Most PCI DSS purchases go wrong in the first week, before anyone opens a pricing page. A deadline arrives from an acquiring bank or a payment processor, somebody searches for PCI compliance software, and a platform gets bought. Nine months later the company still is not validated, because software was never the thing that validates you.
Teams that get this right treat it as two separate purchases plus one engineering decision. The two purchases are compliance tooling and assessment services. The engineering decision, how much cardholder data your systems touch at all, is worth more than both purchases combined.
This guide is for the person who has to run that evaluation and then defend the invoice. Security lead at a 90-person ecommerce company. The engineering manager at a fintech whose processor just asked for an Attestation of Compliance. You get the scorecard, the full cost stack, and the questions that make vendors squirm.
Fill in the downloadable scorecard as you read.
The scope question that sets your entire budget
Answer two questions in writing before a single vendor call. Which level are you under the card brands, and which validation document do you owe. Every number in your budget follows from those two answers, and no software product changes either one.
Levels are set by the payment brands, not by the PCI Security Standards Council. Visa’s published validation table puts merchants above 6 million Visa transactions a year at Level 1, which means an annual Report on Compliance signed off by a Qualified Security Assessor plus quarterly scans by an Approved Scanning Vendor.
Below that, validation runs on a Self-Assessment Questionnaire. Level 2 covers 1 million to 6 million transactions, Level 3 covers 20,000 to 1 million ecommerce transactions, and Level 4 is everyone smaller, with requirements your acquirer sets.
| Level (Visa volumes) | Validation document | Recurring scan duty |
|---|---|---|
| Level 1, over 6M transactions/yr | Annual ROC by a QSA (or an internal auditor with officer sign-off) plus AOC | Quarterly ASV scans |
| Level 2, 1M to 6M/yr | Annual SAQ plus AOC | Quarterly ASV scans |
| Level 3, 20,000 to 1M ecommerce/yr | Annual SAQ plus AOC | Quarterly ASV scans |
| Level 4, under 20,000 ecommerce/yr | Annual SAQ, set by your acquirer | Scan duty set by your acquirer |
The second answer is the SAQ type, and that is where real money moves. SAQ A is for ecommerce merchants who have fully outsourced card handling to a compliant third party. SAQ A-EP is for merchants whose own site controls how the payment happens without touching card data. SAQ D covers everything else, meaning every applicable PCI DSS requirement.
The distance between those documents is not marginal. The Council’s v4.0 SAQ A runs 40 pages; SAQ D for merchants runs 118. A tool that helps you complete SAQ D faster is worth a fraction of an architecture change that moves you to SAQ A.
So put the scope decision first on the calendar and the software decision second. Buyers who do it the other way around pay for a platform to manage a cardholder data environment they did not need to have.
Four product categories vendors blur together
Search results for this category mix four different products, sold by four different kinds of company, at four different price points. Sorting them is most of the work.
Compliance automation platforms map PCI DSS controls to evidence and monitor drift. Vanta, Drata, Sprinto, Secureframe, Scytale, Strike Graph and OneTrust live here. They are useful for the technical requirements that map cleanly to cloud configuration, and they do not scan, assess, or sign anything.
ASV scanning vendors run the external vulnerability scans PCI DSS requires. Only companies on the Council’s Approved Scanning Vendor list can produce a scan report that counts, which includes SecurityMetrics, Qualys and Trustwave.
QSA firms perform the assessment itself and sign the ROC. Check any claimed assessor against the Council’s Qualified Security Assessor list before you believe a marketing page. A-LIGN and Thoropass sit in this lane, and Thoropass is unusual in bundling software with an in-house assessor.
Tokenization and vault providers, VGS, Basis Theory, Skyflow, take card data out of your systems so the assessment has less to look at. They are the only category on this list that changes your scope rather than documenting it.
None of the four makes you compliant. Validation is a signed SAQ with an Attestation of Compliance, or a QSA-signed Report on Compliance, filed with your acquirer or the brands. Our roundup of 20 PCI DSS compliance tools splits vendors by these categories for exactly this reason.
The weighted scorecard, locked before the demos
Set your criteria and weights before you watch a demo, and get them signed off by whoever owns the payment stack. A weight you assign after a demo is not a weight, it is a rationalisation of what you already liked.
