCI compliance or ASV-scanning services for a few hundred US dollars per year. The real cost becomes larger when you add employee time, technical remediation, security controls, multiple payment channels, additional Internet-facing systems, or professional assessment work.
As of August 2026, public vendor pricing illustrates the low end. Sectigo lists its HackerGuardian Standard PCI scanning service at $286 per year for up to five IPs or domains, while SecurityMetrics lists a small-business PCI service starting at $399 per year that includes one external vulnerability-scan IP, an SAQ workflow, and compliance reporting tools. These are vendor examples, not PCI Security Standards Council fees or universal market prices.
PCI SSC itself does not publish one required merchant compliance fee. The Council maintains the security standard and assessor programs, while individual payment brands and acquirers determine validation and reporting requirements for merchants.
| Cost layer | Small-business impact | What changes it |
|---|---|---|
| SAQ / compliance portal | Often inexpensive or bundled | Processor program, SAQ type, support level |
| ASV scanning | Often hundreds per year at small scale | Number of Internet-facing IPs/domains and included services |
| Internal labor | Frequently larger than the software bill | Scope, documentation quality, staff knowledge |
| Remediation | Can range from trivial to dominant | Legacy systems, insecure configurations, network design |
| Security tooling | Highly variable | Which PCI requirements your environment must satisfy |
| Professional assessment | Quote-driven | Validation method, CDE complexity, locations, evidence, testing |
Key takeaway: A $300 compliance product does not mean PCI compliance costs $300. Think of that figure as one line in the budget, not the budget itself.
A better budgeting formula
For planning purposes, use this equation:
Direct validation costs + required security tools + internal labor + remediation + professional services + contingency = realistic PCI DSS budget.
A small merchant whose processor hosts the payment experience may have almost nothing in the professional-services column. A business running custom checkout infrastructure may find that remediation and engineering time dwarf the cost of the questionnaire or scanning subscription.
The six variables that change your PCI cost
If two businesses each process $1 million in card sales, their PCI bills can still look completely different. The answer changes when the payment architecture changes.
1. Whether cardholder data touches your systems
This is usually the biggest lever. If your web server, application, database, workstation, call-center software, or back-office system stores, processes, or transmits payment account data, more systems may enter the cardholder data environment, or CDE.
PCI DSS defines security requirements for environments where payment account data is stored, processed, or transmitted. Outsourcing payment processing can reduce your technical footprint, although outsourcing does not automatically remove every merchant validation responsibility.
2. Your payment channels
- E-commerce checkout
- Physical payment terminals
- Telephone payments
- Mail-order payments
- Recurring billing
- Virtual terminals
- Mobile point-of-sale devices
More channels can create more systems, vendors, workflows, documentation, and edge cases to assess.
3. Which SAQ or validation method applies
PCI SSC provides different Self-Assessment Questionnaires for specific merchant environments. Eligibility is based on the architecture described in each SAQ, not whichever questionnaire is shortest. PCI SSC specifically warns that the environment must satisfy the applicable eligibility criteria before using a particular SAQ.
4. How many systems remain in scope
A single outsourced checkout page and a segmented payment network are one thing. A flat corporate network where payment systems coexist with employee laptops, servers, remote access, and assorted legacy machinery is another creature entirely.
More scope typically means more evidence, patching, account management, vulnerability management, logging, configuration review, testing, and staff coordination.
5. Your starting security maturity
A business that already maintains MFA, inventories assets, patches promptly, manages access, documents policies, scans systems, trains staff, and retains usable evidence may absorb PCI work into normal security operations.
A company discovering five years of security chores during the PCI project is not really paying for a questionnaire. It is paying down accumulated technical debt.
6. Whether independent assessment is required
Some merchants may self-assess. Others may be required by a compliance-accepting entity to undergo an independent assessment. Your acquirer or payment brand is the right place to confirm the required validation route.

Find your PCI scope before pricing anything
Buying a PCI product before establishing scope is backwards. It is a little like ordering windows before measuring the house.
Start by drawing the payment path from the customer’s card to the processor. Mark every component that stores, processes, transmits, redirects, or can materially affect payment security.
The five-question scope test
- Where does the customer enter card data?
