The PCI DSS certification process, explained

PCI DSS certification, end to end.

ROC or SAQ? How long? What does the QSA actually do? We walk through the entire PCI DSS certification process — the five phases, the real timeline, the real costs — and then match you with accredited QSA companies to do the work. Free. Two minutes. No obligation.

Free · 2 minutes · No obligation

5 phasesScope → gap → remediate → fieldwork → report
4–9 moTypical first certification, end to end
1 yearHow long a ROC stays valid
ROC or SAQYour level decides which path you take

How quote matching works

  1. Tell us once — 4 questions, 2 minutes, free.
  2. We match you — accredited QSA companies filtered to your size, scope, and timeline.
  3. QSAs quote you — they send scoped quotes directly; you pick.
The process

The five phases of PCI DSS certification

Every PCI certification — ROC or SAQ — follows the same five phases. Knowing them is how you budget, schedule, and avoid paying a QSA to discover what a gap assessment would have found.

1. Scoping

Define exactly what's in your cardholder data environment — the step that controls your fee.

2. Gap assessment

Measure your controls against PCI DSS v4.0.1 before the real assessment starts.

3. Remediation

Close the gaps. This is where most of the calendar time goes.

4. QSA fieldwork

The assessor tests your controls and documents evidence — 2 to 12 weeks.

5. Report & attest

The ROC is signed and your AoC goes to your acquirer. Valid one year.

Read the full process guide →

Start here

PCI DSS certification, explained honestly

How PCI Certification Works

The full end-to-end process: ROC vs SAQ, the five phases, and the annual cycle.

PCI Certification Timeline

Realistic durations for every phase — first certification and renewals.

PCI DSS Cost Guide

What each phase costs, what drives the fee, and an interactive estimator.

PCI Readiness Check

A 2-minute scored quiz: are you ready for a QSA, or do you need gap work first?

2026 Pricing Report

Every cost figure we publish, with its source and date. No invented averages.

ROC vs SAQ

Which validation path applies to you — and who signs what.

SAQ Types A–D, Explained

Which self-assessment questionnaire fits your payment setup.

RFP & Quote Comparison

What to put in your brief, a printable comparison worksheet, and engagement-letter red flags.

Our Methodology

How we vet QSA companies, label every price, and keep rankings unbought.

QSA company directory

When you're ready: accredited QSA companies

Phases 4 and 5 need a QSA — and only an accredited QSA company can sign your ROC. Every firm below is a real, operating QSA company with a website we load-verified in September 2026. We are an independent directory — listings are not endorsements.

QSA company

Coalfire Systems

Coalfire is one of the largest QSA companies operating in North America. It is the named assessor on Amazon and AWS PCI DSS validations in Visa's Glob…

Westminster, Colorado · QSA company (QSAC)
QSA company

SecurityMetrics

SecurityMetrics is a PCI-focused QSA company whose published materials emphasize practical, deadline-driven assessments with strong communication. Its…

Orem, Utah · QSA company (QSAC)
QSA company

KirkpatrickPrice

KirkpatrickPrice is an assurance firm with PCI DSS, SOC, ISO, HIPAA, and HITRUST practices. Its published materials emphasize a concierge-style client…

Brentwood, Tennessee · QSA company (QSAC)
QSA company

BARR Advisory

BARR Advisory announced its accreditation as a PCI QSA company by the PCI Security Standards Council in January 2024 (Business Wire), adding PCI DSS t…

Kansas City, Missouri · QSA company (QSAC)

See all 17 firms →

Common questions

PCI DSS certification basics

Do I need a ROC or a SAQ?

It depends on your merchant or service-provider level, which the card brands set by annual transaction volume. Level 1 merchants (6M+ Visa/Mastercard transactions a year) and Level 1–2 service providers need an on-site assessment by a QSA producing a Report on Compliance (ROC). Smaller merchants typically complete a Self-Assessment Questionnaire (SAQ) themselves. Your acquirer confirms your level — don't buy a ROC nobody asked for. See how certification works.

How long does PCI DSS certification take?

The QSA's fieldwork is 2 to 12 weeks, but the full journey — scoping, gap assessment, remediation, then the ROC — usually takes 4 to 9 months for a first certification. The ROC is valid for one year, and the cycle repeats. See the timeline.

How much does PCI DSS certification cost?

Planning estimates (September 2026): a Level 1 ROC assessment typically runs $30,000 to $100,000+ in QSA fees depending on scope, with first-year all-in costs of $75,000 to $250,000+ once readiness, pen testing, remediation, and staff time are included. Guided SAQ engagements run $5,000–25,000. See our cost guide and the 2026 pricing report for every figure with its source.

Who can certify us for PCI DSS?

Only a Qualified Security Assessor (QSA) — an individual employed by an accredited QSA company and qualified by the PCI Security Standards Council — can perform an on-site assessment and sign a ROC. Compliance platforms can prepare you, but they cannot sign the report. Verify any firm on the PCI SSC's assessor listings before engaging.

All frequently asked questions →

Get quotes from accredited QSA companies

Tell us about your environment and timeline once. We’ll match you with QSA companies that fit — no obligation, no spam.

Get a free quote