PCI DSS Assessment Cost: SAQ vs ROC

PCI DSS assessment cost

A PCI DSS SAQ can cost almost nothing to complete if your organization is genuinely eligible, already compliant, and can handle the assessment internally. A Report on Compliance (ROC) is a different budget category: a QSA-led ROC commonly requires tens of thousands of dollars in assessment work, and complex environments can move into six figures.

The important distinction is not simply “small company versus large company.” Your payment brand, acquirer, transaction volume, merchant or service-provider status, and cardholder data environment determine which validation method is acceptable. PCI SSC provides the assessment framework, but the entity accepting your compliance validation generally determines whether you may use an SAQ or must provide a ROC.

Before requesting quotes, confirm that validation path. Paying a QSA to scope a ROC you never needed is expensive. Building a budget around an SAQ when your acquirer expects a ROC is worse.

PCI DSS assessment cost

How Much Does a PCI DSS SAQ or ROC Cost?

PCI SSC does not publish a standard fee schedule for assessments. QSA companies set their own commercial rates, and the actual bill depends much more on assessment effort than on the letters “SAQ” or “ROC.”

Validation PathUseful Budget ExpectationWhat You Are Paying For
DIY SAQOfficial questionnaire itself can be completed without an assessor feeInternal scoping, evidence collection, control validation and documentation
Assisted SAQOften several thousand dollars; complex SAQ D engagements can reach five figuresScoping help, requirement interpretation, evidence review, remediation guidance and possibly QSA involvement
ROCUsually a five-figure assessment project; large or complex environments can reach six figuresFormal assessment procedures, sampling, interviews, evidence testing, reporting, quality review and AOC preparation

These are planning bands, not PCI-mandated prices. A tightly scoped environment with excellent documentation may sit near the lower end. A first-time assessment involving several payment channels, cloud environments, offices, service providers, customized controls, and unfinished remediation can sit far above it.

Also separate the assessment fee from the cost of becoming compliant. Penetration testing, Approved Scanning Vendor services, logging, MFA, segmentation, vulnerability management, policy work, security tooling and engineering remediation may be separate line items.

SAQ vs ROC: The Difference That Actually Changes the Cost

An SAQ is a self-assessment reporting mechanism for organizations that meet the eligibility conditions for the applicable questionnaire. A ROC documents a PCI DSS assessment through the formal Report on Compliance process and requires substantially more testing and reporting effort.

The mistake is treating an SAQ as “PCI Lite.” Some SAQs contain a narrow subset of requirements because the payment architecture removes much of the environment from scope. Others, particularly SAQ D, are far broader. PCI SSC states that SAQ D for Service Providers is the only SAQ available to SAQ-eligible service providers.

You can review the current questionnaires and PCI DSS v4.0.1 documentation in the PCI SSC Document Library.

QuestionSAQROC
Who performs the validation work?Primarily the organization itself, although advisers or QSAs may assistFormal assessment process, commonly performed by a QSA when independent validation is required
Is eligibility restricted?Yes. The specific SAQ eligibility criteria must be satisfiedUsed when the applicable compliance program requires or accepts ROC reporting
Evidence effortVaries dramatically by SAQ type and environmentUsually substantial testing, sampling, interviews and documentation
Typical external costLowest when genuinely self-managedMaterial professional-services engagement
Best way to reduce costConfirm the correct SAQ and narrow PCI scopeNarrow PCI scope and enter assessment with evidence ready
PCI DSS assessment cost

Do You Actually Need a ROC?

Do not choose between an SAQ and ROC because one quote looks cheaper. First determine what your compliance-accepting entity requires.

PCI SSC explicitly distinguishes its role from that of payment brands and acquirers. The Council publishes PCI DSS and its validation tools, while payment brands, acquirers and similar compliance-accepting entities determine how an organization must demonstrate compliance. PCI SSC explains this division in its guidance on validation and reporting methods.

Transaction thresholds can matter, but they are not universal across every payment brand and every relationship. For example, Visa currently identifies merchants processing more than six million Visa transactions annually as Level 1 and generally requires annual ROC validation, while lower Visa merchant levels generally use SAQ-based validation. Organizations should check the current Visa compliance validation criteria when Visa rules apply.

Your acquirer may also impose a stricter validation requirement based on risk, a previous account-data compromise, contractual terms, or other program rules. That is why “we process fewer than X transactions” is not enough to approve your own SAQ route.

The Six Variables That Move a PCI DSS Quote

If two companies ask for a “PCI assessment quote,” the numbers can be several multiples apart without either quote being unreasonable. These are the variables doing most of the work.