- Does card data ever pass through a server, application, network, device, or employee-controlled system that you operate?
- Do you store full card numbers anywhere, including logs, exports, email, recordings, spreadsheets, or backups?
- Which third-party providers participate in payment processing?
- What does your acquirer or payment processor require you to submit each year?
Decision rule: If you cannot confidently explain your payment-data flow, spend money on scoping clarity before spending money on automation. The wrong scope can make a cheap compliance program surprisingly expensive.
Do not assume outsourced checkout means zero PCI work
PCI DSS v4.0.1 is the current PCI DSS version as of this review. The future-dated v4.x requirements became effective on 31 March 2025.
There is also an important 2026 clarification for small e-commerce merchants. PCI SSC’s FAQ 1604 addresses merchants using third-party redirects or embedded payment-provider iframes and confirms that SAQ A includes applicable ASV external-scanning requirements for merchant e-commerce webpages.
That means “the processor handles the card number” and “there is nothing for us to scan or validate” are not interchangeable statements.
- Security Tool Stack Cost Calculator for Small Businesses
- SOC 2 Budget Calculator: Estimate Compliance Costs
- Vendor Security Questionnaire Guide for Small Businesses
- MFA Rollout Guide: Cost, Planning, and Implementation
- Cyber Insurance for Small Businesses: Coverage and Cost Guide
Build a realistic PCI DSS budget
The easiest way to budget PCI is to stop asking for one magic number and price five layers separately.
Your PCI DSS Cost Stack
SAQ, AOC, ASV or assessor path
Scanning, logging, MFA, monitoring
IT, engineering, operations, management
Patching, redesign, replacement, cleanup
Quarterly and annual evidence cycles
The expensive layer is often not the validation form. It is whatever the form reveals that you now need to fix and maintain.
Direct compliance and scanning costs
Current public pricing gives a useful floor, although it should not be treated as a universal quote. Entry-level ASV scanning can sit in the few-hundred-dollar annual range, and processor relationships may discount or bundle some compliance services.
| Public example checked August 2026 | Published starting price | Useful context |
|---|---|---|
| Sectigo HackerGuardian Standard | $286/year | Up to 5 IPs/domains and ASV scan reporting |
| SecurityMetrics small-business PCI service | $399/year | Includes 1 external vulnerability-scan IP, SAQ workflow and reporting features |
These examples are useful for recognizing the scale of entry-level tooling. They do not tell you what your complete PCI program will cost, and product pricing can change.
Internal labor is the missing line item
Record the hours spent by everyone involved, not merely the person filling out the SAQ.
- Payment-flow discovery
- Asset inventory
- Vendor evidence collection
- Policy updates
- Access reviews
- Vulnerability remediation
- Developer work
- Scan troubleshooting
- Evidence gathering
- Management review
If three employees collectively spend 30 hours and your internal loaded labor cost averages $50 per hour, your planning model should record $1,500 of internal effort. The $50 figure here is simply an example assumption. Replace it with your own labor cost.
Use a budget worksheet, not a headline number
| Budget item | Your quantity | Your unit cost | Annual estimate |
|---|---|---|---|
| Compliance portal / SAQ service | 1 | Enter quote | Calculate |
| ASV scan coverage | IPs/domains | Enter quote | Calculate |
| Internal compliance work | Hours | Loaded hourly cost | Calculate |
| Engineering / IT remediation | Hours | Loaded hourly cost | Calculate |
| New security tooling | Licenses/assets | Enter quote | Calculate |
| Professional services | Engagement | Enter quote | Calculate |
| Hardware or payment-system changes | Devices/projects | Enter quote | Calculate |
| Contingency | 1 | Your chosen reserve | Calculate |
The costs that rarely appear in the first quote
The software subscription is visible. The awkward little invoices hiding behind it are often more important.
Failed scans and remediation cycles
PCI DSS Requirement 11.3.2 requires applicable external scans to be performed by a PCI SSC Approved Scanning Vendor at least once every three months. A failed scan may therefore create patching, configuration, investigation, exception-handling, and rescanning work before you obtain passing evidence.
The scan subscription can be cheap while the server nobody remembered existed becomes expensive.
