PCI DSS assessments must be performed by a Qualified Security Assessor (QSA) company approved by the PCI Security Standards Council. There are approximately 389 QSA companies globally. Choosing the right QSA affects the efficiency of your assessment, the quality of your Report on Compliance (ROC), and your ongoing relationship with your acquiring bank.
The world's largest PCI QSA company, having assessed more organizations for PCI compliance than any other firm. Now operating under the VikingCloud brand, they offer QSA services, managed security, and compliance technology platforms.
Major cybersecurity firm and PCI QSA company with extensive experience across all merchant levels and service provider types. Coalfire is known for complex, large-scale PCI assessments in retail, financial services, and payment processing.
One of the most affordable QSA companies, SecurityMetrics is popular with smaller merchants and service providers. They also serve as an Approved Scanning Vendor (ASV) and offer integrated compliance management tools.
PCI QSA company that excels at multi-framework assessments. Schellman can combine PCI DSS with SOC 2, ISO 27001, and HITRUST assessments, which is valuable for service providers who need multiple compliance reports.
PCI QSA company offering assessments alongside SOC 2, ISO 27001, and HIPAA services. A-LIGN is popular with technology companies and payment service providers that need efficient multi-framework compliance.
Nashville-based QSA company known for competitive pricing and a technology-forward audit approach. They serve merchants and service providers across all PCI reporting levels.
UK-based QSA company with global operations, specializing in PCI DSS and payment security. Foregenix also provides payment forensic investigation services (PFI) for payment card data breaches.
US-based QSA and compliance firm with global delivery capabilities. ControlCase is known for their unified compliance approach, offering PCI DSS alongside dozens of other frameworks through a single integrated assessment.
$10,000 – $90,000
Depending on organization size, scope, and complexity. First-time assessments may include readiness and gap analysis fees.
2-4 weeks for scoping and gap assessment, 4-8 weeks for the on-site/remote assessment, and 2-4 weeks for ROC/AOC issuance. Total time from kickoff to final report is typically 2-4 months.
Walk into your audit with policies already drafted and evidence organized. PoliWriter generates PCI DSS-specific policies customized to your infrastructure, saving weeks of preparation and reducing auditor billable hours.
A Qualified Security Assessor (QSA) is an individual certified by the PCI Security Standards Council to perform PCI DSS assessments. QSA companies employ these individuals. Level 1 merchants and service providers must have their PCI DSS assessment performed by a QSA.
A Self-Assessment Questionnaire (SAQ) is for smaller merchants who can self-assess their PCI compliance. A Report on Compliance (ROC) is a detailed assessment report completed by a QSA, required for Level 1 merchants and service providers.
PCI DSS assessments are required annually. Level 1 merchants need an annual QSA assessment, while smaller merchants typically complete annual SAQs. Quarterly ASV scans are also required for externally-facing systems.
PCI DSS v4.0 introduced a customized approach (in addition to the defined approach), new requirements for multi-factor authentication, expanded encryption requirements, and stronger e-commerce security controls. PCI DSS v3.2.1 was retired on March 31, 2024.
PCI DSS assessments range from $10,000 for smaller merchants to $90,000+ for Level 1 merchants or complex service providers. Cost depends on scope, number of locations, cardholder data environment complexity, and whether remediation support is included.
Yes. Scope reduction through network segmentation, tokenization, and point-to-point encryption (P2PE) can significantly reduce PCI DSS assessment costs and effort. A good QSA will help you identify scope reduction opportunities.
Yes. PCI DSS requires quarterly external vulnerability scans by an Approved Scanning Vendor (ASV), which is separate from the annual QSA assessment. Many QSA companies also hold ASV status and can provide both services.
Generate all the PCI DSS policies your auditor will ask for. Customized to your tech stack and practices. Hours, not months.
Get Started Free