Topic, verified June 2026

PCI Compliance Cost

PCI DSS compliance cost varies enormously by merchant level. Level 4 SAQ-A self-assessment can be effectively zero. Level 1 ROC with a Qualified Security Assessor runs into five or six figures annually. Some gateways absorb the SAQ; some pass through a PCI non-compliance fee if the merchant fails to attest.

L1
Over 6M tx/yr
Annual ROC + QSA + ASV scans
L2
1M to 6M tx/yr
Annual SAQ + ASV scans
L3
20K to 1M e-com tx/yr
Annual SAQ + ASV scans
L4
Under 20K e-com tx/yr
Annual SAQ
Direct answer
For a Level 4 SaaS / ecommerce merchant using a fully tokenised gateway like Stripe Checkout or PayPal hosted fields, PCI compliance reduces to a SAQ-A questionnaire that the gateway typically pre-fills and the merchant attests to in minutes; direct cost ~$0. For Level 1 merchants, an annual Report on Compliance (ROC) from a Qualified Security Assessor (QSA) and quarterly Approved Scanning Vendor (ASV) scans are both quoted per engagement: QSA fees depend on cardholder-data environment scope, locations, and remediation scope, and ASV fees depend on the number of external IPs scanned. QSA and ASV companies are listed in the PCI SSC public directories rather than via a published rate card.

Levels and what is required

FeatureAnnual scopeValidation
Level 1 (>6M tx)Annual ROC by QSAQuarterly ASV scans
Level 2 (1M-6M tx)Annual SAQQuarterly ASV scans
Level 3 (20K-1M e-com)Annual SAQQuarterly ASV scans
Level 4 (<20K e-com)Annual SAQAcquirer-discretion ASV

Where to source a QSA or ASV

PCI SSC maintains the only authoritative live directories of qualified assessors and scanning vendors. Use these directly to scope quotes rather than relying on third-party cost ranges:

PCI non-compliance fees by gateway

Gateways that bill PCI non-compliance fees if the merchant fails to attest annually. We list only what we can verify.

Related

Quote-only vendors
Where the PCI fee usually lurks.
Methodology
How we verify gateway claims.
3DS and fraud tooling
Other compliance-adjacent costs.
Last verified June 2026. Next review September 2026. Rates change without notice; always confirm directly with the vendor before signing a contract.