Legacy systems
Unsupported operating systems, obsolete payment applications, old network equipment, shared accounts, weak remote-access arrangements, and hard-to-patch applications can turn compliance into a modernization project.
Before accepting a PCI quote, ask which remediation work is included and which work will become a separate project.
Third-party evidence
Using a payment or hosting provider does not mean you should simply write “outsourced” and move on. You may need to identify which PCI responsibilities the provider performs, verify relevant compliance documentation, and document what remains yours.
Recurring control maintenance
Budget for the year, not assessment week. PCI controls can involve recurring scanning, access reviews, security awareness, policy reviews, vendor monitoring, log review, patching, incident-response preparation, and evidence retention depending on your scope.
Where the cost comes from
Compliance becomes expensive when a business treats PCI as an annual form rather than an operating process. A clean, repeatable evidence routine usually costs less to maintain than rebuilding twelve months of proof just before validation.
DIY, software, or professional help?
The cheapest option is not automatically DIY. The sensible choice depends on whether the hard part is administration, scale, or judgment.
| Approach | Best fit | What you are paying for | Watch for |
|---|---|---|---|
| DIY / processor portal | Simple, well-understood payment environment | Mainly staff time | Wrong SAQ, incomplete scope, weak evidence |
| Compliance software / ASV service | Repeatable SAQ, scanning and evidence workflows | Automation, reminders, scanning and reporting | Paying for features that do not reduce actual work |
| Consultant / QSA support | Ambiguous scope, complex systems, required independent assessment | Specialist judgment, validation work and credibility | Vague scope, remediation excluded, dependency on consultant |
Do it free or mostly DIY when…
- Your payment architecture is simple and documented.
- Your acquirer confirms that self-assessment is appropriate.
- Your processor provides the needed compliance workflow.
- Your team understands the applicable controls.
- You can collect and maintain evidence without a separate platform.
Pay for software when…
- Quarterly scanning and remediation coordination are becoming repetitive.
- Multiple employees or locations need one evidence workflow.
- You need reminders, reporting, asset tracking, or automated evidence collection.
- The administrative burden is more expensive than the subscription.
Pay for professional help when…
- You do not know which systems belong in PCI scope.
- Your acquirer requires independent validation.
- You have a custom payment application or complicated CDE.
- You store cardholder data and cannot easily eliminate it.
- Segmentation decisions materially change scope.
- You need independent testing or assessment evidence.
- Your internal team is about to spend weeks interpreting requirements instead of implementing them.
Three small-business scenarios
These hypothetical examples show why company size alone is a poor cost predictor. They are planning examples, not price quotes.
Scenario 1: Eight-person online retailer with outsourced checkout
The store uses a third-party processor for payment collection, does not intentionally store card numbers, has one e-commerce site, and has a staff member capable of handling the validation workflow.
Its direct purchased cost could plausibly remain close to the few-hundred-dollar entry-level tools currently advertised by ASV/compliance providers. But the budget still needs staff time for SAQ work, ASV scanning, vendor documentation, fixing findings, and maintaining the website securely.
Best strategy: preserve the narrow architecture. Avoid adding payment functionality that causes more merchant systems to handle cardholder data merely to save a small processor fee.
Scenario 2: Three-location retailer with payment terminals
The merchant has several terminals, store networks, remote administration, staff turnover, and multiple locations. Card data is not intentionally stored.
Here, the compliance subscription may still be modest, but operational cost grows. Device inventories, network architecture, access controls, staff procedures, vendor management, scans where applicable, and evidence collection all consume time.
Best strategy: determine whether validated payment technologies and stronger segmentation can simplify the PCI environment before buying another compliance dashboard.
Scenario 3: Forty-person SaaS company with custom billing infrastructure
The company built parts of its own payment workflow, runs cloud services, uses administrative access, has developers changing the application frequently, and is uncertain which components can affect payment security.
The expensive part is no longer the SAQ subscription. Engineering work, cloud configuration, access controls, application security, logging, vulnerability management, evidence generation, testing, and possibly professional scoping can become the dominant cost.
Best strategy: compare the cost of maintaining custom PCI scope with the cost of redesigning the payment flow so fewer systems remain involved. Sometimes architecture is the most powerful compliance tool you can buy.