1. The Size of the Cardholder Data Environment

The assessor is interested in systems that store, process or transmit account data, plus systems that can affect the security of that environment. More applications, network segments, databases, identities, cloud accounts and supporting components generally mean more evidence and testing.

A company with 5,000 employees can sometimes have a cleaner PCI scope than a 100-person company that allows payment data to wander through call-center desktops, CRM notes, email and internal applications.

2. Your Payment Architecture

Redirecting payment collection to an appropriate third-party payment provider can produce a very different assessment footprint from directly handling card data. Embedded payment pages, virtual terminals, call centers, physical terminals and internally hosted payment applications each create different scope questions.

This is why changing architecture before the assessment can sometimes save more than negotiating the assessor’s day rate.

3. SAQ Type

“We only need an SAQ” tells a QSA very little. SAQ A and SAQ D represent profoundly different amounts of work. Your quote should identify the expected SAQ type and the assumptions supporting that classification.

For e-commerce merchants, this deserves particular attention. PCI SSC revised SAQ A eligibility for PCI DSS v4.0.1, including considerations around scripts that could affect certain embedded payment implementations. Do not rely on an old SAQ decision made before the current criteria.

4. First Assessment vs Mature Renewal

A mature organization may already have current network diagrams, data-flow diagrams, inventories, responsibility matrices, policies, penetration-test evidence, vulnerability scans, access reviews and previous workpapers. A first-time organization often has to discover the environment while trying to assess it.

That discovery work is billable somewhere, whether it appears on the assessor invoice or consumes internal engineering hours.

5. Defined Approach vs Customized Approach

PCI DSS v4.x permits a customized approach for eligible requirements, but flexibility does not mean less assessment work. Customized controls require the organization to demonstrate how its implementation meets the customized approach objective, and the assessor has additional validation work to perform.

If your goal is simply to minimize audit cost, introducing customized approaches without a strong technical reason can send the meter in the wrong direction.

6. Remediation During the Engagement

The cleanest assessment is an assessment, not a construction site. If evidence reveals failed controls, the organization may need engineering work, policy changes, new testing and subsequent validation before reporting can be finalized.

A quote that looks unusually cheap may simply exclude those additional cycles.

The Real PCI DSS Budget Is Bigger Than the Assessor Invoice

For budgeting, use a broader model:

Real PCI budget = scoping and readiness + assessment + required technical testing + remediation + internal labor + recurring compliance operations.

The assessment may be the easiest number to obtain because it arrives as a proposal. The expensive surprises usually live outside that proposal.

  • Scoping and readiness: architecture review, data-flow mapping, inventory work and gap analysis.
  • Technical validation: required vulnerability scanning, penetration testing and other security testing where applicable.
  • Remediation: engineering time, configuration changes, segmentation, MFA, logging or platform changes.
  • Documentation: policies, risk analyses, inventories, diagrams and evidence packaging.
  • Internal labor: security, IT, engineering, HR, legal, procurement and business owners answering assessor requests.
  • Ongoing operations: controls that must continue working after the AOC is signed.

If tooling becomes part of remediation, separate that spend from the assessment quote. A broader security tool stack cost calculation can help prevent software subscriptions from disappearing into the audit budget as unexplained “compliance costs.”

How to Reduce PCI Assessment Cost Without Under-Scoping

The safest cost lever is not asking the assessor to test less. It is designing the environment so that less genuinely belongs in PCI scope.

  • Confirm your validation method before procuring assessment services. Ask the acquirer or other compliance-accepting entity whether it expects an SAQ, ROC, AOC or additional documentation.
  • Map every payment channel. Include web, mobile, telephone, virtual terminal, recurring billing, physical locations and exceptional manual processes.
  • Find stored card data. Old databases, support tickets, logs, spreadsheets and call recordings can quietly enlarge the environment.
  • Validate segmentation. A diagram claiming that the CDE is isolated is not the same as evidence that the isolation works.
  • Outsource payment functions deliberately. Outsourcing can reduce scope, but it does not automatically remove your responsibilities for selecting and managing third-party service providers.
  • Prepare evidence before the formal assessment. Paying QSA rates while employees hunt for screenshots and policies is an avoidable luxury.

The dangerous version of “scope reduction” is declaring systems out of scope because assessing them would be expensive. The useful version changes architecture, data flows or dependencies so those systems no longer meet the criteria for inclusion.

What a Good ROC Quote Should Tell You

A ROC proposal should make it possible to understand why the number is what it is. If three quotes differ by $30,000 and you cannot identify the scope difference, you are not yet comparing equivalent services.