Score each vendor 1 to 5 per criterion, force a written note on every 1 and every 5, and multiply through. The weights below sit heaviest on scope and validation completeness because those two decide whether the program closes at all. See our methodology for how we build and test these frameworks.
| Criterion | Weight | What to score, and the evidence to demand |
|---|---|---|
| Scope-reduction effect | 18 | Which SAQ type you qualify for after implementation, in writing from the vendor and confirmed by your assessor. No answer means no points. |
| PCI DSS v4.x control and evidence coverage | 18 | A per-requirement mapping against YOUR SAQ type or ROC, including the requirements that went mandatory on 31 March 2025. Not a framework logo. |
| Validation path completeness | 15 | What the vendor actually produces: ASV scan report, SAQ support, ROC, AOC, or none of them. Name the deliverable and who signs it. |
| Three-year program cost | 14 | License plus scanning plus assessment plus testing plus remediation, years one to three, with the renewal uplift capped in the contract. |
| Evidence automation against your stack | 12 | Percentage of your in-scope controls with automated, timestamped evidence. Demand a per-control breakdown on your own infrastructure. |
| Assessor and acquirer acceptance | 11 | Ask your QSA to review the platform’s evidence export before you sign. Ask the vendor for its own current AOC as a service provider. |
| Recurring-obligation handling | 8 | Quarterly ASV rescans, annual segmentation testing, annual scope confirmation, log reviews. Score how much of the calendar the tool actually owns. |
| Vendor security posture and viability | 4 | Their own assessment reports, subprocessor list, breach history, and whether they will still be here at renewal three. |
Get the PCI DSS Compliance Evaluation Toolkit
The weighted vendor scorecard (Excel, auto-scores your shortlist and ranks the winner) plus the 1-page checklist of questions to ask every vendor and the red flags to walk away from. Free.
The three-year cost of a PCI program, not a license
The platform subscription is usually the smallest line on a PCI program budget and the only one vendors quote you unprompted. Build the whole stack before you take a number upstairs.
| Cost line | What drives it | Anchor (verified July 2026) |
|---|---|---|
| Compliance platform license | Headcount band, framework count | Strike Graph publishes $10,000/yr for Certify; PCI DSS is a Tier 2 framework at $5,000/yr on that plan. Most rivals are quote-only. |
| ASV scanning | External IP count, rescan volume | SecurityMetrics publishes $399/yr for a one-IP external scan bundled with an online SAQ portal. |
| Validation (SAQ support or QSA-led ROC) | SAQ vs ROC, number of sites, CDE complexity | Quote-only. No major QSA firm publishes list pricing, so get a fixed-fee written proposal, not a day rate. |
| Penetration and segmentation testing | Scope size, and whether you are a service provider | Quote-only, and recurring. Budget every 12 months as a merchant, every 6 as a service provider. |
| Tokenization or vaulting | Token volume, payment channels | Basis Theory publishes $995/mo for Starter, which includes a PCI Attestation of Compliance for the vault. |
| Remediation and control build | MFA rollout, log centralisation, payment-page script monitoring | Your own engineering cost. This is where the v4.x requirements land. |
| Internal program hours | Quarterly rescans, evidence, annual scope confirmation | Your loaded hourly cost. Assume it does not go to zero after year one. |
Two lines get underestimated every time. Remediation is one, because tooling shows you the gap and then hands the gap back to engineering. Recurring testing is the other, since segmentation and penetration testing are annual obligations, not launch costs.
Ask for the year-three number in writing during the first negotiation, with an uplift cap. Compliance platform renewals in this category routinely reset the discount that closed the original deal. After signature you have nothing to push back with.
One more line item nobody prices: what happens if you fail. Fines and enforcement do not come from the Council. PCI SSC states in its own FAQs that compliance is enforced by the founding payment brands and that it has no information about penalties or fines.
So the only accurate answer to “what is the fine” lives with your acquirer. Get that number from your bank, not from a vendor deck.
Scope reduction as the cheapest control you will buy
Every dollar you spend keeping card data out of your systems buys more than a dollar spent documenting card data inside them. The Council’s own scoping and segmentation guidance sets out the test for whether a system is out of scope, and the practical levers are short: outsource the payment page, tokenize at capture, and segment what is left.
Tokenization is the strongest of the three for anything digital. Card data goes straight to a vault, your application holds tokens, and a breach of your infrastructure exposes tokens rather than usable card numbers. Read the vault vendor’s AOC carefully though, because it covers their environment, not yours.
Redirects and hosted iframes are the classic route to SAQ A eligibility for ecommerce. This is also where teams get lazy: outsourcing the payment form does not outsource the page it sits on.
The Council tightened exactly that point in January 2025. Requirements 6.4.3, 11.6.1 and the supporting 12.3.1 risk analysis were removed from SAQ A, and in their place merchants must confirm their site is not susceptible to script attacks that could affect their ecommerce systems. Simpler paperwork, harder engineering claim.
SAQ A also carries Requirement 11.3.2 now, which means quarterly ASV scans of the system hosting the redirect or the embedded form. “We use a hosted payment page, so we have nothing to do” stopped being true.
