PCI DSS certification, end to end.
ROC or SAQ? How long? What does the QSA actually do? We walk through the entire PCI DSS certification process — the five phases, the real timeline, the real costs — and then match you with accredited QSA companies to do the work. Free. Two minutes. No obligation.
Free · 2 minutes · No obligation
How quote matching works
- Tell us once — 4 questions, 2 minutes, free.
- We match you — accredited QSA companies filtered to your size, scope, and timeline.
- QSAs quote you — they send scoped quotes directly; you pick.
We are a quote-matching service, not an assessment firm, and listings are not endorsements. How we vet firms and label prices →
The five phases of PCI DSS certification
Every PCI certification — ROC or SAQ — follows the same five phases. Knowing them is how you budget, schedule, and avoid paying a QSA to discover what a gap assessment would have found.
1. Scoping
Define exactly what's in your cardholder data environment — the step that controls your fee.
2. Gap assessment
Measure your controls against PCI DSS v4.0.1 before the real assessment starts.
3. Remediation
Close the gaps. This is where most of the calendar time goes.
4. QSA fieldwork
The assessor tests your controls and documents evidence — 2 to 12 weeks.
5. Report & attest
The ROC is signed and your AoC goes to your acquirer. Valid one year.
PCI DSS certification, explained honestly
How PCI Certification Works
The full end-to-end process: ROC vs SAQ, the five phases, and the annual cycle.
PCI Certification Timeline
Realistic durations for every phase — first certification and renewals.
PCI DSS Cost Guide
What each phase costs, what drives the fee, and an interactive estimator.
PCI Readiness Check
A 2-minute scored quiz: are you ready for a QSA, or do you need gap work first?
2026 Pricing Report
Every cost figure we publish, with its source and date. No invented averages.
ROC vs SAQ
Which validation path applies to you — and who signs what.
SAQ Types A–D, Explained
Which self-assessment questionnaire fits your payment setup.
RFP & Quote Comparison
What to put in your brief, a printable comparison worksheet, and engagement-letter red flags.
Our Methodology
How we vet QSA companies, label every price, and keep rankings unbought.
When you're ready: accredited QSA companies
Phases 4 and 5 need a QSA — and only an accredited QSA company can sign your ROC. Every firm below is a real, operating QSA company with a website we load-verified in September 2026. We are an independent directory — listings are not endorsements.
Coalfire Systems
Coalfire is one of the largest QSA companies operating in North America. It is the named assessor on Amazon and AWS PCI DSS validations in Visa's Glob…
SecurityMetrics
SecurityMetrics is a PCI-focused QSA company whose published materials emphasize practical, deadline-driven assessments with strong communication. Its…
KirkpatrickPrice
KirkpatrickPrice is an assurance firm with PCI DSS, SOC, ISO, HIPAA, and HITRUST practices. Its published materials emphasize a concierge-style client…
BARR Advisory
BARR Advisory announced its accreditation as a PCI QSA company by the PCI Security Standards Council in January 2024 (Business Wire), adding PCI DSS t…
PCI DSS certification basics
Do I need a ROC or a SAQ?
It depends on your merchant or service-provider level, which the card brands set by annual transaction volume. Level 1 merchants (6M+ Visa/Mastercard transactions a year) and Level 1–2 service providers need an on-site assessment by a QSA producing a Report on Compliance (ROC). Smaller merchants typically complete a Self-Assessment Questionnaire (SAQ) themselves. Your acquirer confirms your level — don't buy a ROC nobody asked for. See how certification works.
How long does PCI DSS certification take?
The QSA's fieldwork is 2 to 12 weeks, but the full journey — scoping, gap assessment, remediation, then the ROC — usually takes 4 to 9 months for a first certification. The ROC is valid for one year, and the cycle repeats. See the timeline.
How much does PCI DSS certification cost?
Planning estimates (September 2026): a Level 1 ROC assessment typically runs $30,000 to $100,000+ in QSA fees depending on scope, with first-year all-in costs of $75,000 to $250,000+ once readiness, pen testing, remediation, and staff time are included. Guided SAQ engagements run $5,000–25,000. See our cost guide and the 2026 pricing report for every figure with its source.
Who can certify us for PCI DSS?
Only a Qualified Security Assessor (QSA) — an individual employed by an accredited QSA company and qualified by the PCI Security Standards Council — can perform an on-site assessment and sign a ROC. Compliance platforms can prepare you, but they cannot sign the report. Verify any firm on the PCI SSC's assessor listings before engaging.
Get quotes from accredited QSA companies
Tell us about your environment and timeline once. We’ll match you with QSA companies that fit — no obligation, no spam.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.