PCI DSS compliance cost varies enormously by merchant level. Level 4 SAQ-A self-assessment can be effectively zero. Level 1 ROC with a Qualified Security Assessor runs into five or six figures annually. Some gateways absorb the SAQ; some pass through a PCI non-compliance fee if the merchant fails to attest.
| Feature | Annual scope | Validation |
|---|---|---|
| Level 1 (>6M tx) | Annual ROC by QSA | Quarterly ASV scans |
| Level 2 (1M-6M tx) | Annual SAQ | Quarterly ASV scans |
| Level 3 (20K-1M e-com) | Annual SAQ | Quarterly ASV scans |
| Level 4 (<20K e-com) | Annual SAQ | Acquirer-discretion ASV |
PCI SSC maintains the only authoritative live directories of qualified assessors and scanning vendors. Use these directly to scope quotes rather than relying on third-party cost ranges:
Gateways that bill PCI non-compliance fees if the merchant fails to attest annually. We list only what we can verify.