Ask the QSAWhy It MattersRed Flag
What systems, locations and payment channels are assumed in scope?Defines the workload behind the feeNo written scope assumptions
Is readiness or gap analysis included?Separates preparation from formal assessment“Everything included” without deliverables
Are remediation validation cycles included?Controls surprise change ordersEvery retest is automatically extra
Are ASV scanning and penetration testing included?Identifies separate technical-testing spendAssessment quote silently excludes expected testing
How much onsite work is assumed?Can affect assessor time and travelTravel costs left undefined
Who writes and quality-reviews the ROC?Reporting effort is a real part of the engagementUnclear responsibility for final documentation
What triggers a change order?Makes competing bids comparableOpen-ended additional-effort language

Before engaging a firm, verify that it is currently qualified in the PCI SSC Qualified Security Assessor directory. QSA qualification means the company has met PCI SSC program requirements to perform assessments. It is not an endorsement of the firm’s pricing, project management or commercial practices.

Do Not Pay Extra for a PCI “Certificate”

A glossy certificate should not be confused with recognized PCI DSS validation documentation. PCI SSC identifies the official SAQ, ROC and Attestation of Compliance forms as the relevant reporting documents and does not recognize generic compliance certificates as substitutes.

If a provider’s sales package emphasizes a proprietary “PCI certification,” ask exactly which official PCI SSC validation document you will receive. PCI SSC addresses this directly in its guidance on PCI DSS compliance certificates.

Your 15-Minute PCI Scope Check Before Requesting Quotes

You can eliminate a surprising amount of quote ambiguity before speaking to a QSA. Write down the answers to these questions and send the same scope summary to every provider.

  • Are you a merchant, service provider, or both?
  • Which payment brand or acquirer is requesting validation?
  • Have they explicitly requested an SAQ, ROC or specific AOC?
  • Which SAQ do you believe applies, and have you checked every eligibility criterion?
  • How many payment channels do you operate?
  • Do your systems store, process or transmit account data directly?
  • How many locations, cloud environments and major network segments are potentially in scope?
  • Which third-party service providers participate in payment processing?
  • Do you already have current network and cardholder-data-flow diagrams?
  • Is this your first PCI DSS v4.0.1 assessment or a repeat validation?
  • Do you expect customized approaches or compensating controls?
  • Do you need readiness consulting, formal assessment, or both?

If a provider cannot quote accurately from that information, the next purchase should usually be a bounded scoping exercise rather than an open-ended compliance project.

PCI DSS assessment cost

Frequently Asked Questions

Can I complete a PCI DSS SAQ without paying a QSA?

Potentially, yes. An SAQ is a self-assessment tool, and PCI SSC does not make hiring a QSA a universal condition for completing one. Your acquirer, payment brand or another compliance-accepting entity may impose specific validation requirements, however. Confirm those requirements before assuming a completely self-managed SAQ will be accepted.

Why can an SAQ D assessment still be expensive?

SAQ D covers a broad PCI DSS scope compared with narrower SAQs. Even when the organization technically self-assesses, identifying applicable requirements, collecting evidence, fixing gaps and validating technical controls can require substantial internal or consulting effort.

Is a ROC always performed by a QSA?

Not under every payment-brand program and every merchant circumstance. Some programs permit specific alternatives, including internal assessment in defined situations. Many organizations requiring a ROC, particularly service providers and entities needing independent validation, use a QSA. The controlling question is what the compliance-accepting entity requires.

Does using Stripe, PayPal or another payment provider eliminate PCI DSS?

No. Outsourcing payment functions can reduce the number of PCI DSS requirements applicable to your environment, sometimes dramatically, but the merchant still needs to determine its applicable responsibilities and validation method. The integration architecture matters as much as the provider name.

Should I choose the cheapest QSA quote?

Choose the least expensive quote only after confirming that scope, testing, travel, remediation validation, reporting and deliverables are comparable. A lower fee created by missing scope assumptions is not a saving. It is an invoice waiting for its second act.

What to Do Before You Request a PCI DSS Quote

Start with one question: “What validation documentation will you accept from us for this reporting period?” Send it to the acquirer, payment brand, payment facilitator or other entity that will receive your compliance evidence.

Once you know whether the answer is SAQ or ROC, document your payment channels and likely CDE boundary before contacting providers. Then request at least two quotes using the same written scope assumptions and ask each provider to separate assessment, readiness, technical testing and remediation support.

That turns PCI pricing from a foggy “How much does compliance cost?” conversation into something procurement can actually compare. More importantly, it prevents the cheapest-looking validation path from becoming the expensive one halfway through the assessment.

Last reviewed: 2026-10

Stay Updated with Kioptrix

Get practical guides, useful resources, and new articles delivered to your inbox.

No spam. Unsubscribe anytime. Read our Privacy Policy.