Skip to main content

What actually drives PCI DSS cost: a decomposition, not a range

PCI DSS cost is five separate bills paid to five different parties. Which lines you carry, what moves each, and why the two largest are set by scope before anyone quotes.

By Chintan J
August 20, 20268 min read

Nobody can give you a PCI DSS cost figure because it is not one number. It is five separate bills, paid to five different parties on five different cadences — and the two that usually dominate the total are settled before you speak to any vendor, by a scoping decision that costs nothing to make and a great deal to make badly.

The five lines, and who bills you for each

LineWho you payBilled inWhen it applies
ValidationA QSA company — or nobodyAssessor-daysWhere a Report on Compliance is required. On the self-assessment path there is no mandatory assessor fee at all
External scanning (11.3.2)A PCI SSC Approved Scanning VendorSubscription, usually per external address, plus rescansAt least once every three months, for as long as you take cards
Penetration testing (11.4)An independent testing firm, or a qualified internal teamTester-daysAt least once every 12 months — six-monthly for one part if you are a service provider
RemediationYour own engineers, and your existing vendorsEngineer-time, licences, sometimes re-architectureWhenever a scan, a test or a gap analysis finds something
Running the programmeNobody — it is internal timePerson-days per month, permanentlyContinuously, between assessments

Only the first is the “audit fee” people ask about, and for a large share of Indian merchants it is zero: a Self-Assessment Questionnaire is exactly that, with SAQ D’s attestation block signed by the Merchant Executive Officer and the assessor block below it applying only “if a QSA was involved or assisted with this assessment”. Lines four and five are normally the largest, and neither appears on anybody’s quotation.

Scope sets four of the five

The SAQ Instructions and Guidelines puts the number of PCI DSS v4.x requirements at 14 or 27 for SAQ A, depending on how the checkout is built, 139 for SAQ A-EP and every applicable requirement for SAQ D for Merchants. That near-tenfold spread is decided by how your checkout was built — a redirect or an iframe to a compliant provider on one side, a Direct Post or a merchant-delivered script on the other — not by revenue or card volume.

That boundary then prices everything else: how many external addresses the ASV covers, how large a perimeter the penetration test must reach, how many systems remediation has to touch, how much evidence somebody produces every month for the next twelve. Which is why remediation started before scope is settled tends to be paid for twice, and why a scoping exercise producing a payment-flow diagram and a defensible cardholder data environment boundary is the cheapest money in the programme. Establish which questionnaire you are eligible for before you price anything.

What moves a QSA’s fee, and the one lever inside it

An assessment is priced on assessor-days: interviews, observation, and examination of evidence across in-scope system components. The standard says plainly what makes that number grow.

“If the entity has standardized processes and controls in place… the sample can be smaller… If the entity has no standardized PCI DSS processes/controls in place and each item in the population is managed through non-standardized processes, the sample must be larger.”

Samples must also “include every type and combination being used”. The multiplier on an assessment is therefore not the size of your estate but its heterogeneity: five operating system variants, three build processes and four ways of provisioning a server generate more sample sets and more assessor-days than a larger, uniform environment.

Nor can you amortise it. Assessors “must revalidate the sampling rationale for each assessment and consider previous sample sets”, and “different samples must be selected for each assessment”. Last year’s evidence set does not carry over, which makes standardisation the rare lever that pays again every year rather than once. On the fee itself, no figure published here would describe your market — the assessor list is public, and two quotations will tell you more than any average.

The ASV line is a subscription; the variable is rescans

Requirement 11.3.2 requires external scans “at least once every three months”, “by a PCI SSC Approved Scanning Vendor (ASV)”, with vulnerabilities “resolved and ASV Program Guide requirements for a passing scan… met” and “rescans… performed as needed”. It is also the one requirement in Requirement 11 that “is not eligible for the customized approach”.

So the annual bill is four scans plus however many rescans your remediation velocity forces. An estate that passes first time and one that needs six attempts are on the same subscription and not the same invoice: remediation speed, not address count, moves this line.

One first-year concession removes a twelve-month wait from the schedule: for an initial assessment, four passing scans within twelve months are not required if the assessor verifies that the most recent scan passed, that documented policies require three-monthly scanning, and that noted vulnerabilities were corrected as shown in a rescan. From the second year the passing scans must actually have occurred.

The post-change scan is a separate requirement with a separate rule. Requirement 11.3.2.1 covers external scanning after any significant change, resolving anything scored 4.0 or higher by CVSS, and specifies that “scans are performed by qualified personnel and organizational independence of the tester exists (not required to be a QSA or ASV)”. Your quarterly scanning is locked to your ASV’s price list. Your change-driven scanning is not.

