How PCI DSS certification works
Every PCI DSS certification — whether it ends in a ROC signed by a QSA or a SAQ you sign yourself — follows the same five phases. This is the full journey, with realistic durations, who does what, and where the money goes.
First: which path are you on?
Your merchant or service-provider level decides. Level 1 (6M+ transactions/year for most card brands; 300K+ for service providers) means an on-site QSA assessment producing a Report on Compliance (ROC). Everyone else typically completes a Self-Assessment Questionnaire (SAQ). Your acquirer confirms — and can require more than the minimum. See ROC vs SAQ and merchant levels.
Phase 1: Scoping
What happens: you (ideally with a QSA) map exactly where cardholder data lives, moves, and is processed — systems, networks, people, and service providers. Everything in the cardholder data environment (CDE) is in scope for testing; everything else isn't.
Duration: 1–3 weeks. Who: your team, ideally with QSA guidance.
Phase 2: Gap assessment
What happens: your current controls are measured against PCI DSS v4.0.1 (the current standard; v3.2.1 was retired March 31, 2025) before the formal assessment begins. This is a rehearsal, not the exam — findings here don't go on any record.
Duration: 2–4 weeks. Who: a QSA company (often — not always — the same firm that will do the ROC), an ISA, or a strong internal team.
Cost: often bundled with the assessment or priced as a short engagement ($5K–$20K planning estimate). Skipping it to save money is how companies pay for findings during fieldwork instead — at higher rates and under deadline pressure.
Phase 3: Remediation
What happens: you close the gaps the assessment found — fix configurations, write the missing policies, build the logging you never had, segment the network, deploy MFA where v4.0.1 requires it.
Duration: 4–12 weeks for first-timers; often the longest phase. Who: your engineering and security teams.
Phase 4: QSA fieldwork
What happens: the QSA tests your controls using three procedures — examine (documentation and configurations), interview (the people who operate the controls), and test (observe the control working). Evidence is sampled across systems, and every requirement gets a verdict: in place, not in place, or not applicable.
Duration: 2–12 weeks depending on scope. Who: the QSA's assessment team, with your team providing evidence and access.
Findings (“not in place”) send you back to remediation for those items, then re-testing. See what QSAs actually test and what happens if you don't pass.
Phase 5: Report & attest
What happens: the QSA compiles the Report on Compliance, you review it for factual accuracy, the QSA signs it, and the Attestation of Compliance (AoC) goes to your acquirer — and to the customers and partners who ask for it.
Duration: 2–4 weeks for report writing and review. The ROC is valid for one year from the assessment date.
Your AoC is now a sales asset: put it in your trust center, attach it to security questionnaires, and never let it expire mid-deal. See sharing your AoC.
After certification: the annual cycle
Certification isn't a project, it's a cycle. Renewals re-test everything but skip the discovery: scoping becomes a delta review, evidence reuses last year's package, and planning estimates typically run 40–70% of the first-year fee once the program matures. Engage the QSA 3–4 months before expiry — late bookers wait, and lapsed attestations kill deals. Full playbook: ROC validity and renewals.
Start with scoped quotes
Tell us your environment once — matched QSA companies send competing quotes for your certification. Free, two minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.