PCI Assessments Center
Loading your workspace…
There is no list price for PCI DSS compliance, because cost tracks scope rather than company size. The spend falls into four buckets: validation effort (SAQ or ROC), mandatory testing (quarterly ASV scans, annual penetration testing where applicable), remediation of gaps, and ongoing operations. Cutting scope cuts every bucket at once.
The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.
Written by Haumaru Whānau QSAs. PCI DSS content paraphrased from PCI DSS v4.0.1 and PCI SSC published guidance; payment brand programmes are set by the brands and your acquirer. Independent summary; not endorsed by PCI SSC.