Requirement 11.4 is not one test a year

RequirementWhat has to happenMinimum cadenceAdditional trigger
11.4.1A documented penetration testing methodology, held by youMaintained
11.4.2Internal penetration testingEvery 12 monthsAfter any significant infrastructure or application upgrade or change
11.4.3External penetration testingEvery 12 monthsAfter any significant infrastructure or application upgrade or change
11.4.4Correction of exploitable findings, and the repeat test that verifies itAfter every test that finds something exploitable
11.4.5Segmentation control testing, where segmentation is usedEvery 12 monthsAfter any changes to segmentation controls or methods
11.4.6Segmentation testing, service providers onlyEvery six monthsAfter any changes to segmentation controls or methods
11.4.7Multi-tenant providers support customer testing under 11.4.3 and 11.4.4On customer request

Two organisations of identical size sit at opposite ends of that table. A merchant with a flat cardholder data environment and no segmentation carries two tests a year and their retests. A service provider that segments carries internal, external, two segmentation tests, the retests, whatever significant change adds, and the cost of supporting its own customers under 11.4.7.

The retest is the line most often missing from a comparison. Requirement 11.4.4 is not closed by fixing things — “penetration testing is repeated to verify the corrections” — so a quotation without a retest in it is not a cheaper version of one with a retest.

Our own scope, in tester-days

Effort rather than price, wide on purpose, and what any quotation is reasoning about underneath.

EngagementBand assumesTester-days
External test, 11.4.3CDE perimeter and connected critical systems, up to roughly fifty distinct live hosts5 – 10
Internal test, 11.4.2One CDE and its trusted adjacent networks, assumed-breach start8 – 15
Application-layer testing within 11.4.1One payment application, authenticated, covering at minimum the classes at Requirement 6.2.48 – 15
Segmentation testing, 11.4.5 / 11.4.6All segmentation methods in use, one cycle3 – 6
Retest, 11.4.4Verification of corrections from a single prior test2 – 4

The variable nobody prices: significant change

Both annual penetration tests are triggered by it, and so is the post-change external scan at 11.3.2.1 — and the standard leaves the judgement with you, because what counts “is highly dependent on the configuration of a given environment”. It does fix the minimum list you must evaluate: new or replaced hardware, software and networking equipment in the CDE; changes to the flow or storage of account data; changes to the CDE boundary or the assessment scope; changes to supporting infrastructure — directory services, time servers, logging, monitoring; and changes to the third parties supporting the CDE.

For a business shipping infrastructure changes weekly, that list is a budget item. Treat everything as significant and the testing line stops being annual; treat nothing as significant and the judgement has to survive an assessor reading your change records. Your change process decides this, not your vendor.

The line that never ends

Between assessments the programme runs on internal time. Penetration testing results and remediation records are retained for at least 12 months. Each requirement that specifies a targeted risk analysis — the ones that let you set your own frequency — needs one documented under 12.3.1 and reviewed at least once every 12 months. Third-party service providers need a maintained list, a compliance status monitored at least once every 12 months (12.8.4), and a record of which requirements each manages (12.8.5).

Service providers carry the quietest permanent cost in the standard. Requirement 12.4.2 requires reviews “at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures”, performed “by personnel other than those responsible for performing the given task”. Four times a year, indefinitely, by someone who did not do the work — a staffing decision rather than a project cost, and the part of the evidence pack most often assembled retrospectively.

Five questions before you compare two numbers

  • Which questionnaire or report is this scoped to? A price against SAQ A and one against SAQ D are not comparable.
  • How many assessor-days, against how many sample sets? Sample size follows from how standardised your estate is.
  • How many external addresses does the ASV price, and what does a rescan cost? That clause is where the line overruns.
  • Does the testing price include the 11.4.4 retest, and how many? Ask before you compare, not after you choose.
  • Are you a service provider? Then six-monthly segmentation testing under 11.4.6 and quarterly reviews under 12.4.2 both need pricing, and both are routinely missing from a first budget.

None of those answers is a price. Together they are why two honest quotations for the same organisation differ by a factor of three. To turn effort into money, the pricing primer builds an estimate from tester-days rather than a rate card, and the arithmetic in it is yours rather than ours.

About the author

Chintan J

CISO & Director — Security Advisory

Oversees Security Brigade's cybersecurity advisory practice, helping regulated enterprises meet RBI, SEBI, CERT-In, and IRDAI compliance mandates. Previously held senior security leadership roles across BFSI.