Cost insight: A larger company with a clean outsourced payment model can have a simpler PCI program than a tiny merchant running card data through a custom server.
How to compare PCI DSS quotes without buying the wrong thing
If you ask three providers, “How much is PCI compliance?” you may receive three incomparable numbers. Give every provider the same scope facts instead.
Send this quote-preparation packet
- Number of merchant accounts
- Number of business locations
- Payment channels
- Approximate transaction volume if requested by your compliance program
- Payment processors and gateways
- Checkout architecture
- Whether PAN is stored anywhere
- Number of external IPs and relevant domains
- Whether payment systems are segmented from the rest of the network
- Current SAQ or prior validation method
- Any requirement from the acquiring bank or processor
- Known remediation issues
Ask these questions before paying
- Exactly what validation deliverable is included?
- Does the price include ASV scanning, and how many IPs or domains?
- Are rescans included?
- Is remediation assistance included or billed separately?
- Will you help determine scope and the correct validation path?
- What technical testing is excluded?
- What evidence must my staff produce?
- How much staff time should we expect to contribute?
- Is this a one-time project or an annual subscription?
- What happens if our environment changes during the year?
Red flags in a PCI proposal
- A guaranteed compliance outcome before the provider understands your environment.
- No written scope.
- A quote that never asks how card data flows.
- Scanning presented as equivalent to complete PCI compliance.
- Remediation fees left completely undefined.
- A provider calling every merchant assessment a “certification” without explaining the actual validation deliverable.
- No distinction between the provider’s work and your continuing responsibilities.
For official versions of PCI DSS, SAQs, AOCs, and supporting material, use the PCI Security Standards Council document library rather than relying on a vendor’s abbreviated checklist.

Frequently Asked Questions
Can a small business do PCI DSS compliance for free?
Possibly, if your processor provides the required compliance workflow and your environment does not require separately purchased services. However, “free” normally ignores employee time, remediation, security controls, and any applicable ASV scanning. Confirm your validation requirements with your acquirer or processor first.
Do I need a PCI consultant if I use a Self-Assessment Questionnaire?
Not automatically. A straightforward merchant that clearly meets an SAQ’s eligibility criteria may be able to complete the process internally. Professional scoping help becomes more valuable when payment flows are complex, eligibility is unclear, card data is stored, segmentation matters, or substantial remediation is expected.
Does using Stripe, PayPal, Square, or another payment provider eliminate PCI DSS?
Outsourcing payment processing can substantially reduce your scope, but PCI SSC states that merchants outsourcing all payment processing may still have compliance-validation responsibilities. The exact obligation should be confirmed with the organization managing your compliance program.
Are quarterly vulnerability scans always required?
No single answer applies to every merchant environment. ASV scanning applies where the relevant PCI DSS requirements and validation method require it. Importantly, current SAQ A guidance includes applicable external-scanning requirements for e-commerce merchant webpages even when checkout redirects to a third party or uses an embedded iframe.
Can my payment processor charge a PCI non-compliance fee?
Your merchant agreement may contain compliance-related charges or contractual consequences, but there is no single PCI SSC merchant penalty schedule that applies uniformly to every business. Payment brands and acquirers operate their own compliance programs. Review the actual merchant-services agreement rather than relying on generic online penalty claims.
Should I choose the cheapest ASV?
Price matters, particularly for a very small environment, but compare the number of assets covered, rescanning policy, report workflow, remediation support, usability, and whether the provider appears on PCI SSC’s current Approved Scanning Vendor list. A slightly cheaper scan becomes poor value if your team spends hours untangling every failed result.
Your 15-minute PCI cost check
Do one thing before requesting prices: write down your payment flow on a single page.
- List every payment channel you use.
- Write where customers enter card data and whether that data ever touches a system you control.
- Record what your acquirer or processor says you must submit, such as a particular SAQ, AOC, ASV scan, or other validation evidence.
Those three facts will make your next PCI conversation dramatically more useful. They let you compare equivalent quotes, recognize unnecessary scope, and distinguish a $300 tool problem from a much larger security-remediation project.
The number that matters most: not “What does PCI cost?” but “How much of our environment actually needs to remain in PCI scope?” Solve that first, and the budget becomes much easier to control.
Last reviewed: 2026-09