What actually drives PCI DSS cost: a decomposition, not a range
PCI DSS cost is five separate bills paid to five different parties. Which lines you carry, what moves each, and why the two largest are set by scope before anyone quotes.
Nobody can give you a PCI DSS cost figure because it is not one number. It is five separate bills, paid to five different parties on five different cadences — and the two that usually dominate the total are settled before you speak to any vendor, by a scoping decision that costs nothing to make and a great deal to make badly.
The five lines, and who bills you for each
| Line | Who you pay | Billed in | When it applies |
|---|---|---|---|
| Validation | A QSA company — or nobody | Assessor-days | Where a Report on Compliance is required. On the self-assessment path there is no mandatory assessor fee at all |
| External scanning (11.3.2) | A PCI SSC Approved Scanning Vendor | Subscription, usually per external address, plus rescans | At least once every three months, for as long as you take cards |
| Penetration testing (11.4) | An independent testing firm, or a qualified internal team | Tester-days | At least once every 12 months — six-monthly for one part if you are a service provider |
| Remediation | Your own engineers, and your existing vendors | Engineer-time, licences, sometimes re-architecture | Whenever a scan, a test or a gap analysis finds something |
| Running the programme | Nobody — it is internal time | Person-days per month, permanently | Continuously, between assessments |
Only the first is the “audit fee” people ask about, and for a large share of Indian merchants it is zero: a Self-Assessment Questionnaire is exactly that, with SAQ D’s attestation block signed by the Merchant Executive Officer and the assessor block below it applying only “if a QSA was involved or assisted with this assessment”. Lines four and five are normally the largest, and neither appears on anybody’s quotation.
Scope sets four of the five
The SAQ Instructions and Guidelines puts the number of PCI DSS v4.x requirements at 14 or 27 for SAQ A, depending on how the checkout is built, 139 for SAQ A-EP and every applicable requirement for SAQ D for Merchants. That near-tenfold spread is decided by how your checkout was built — a redirect or an iframe to a compliant provider on one side, a Direct Post or a merchant-delivered script on the other — not by revenue or card volume.
That boundary then prices everything else: how many external addresses the ASV covers, how large a perimeter the penetration test must reach, how many systems remediation has to touch, how much evidence somebody produces every month for the next twelve. Which is why remediation started before scope is settled tends to be paid for twice, and why a scoping exercise producing a payment-flow diagram and a defensible cardholder data environment boundary is the cheapest money in the programme. Establish which questionnaire you are eligible for before you price anything.
What moves a QSA’s fee, and the one lever inside it
An assessment is priced on assessor-days: interviews, observation, and examination of evidence across in-scope system components. The standard says plainly what makes that number grow.
“If the entity has standardized processes and controls in place… the sample can be smaller… If the entity has no standardized PCI DSS processes/controls in place and each item in the population is managed through non-standardized processes, the sample must be larger.”
Samples must also “include every type and combination being used”. The multiplier on an assessment is therefore not the size of your estate but its heterogeneity: five operating system variants, three build processes and four ways of provisioning a server generate more sample sets and more assessor-days than a larger, uniform environment.
Nor can you amortise it. Assessors “must revalidate the sampling rationale for each assessment and consider previous sample sets”, and “different samples must be selected for each assessment”. Last year’s evidence set does not carry over, which makes standardisation the rare lever that pays again every year rather than once. On the fee itself, no figure published here would describe your market — the assessor list is public, and two quotations will tell you more than any average.
The ASV line is a subscription; the variable is rescans
Requirement 11.3.2 requires external scans “at least once every three months”, “by a PCI SSC Approved Scanning Vendor (ASV)”, with vulnerabilities “resolved and ASV Program Guide requirements for a passing scan… met” and “rescans… performed as needed”. It is also the one requirement in Requirement 11 that “is not eligible for the customized approach”.
So the annual bill is four scans plus however many rescans your remediation velocity forces. An estate that passes first time and one that needs six attempts are on the same subscription and not the same invoice: remediation speed, not address count, moves this line.
One first-year concession removes a twelve-month wait from the schedule: for an initial assessment, four passing scans within twelve months are not required if the assessor verifies that the most recent scan passed, that documented policies require three-monthly scanning, and that noted vulnerabilities were corrected as shown in a rescan. From the second year the passing scans must actually have occurred.
The post-change scan is a separate requirement with a separate rule. Requirement 11.3.2.1 covers external scanning after any significant change, resolving anything scored 4.0 or higher by CVSS, and specifies that “scans are performed by qualified personnel and organizational independence of the tester exists (not required to be a QSA or ASV)”. Your quarterly scanning is locked to your ASV’s price list. Your change-driven scanning is not.
