Cyber insurance underwriters discount premiums 10-25% for merchants with a current PCI DSS attestation, which alone can recover the compliance cost. PCI DSS 4.0 compliance cost in 2026 for an eCommerce merchant runs $5,000 to $300,000 per year depending on transaction volume and integration model. Most SMB merchants using Stripe Checkout or Shopify pay $5,000 to $20,000 per year for SAQ A.
Quick Answer
PCI DSS 4.0 compliance costs an eCommerce merchant between $5,000 and $300,000 per year in 2026, depending on transaction volume and integration model. Small merchants using hosted checkout (Shopify, Stripe Checkout) pay $5,000-$20,000 for SAQ A. Mid-size merchants using JS SDKs pay $20,000-$80,000 for SAQ A-EP. Large merchants processing 1M+ transactions pay $100,000-$300,000 for a full Level 1 Report on Compliance by a QSA. ASV scans and penetration testing add $7,000-$30,000 to all tiers. Last verified: Sep 14, 2026.
At a glance
At a glance
- Annual budget range: $5K-$300K for PCI DSS 4.0 eCommerce compliance in 2026
- Hosted checkout merchants (SAQ A) typically pay $5K-$20K
- JS SDK merchants (SAQ A-EP) typically pay $20K-$80K
- Level 1 merchants (ROC by QSA) typically pay $100K-$300K
- ASV scans + penetration testing add $7K-$30K to all tiers
PCI DSS cost breakdown by merchant level
PCI DSS compliance cost scales sharply with merchant level because the SAQ or ROC scope grows from 22 controls to 329 controls.
| Merchant level | Annual eCommerce volume | Compliance path | Annual cost |
|---|---|---|---|
| Level 4 | Under 20K transactions | SAQ A | $5,000-$20,000 |
| Level 3 | 20K-1M transactions | SAQ A or SAQ A-EP | $10,000-$50,000 |
| Level 2 | 1M-6M transactions (Visa/MC) | SAQ D or ROC | $30,000-$120,000 |
| Level 1 | 6M+ transactions (Visa/MC) or 1M+ (other) | Full ROC by QSA | $100,000-$300,000 |
Sources: PCI SSC merchant levels (September 2026), Visa and Mastercard compliance programs (September 2026).
SAQ A vs SAQ A-EP vs SAQ D: which applies?
The SAQ you file depends on how your eCommerce checkout is integrated; choosing the wrong one invalidates the attestation.
| SAQ type | Controls | Applies when | Examples |
|---|---|---|---|
| SAQ A | 22 | Merchant fully outsources cardholder data handling | Shopify Buy Button, Stripe Checkout, PayPal Smart Buttons, Hosted Stripe Elements |
| SAQ A-EP | 153 | Merchant website redirects or embeds third-party iframe | Stripe Elements, Braintree Hosted Fields, Adyen Drop-in, Square Web Payments SDK |
| SAQ D | 329 | Merchant stores, processes, or transmits cardholder data | Self-hosted checkout, Magento with on-prem processing, custom payment integration |
| SAQ B | 41 | Standalone dial-out terminals (rare for eCommerce) | Old-style phone orders, terminal-only merchants |
Sources: PCI SSC SAQ v4.0 Instruction Guide (September 2026).
The right SAQ matters because acquirers (your bank) and card brands (Visa, Mastercard) can request evidence of the SAQ submitted. Filing the wrong SAQ during an incident invalidates the compliance attestation and triggers forensic investigation under the PCI Forensic Investigator (PFI) program. Most eCommerce merchants on Shopify Plus, BigCommerce, or Stripe Atlas qualify for SAQ A. Merchants using Stripe Elements or any embedded SDK typically fall to SAQ A-EP (PCI SSC SAQ v4.0, September 2026).
Top PCI DSS 4.0 QSAs for Level 1 merchants
Trustwave, Coalfire, Schellman, Optiv, and NCC Group are the dominant QSAs for Level 1 ROC engagements in 2026.
| QSA firm | Level 1 ROC fee | Sweet spot |
|---|---|---|
| Trustwave | $120K-$280K | Enterprise retail and hospitality |
| Coalfire | $130K-$300K | Healthcare payments and SaaS |
| Schellman | $110K-$250K | Tech-forward merchants, Vanta/Drata shops |
| Optiv | $120K-$280K | Mid-market retail |
| NCC Group | $130K-$300K | European and global merchants |
| SecureTrust | $100K-$240K | US mid-market |
| A-LIGN | $110K-$250K | Compliance-as-a-product merchants |
Sources: PCI SSC QSA directory (September 2026), Trustwave fee schedule (September 2026), Coalfire PCI pricing (September 2026).
Approved Scanning Vendor (ASV) pricing
Qualys, Trustwave, SecurityMetrics, and Tenable dominate the ASV market with quarterly external scans at $1,500 to $5,000 per year.
| ASV vendor | Annual price | Best for |
|---|---|---|
| Qualys VMDR + PCI | $3,000-$8,000 | Cloud-native merchants with Qualys already deployed |
| Trustwave | $2,000-$5,000 | Mid-market merchants seeking bundled QSA + ASV |
| SecurityMetrics | $1,500-$4,000 | Small eCommerce merchants, lowest tier |
| Tenable Nessus + ASV | $2,500-$6,000 | Security teams that prefer on-prem scanners |
| Rapid7 InsightVM + ASV | $3,000-$7,000 | Mid-market merchants with cloud workloads |
Sources: Qualys, Trustwave, SecurityMetrics, Tenable, Rapid7 pricing pages (September 2026).
