ZenGRC

How Much Does a PCI Audit Cost?

A PCI audit typically costs between $15,000 and $40,000 depending on business size and type, with Level 1 merchants paying more for on-site Qualified Security Assessor audits and additional expenses such as vulnerability scans, penetration testing, training, remediation, and potential processor fees potentially raising total compliance costs above $50,000 annually, while smaller businesses may spend as little as $300 per year on self-assessment questionnaires, vulnerability scans, and training.

An audit to determine your organization’s compliance with the Payment Card Industry Data Security Standard (PCI DSS) can cost $15,000 to $40,000, depending on factors such as business type, company size, security culture, and card processing methods.

The higher cost is typically what Level 1 merchants pay for a Qualified Security Assessor (QSA) to perform an on-site audit and complete a Report on Compliance (ROC) attesting that your organization is PCI compliant. Additional costs, such as quarterly vulnerability scans, penetration testing, employee security training, policy development, and more, can push compliance costs above $50,000 per year.

If you have dedicated PCI staff, their salaries will also factor into the total cost. If the auditor finds compliance gaps or vulnerabilities, remediation costs should be expected.

An on-site PCI audit is required only for Level 1 merchants and service providers, but many Level 2 and 3 entities choose to comply at this level. Smaller entities can expect to pay around $15,000 for the audit and report.

Organizations submitting an Attestation of Compliance and self-assessment questionnaire (SAQ) can save on third-party audit expenses but may still need to pay someone to complete the forms.

Other costs include quarterly vulnerability scans of your network environment, security training, and remediation. Estimates range from $60 per month for small businesses to $50,000 for those with multiple IP addresses.

Credit card processors may charge a PCI compliance fee of $70 to $120 per year. While you may wonder how to avoid this fee, it may be worthwhile if your processor provides PCI DSS compliance support such as vulnerability scanning and assistance with the self-assessment questionnaire.

If you’re a small business, PCI DSS compliance could cost at least $300 per year, depending on your environment:

  • Self-Assessment Questionnaire: $50 – $200
  • Vulnerability scanning: $100 – $200 per IP address
  • Training and policy development: $70 per employee
  • Remediation (software and hardware updates, etc.): Varies greatly, but estimated at $100 – $10,000

For very large enterprises needing a PCI DSS assessment, expect to pay $70,000+ in total costs (depending on your environment):

  • Onsite audit: ~$40,000
  • Vulnerability scans: ~$1,000
  • Penetration testing: ~$15,000
  • Training and policy development: ~$5,000
  • Remediation (software and hardware updates, etc.): Estimated at ~$10,000–$500,000

Level-by-level PCI compliance costs

Level 1

Merchants with more than 6 million transactions a year or any merchant that has had a data breach.

  • PCI environment hardware, software, and security
  • Self-assessment
  • On-site third-party audit by qualified security assessor (QSA) plus remediation costs
  • Quarterly ASV-performed vulnerability scan
  • Penetration testing
  • Data security, classification, and encryption
  • Training

Total cost: Minimum $50,000 per year

Level 2

Merchants with between 1 million and 6 million transactions annually.

  • Quarterly Approved-Scanning-Vendor-performed vulnerability scans
  • Annual Self-assessment Questionnaire
    • Remediation
  • Penetration testing
  • Training

Total cost: Minimum $10,000 per year

Level 3

Merchants with between 20,000 and 1 million transactions annually.

  • Quarterly Network Vulnerability Scans performed by an Approved Scanning Vendor (ASV)
  • Yearly Self-Assessment Questionnaire
    • Remediation
  • Training

Total cost: Minimum $1,200 per year

Level 4

Merchants with fewer than 20,000 online transactions a year or any merchant processing up to 1 million regular transactions per year.

  • Quarterly Network Vulnerability Scans performed by an Approved Scanning Vendor (ASV)
  • Yearly Self-Assessment Questionnaire
    • Remediation
  • Training

Total cost: Minimum $60 to $75 per month

The high(er) costs of non-compliance

PCI DSS is not a law or regulation but an industry mandate. If your enterprise accepts credit card payments or handles payment card data, it must comply with PCI DSS.

PCI DSS is an information security framework intended to help merchants and service providers protect credit and debit card transactions from data breaches. Being out of compliance can have severe consequences.

PCI DSS’s origins date to 1999, when Visa developed a Cardholder Information Security Program in response to increases in credit card fraud via the Internet. Other major credit-card brands—Mastercard, Discover, American Express, and JCB—followed with their own security programs. In 2004, these five jointly launched PCI DSS 1.0. In 2006, the card brands added financial institutions, merchants, processor companies, software developers, point-of-sale vendors, and others to their security initiative, forming the PCI Security Standards Council (PCI SSC).

The consequences of ignoring or failing PCI DSS compliance include fines of up to $100,000 per month. When banks are notified of non-compliance, it’s usually because cardholder data has been breached. In that case, you could be responsible for:

  • A PCI DSS forensic investigation
  • Lawsuit and other legal fees
  • Remediation
  • High rates to banks and processors
  • Federal Trade Commission audits
  • Cardholder notifications
  • Compensation costs to affected customers (credit monitoring, identity theft insurance, new cards)

You could also lose your credit card privileges, which can be crippling to a business.

A breach that compromises credit card data moves your enterprise, regardless of size, to PCI Compliance Level 1. This most stringent PCI DSS compliance level requires expensive on-site audits every year, network vulnerability scans every 90 days, and, for service providers, penetration tests and internal scans.