Requirement 11.4 is not one test a year
| Requirement | What has to happen | Minimum cadence | Additional trigger |
|---|---|---|---|
| 11.4.1 | A documented penetration testing methodology, held by you | Maintained | — |
| 11.4.2 | Internal penetration testing | Every 12 months | After any significant infrastructure or application upgrade or change |
| 11.4.3 | External penetration testing | Every 12 months | After any significant infrastructure or application upgrade or change |
| 11.4.4 | Correction of exploitable findings, and the repeat test that verifies it | After every test that finds something exploitable | — |
| 11.4.5 | Segmentation control testing, where segmentation is used | Every 12 months | After any changes to segmentation controls or methods |
| 11.4.6 | Segmentation testing, service providers only | Every six months | After any changes to segmentation controls or methods |
| 11.4.7 | Multi-tenant providers support customer testing under 11.4.3 and 11.4.4 | On customer request | — |
Two organisations of identical size sit at opposite ends of that table. A merchant with a flat cardholder data environment and no segmentation carries two tests a year and their retests. A service provider that segments carries internal, external, two segmentation tests, the retests, whatever significant change adds, and the cost of supporting its own customers under 11.4.7.
The retest is the line most often missing from a comparison. Requirement 11.4.4 is not closed by fixing things — “penetration testing is repeated to verify the corrections” — so a quotation without a retest in it is not a cheaper version of one with a retest.
Our own scope, in tester-days
Effort rather than price, wide on purpose, and what any quotation is reasoning about underneath.
| Engagement | Band assumes | Tester-days |
|---|---|---|
| External test, 11.4.3 | CDE perimeter and connected critical systems, up to roughly fifty distinct live hosts | 5 – 10 |
| Internal test, 11.4.2 | One CDE and its trusted adjacent networks, assumed-breach start | 8 – 15 |
| Application-layer testing within 11.4.1 | One payment application, authenticated, covering at minimum the classes at Requirement 6.2.4 | 8 – 15 |
| Segmentation testing, 11.4.5 / 11.4.6 | All segmentation methods in use, one cycle | 3 – 6 |
| Retest, 11.4.4 | Verification of corrections from a single prior test | 2 – 4 |
The variable nobody prices: significant change
Both annual penetration tests are triggered by it, and so is the post-change external scan at 11.3.2.1 — and the standard leaves the judgement with you, because what counts “is highly dependent on the configuration of a given environment”. It does fix the minimum list you must evaluate: new or replaced hardware, software and networking equipment in the CDE; changes to the flow or storage of account data; changes to the CDE boundary or the assessment scope; changes to supporting infrastructure — directory services, time servers, logging, monitoring; and changes to the third parties supporting the CDE.
For a business shipping infrastructure changes weekly, that list is a budget item. Treat everything as significant and the testing line stops being annual; treat nothing as significant and the judgement has to survive an assessor reading your change records. Your change process decides this, not your vendor.
The line that never ends
Between assessments the programme runs on internal time. Penetration testing results and remediation records are retained for at least 12 months. Each requirement that specifies a targeted risk analysis — the ones that let you set your own frequency — needs one documented under 12.3.1 and reviewed at least once every 12 months. Third-party service providers need a maintained list, a compliance status monitored at least once every 12 months (12.8.4), and a record of which requirements each manages (12.8.5).
Service providers carry the quietest permanent cost in the standard. Requirement 12.4.2 requires reviews “at least once every three months to confirm that personnel are performing their tasks in accordance with all security policies and operational procedures”, performed “by personnel other than those responsible for performing the given task”. Four times a year, indefinitely, by someone who did not do the work — a staffing decision rather than a project cost, and the part of the evidence pack most often assembled retrospectively.
Five questions before you compare two numbers
- Which questionnaire or report is this scoped to? A price against SAQ A and one against SAQ D are not comparable.
- How many assessor-days, against how many sample sets? Sample size follows from how standardised your estate is.
- How many external addresses does the ASV price, and what does a rescan cost? That clause is where the line overruns.
- Does the testing price include the 11.4.4 retest, and how many? Ask before you compare, not after you choose.
- Are you a service provider? Then six-monthly segmentation testing under 11.4.6 and quarterly reviews under 12.4.2 both need pricing, and both are routinely missing from a first budget.
None of those answers is a price. Together they are why two honest quotations for the same organisation differ by a factor of three. To turn effort into money, the pricing primer builds an estimate from tester-days rather than a rate card, and the arithmetic in it is yours rather than ours.
About the author
Chintan J
CISO & Director — Security Advisory
Oversees Security Brigade's cybersecurity advisory practice, helping regulated enterprises meet RBI, SEBI, CERT-In, and IRDAI compliance mandates. Previously held senior security leadership roles across BFSI.
Continue reading
All articles →What is and is not PCI DSS: SSF, P2PE, 3DS, PIN — and where PA-DSS went
PCI DSS assesses your organisation. SSF, P2PE, PTS, 3DS and PIN Security assess products and other parties. Where PA-DSS went, and what a listing changes.
Which PCI SSC document says what, and which PCI DSS version it is written against
PCI DSS v4.0.1 is the only active version: v4.0 retired 31 December 2024, v3.2.1 on 31 March 2024. Which PCI SSC document answers which question, and what version each carries.
PCI DSS renewal is a re-scope, not a repeat
Nothing renews on the anniversary. Requirement 12.5.2 asks the entity to re-confirm scope every twelve months, and a test scoped to last year's CDE is the first mismatch an assessor sees.