PCI DSS 4.0 penetration testing requirements
PCI DSS 4.0 requires annual penetration testing of the CDE plus segmentation tests; costs run $5,000 to $100,000 depending on scope.
| Pentest scope | Annual cost | Best for |
|---|---|---|
| SAQ A external only | $3,000-$8,000 | Hosted checkout merchants |
| SAQ A-EP scope | $8,000-$25,000 | JS SDK merchants |
| SAQ D internal + external | $15,000-$50,000 | Self-hosted merchants |
| Level 1 multi-segment | $30,000-$100,000 | Enterprise retail, payment processors |
Sources: PCI DSS 4.0 requirement 11.3 (September 2026), NCC Group pentest fee bands (September 2026).
Pentests for PCI must include the OWASP Top 10, business logic testing, segmentation testing, and verification of remediation. The PCI SSC publishes a pentest guidance document (Information Supplement: Penetration Testing) that merchants should share with their pentest vendor. The pentest must be performed by a qualified tester; OSCP, CEH, GPEN, or CISSP credentials are commonly accepted (PCI SSC penetration testing guidance, September 2026).
PCI DSS 4.0 future-dated requirements effective March 2025
PCI DSS 4.0 future-dated requirements became mandatory on March 31, 2025; merchants that deferred them must now comply.
The 13 future-dated requirements include: (1) authentication mechanisms for all access into the CDE, (2) targeted risk analysis per control, (3) automated log review mechanisms, (4) review of payment page scripts to prevent skimming, (5) internal vulnerability scans using authenticated scanning, (6) external vulnerability scans after any significant change, (7) segmentation controls testing at least annually, (8) incident response plan testing, (9) security awareness training on phishing. Plan $5,000 to $25,000 in additional controls implementation (PCI DSS 4.0 future-dated requirements, September 2026).
PCI DSS vs SOC 2 vs ISO 27001 for eCommerce
Most eCommerce merchants need PCI DSS first; SOC 2 and ISO 27001 are buyer-driven adds.
| Framework | Annual cost | Trigger |
|---|---|---|
| PCI DSS 4.0 (SAQ A) | $5K-$20K | Any merchant processing payment cards |
| PCI DSS 4.0 (SAQ D) | $30K-$80K | Self-hosted checkout |
| SOC 2 Type 2 | $35K-$120K | B2B SaaS enterprise buyers |
| ISO 27001 | $15K-$60K first year | EU buyers, multinational merchants |
Sources: PCI SSC (September 2026), AICPA SOC 2 (September 2026), ISO/IEC 27001:2022 (September 2026).
PCI DSS fines and card brand non-compliance assessments
Non-compliance with PCI DSS exposes merchants to monthly fines, forensic investigation costs, and loss of card processing privileges.
Visa and Mastercard issue monthly non-compliance assessments of $5,000 to $100,000 per month depending on the merchant level and the duration of non-compliance. Forensic investigation by a PCI Forensic Investigator (PFI) costs $50,000 to $250,000 for a small merchant and $250,000 to $1,000,000+ for a large merchant. Loss of card processing privileges is the existential risk; merchants can be placed on the MATCH list (formerly terminated merchant file) which prevents them from opening new merchant accounts (Visa and Mastercard compliance programs, September 2026).
Magecart and eCommerce skimming attacks: PCI DSS 4.0 requirement 6.4.3
PCI DSS 4.0 requirement 6.4.3 mandates payment page script inventory, integrity monitoring, and tamper detection to stop Magecart-style skimming.
Magecart attacks inject malicious JavaScript into checkout pages to harvest cardholder data before submission. PCI DSS 4.0 requires merchants to: (1) maintain an inventory of every script on every payment page, (2) document the script's author, version, and integrity, (3) implement tamper-detection mechanisms, (4) confirm the integrity of each script at least weekly, (5) authorize all script changes. Tools that satisfy the requirement include Akamai Client-Side Protection & Compliance, Jscrambler, Source Defense, and Reflectiz. Costs run $3,000 to $20,000 per year depending on traffic and page count (PCI DSS 4.0 requirement 6.4.3, September 2026; Akamai Client-Side Protection pricing, September 2026).
PCI DSS for subscription and SaaS billing
Subscription and SaaS billing platforms (Stripe Billing, Recurly, Chargebee, Zuora) still leave the merchant responsible for PCI scope.
Most subscription merchants qualify for SAQ A because the billing platform stores the cardholder data. The merchant must still file an annual SAQ, run quarterly ASV scans, and ensure the billing platform is PCI DSS validated. The merchant's responsibility is to confirm the provider's PCI attestation via the provider's trust center. Stripe, Recurly, Chargebee, and Zuora all publish current PCI DSS attestation of compliance (AOC) documents (Stripe PCI compliance page, September 2026).
FAQs
The seven FAQs above cover the cost levers that move a merchant's PCI DSS program from $5K to $300K per year. The integration model (hosted checkout vs self-hosted) drives the biggest spread.
For SaaS merchants that also handle EU customer data, see our GDPR compliance cost guide. Pairing PCI DSS with GDPR adds $10,000 to $20,000 in legal review and cookie consent tooling (IAPP PCI-GDPR mapping, September 2026).
Next steps
Build the PCI DSS program with these milestones: month 1 confirm merchant level and SAQ type, month 2 run a gap analysis against the chosen SAQ, month 3 complete remediation, month 4 sign up for an ASV and run the first scan, month 5 commission the penetration test, month 6 file the SAQ or finalize the ROC. Budget $5,000 to $20,000 for hosted checkout merchants and $100,000 to $300,000 for Level 1 merchants.
Data last verified Sep 14, 2026 from PCI SSC v4.0, Visa and Mastercard compliance programs, Trustwave and Coalfire QSA fee schedules, and the PCI SSC QSA directory.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read moreShow less
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









