PCI Compliance Cost: SAQ-A to Level 1 RoC
What PCI compliance actually costs at your merchant level, and which gateways absorb the burden for you.
PCI DSS sorts merchants into four levels by annual card transaction count (Visa: Level 1 >6M, Level 2 1-6M, Level 3 20K-1M ecommerce, Level 4 <20K ecommerce or <1M total). The PCI Security Standards Council publishes the SAQ types and validation requirements at pcisecuritystandards.org but does not publish a price list, because every cost component (QSA fees, ASV scans, internal compliance program time) is set by the assessor and the merchant's environment complexity. The ranges below are directional bands frequently quoted by QSAs and merchant-advisory firms, not figures from a single named PCI SSC dataset; treat them as a starting point for a scoping conversation, not a verified industry average.
Indicative cost bands by merchant level
Illustrative ranges only. Compiled from QSA-firm public price-list pages and the Verizon Payment Security Report (verizon.com/business/resources/reports/payment-security-report/); your actual cost is set by your QSA, ASV, and environment scope.
The four PCI merchant levels
| Feature | Level 1 | Level 2 | Level 3 | Level 4 |
|---|---|---|---|---|
| Volume threshold (Visa) | ✓ | ✓ | ✓ | ✓ |
| QSA Report on Compliance | ✓ | ✗ | ✗ | ✗ |
| Self-assessment SAQ | ✗ | ✓ | ✓ | ✓ |
| Quarterly ASV scan required | ✓ | ✓ | ✓ | ◐ |
| Penetration test required | ✓ | ✓ | ✗ | ✗ |
| Internal vulnerability scans | ✓ | ✓ | ✓ | ✗ |
Cost ranges per level
Gateways that absorb PCI burden
- Stripe.js, Stripe Checkout, Stripe Elements: tokens never touch your server. Qualifies you for SAQ-A on most ecommerce setups.
- PayPal Hosted: redirect or iframe. Customer enters card on PayPal's domain. SAQ-A scope.
- Square hosted checkout / Square iframe: same scope reduction.
- Direct API (Stripe Payment Intents server-side, Adyen Drop-in self-hosted): scope creeps to SAQ-A-EP or SAQ-D.
Hidden PCI costs even on SAQ-A
- Some flat-rate processors charge $10-$30/mo as a PCI fee. Negotiable; often waivable on request.
- Non-compliance fees: typical $20-$30/mo if you miss the annual self-assessment.
- Breach penalties: card networks levy non-compliance and forensic fines that have been publicly reported in the high five and six figures per incident depending on cardholder volume and violation type. The networks do not publish a public penalty schedule, so use these as directional only and check your acquirer agreement for the specific contractual fines and pass-throughs.