Segmentation is the third lever, and it has to be proven, not drawn. Segmentation controls get penetration tested at least every 12 months for most entities under Requirement 11.4.5, and every six months for service providers under 11.4.6, as Schellman’s assessor FAQ lays out. A network diagram is not evidence.
Then confirm the scope itself on a schedule. Requirement 12.5.2 makes scope confirmation an annual exercise, so the out-of-scope claim you made this year has to be re-earned next year.
The v4.x requirements that broke the old evidence model
PCI DSS v4.0 was retired at the end of December 2024, and v4.0.1 is the active version as of July 2026. The Council opened a request for comments on 3 June 2026 to start shaping the next iteration, so movement is coming, but there is nothing to wait for.
The date that matters for your evaluation is 31 March 2025. Of the 64 new requirements in v4.x, 51 were future-dated and became mandatory then. Any platform demo built around the old v3.2.1 control set is out of date, and some still are.
Score vendors on the requirements that changed rather than the total count of controls they claim to cover. Multi-factor authentication for all access into the cardholder data environment (8.4.2). Twelve-character minimum passwords where passwords are the authentication factor (8.3.6).
Automated mechanisms for audit log review (10.4.1.1). Automated anti-phishing controls for personnel (5.4.1). Those four alone reshape what your evidence pipeline has to produce.
For ecommerce specifically, payment page script management (6.4.3) and tamper detection on payment pages (11.6.1) are the two that most compliance platforms cover thinly or not at all. They tend to need a client-side security product, which is a separate purchase nobody budgets for.
Bring your own list of these to every demo and ask the vendor to produce sample evidence for three of them, against your stack, live. The gap between the framework badge and the actual evidence artifact is where this category oversells.
The QSA and ASV decision, kept separate from the software
Compliance automation and assessment are different purchases with different failure modes. Buying them from one vendor is a legitimate choice, and it costs you assessor independence.
Bundled models like Thoropass shorten the process by putting the assessor inside the contract. That works well for a first assessment and less well if you have an existing QSA relationship, an unusual card-data flow, or a board that wants visible separation between the party building controls and the party testing them.
The Council draws that line explicitly for customized approach work: a QSA employee involved in designing or implementing a customized control cannot then derive testing procedures for it or assess it, per its roles and responsibilities guidance . Apply the same logic to your whole engagement even where the rules do not force it.
The customized approach itself has a consequence buyers miss. If you plan to meet a requirement with a control that is not the defined one, you cannot self-assess it: the Council’s SAQ D states that “SAQs cannot be used to document use of the Customized Approach,” which pushes you to a full ROC with a QSA. That is a five-figure decision made by an architecture choice.
On scanning, verify the ASV listing yourself. And know what passing means: under the Council’s ASV Program Guide, a single vulnerability with a CVSS base score of 4.0 or higher fails the whole scan, and the Council’s FAQ on quarterly scans expects passing scans across the previous four quarters, not one clean run before the audit.
The security and procurement gate
This part is pass or fail. A vendor that touches cardholder data or the systems around it is a third-party service provider in your assessment, which makes their paperwork your problem.
Ask for their current Attestation of Compliance covering the specific services you are buying, not a trust-center badge. Then ask for the written responsibility matrix showing which PCI DSS requirements they manage and which stay with you, because Requirements 12.8.5 and 12.9.2 put that documentation squarely in scope for both sides.
For registered service providers, check the Visa Global Registry of Service Providers rather than taking the sales team’s word for the listing. A provider that cannot be found in a brand registry and cannot produce an AOC is a finding waiting to happen.
Then the ordinary software gates: SOC 2 Type II with its scope, ISO 27001 where relevant, a signed DPA, a named data residency region, encryption and key custody details, breach notification window, subprocessor list.
Confirm in writing that SSO and audit logs sit in the tier you are actually buying. Gating them to an Enterprise plan changes your price after you have already fallen for the product.
The buying committee for a payments purchase
PCI purchases have one extra stakeholder that CRM purchases do not: the acquiring bank. Map the room before you need signatures.
Your CFO wants the three-year total and the payback on avoided assessment labour, not a control count. Your security lead owns the evidence quality and the assessor relationship. Engineering owns the remediation work, which is the biggest hidden line, so bring them in before you promise a timeline.
Legal and procurement care about the DPA, liability for a breach, and the responsibility matrix. Whoever owns the acquirer relationship, usually finance or payments ops, cares about what gets filed and when. Pre-write each person’s top objection and the one artifact that answers it.
Running the trial like an assessment
A demo is the vendor’s environment on its best day. Run your trial as a rehearsal for fieldwork instead.
Connect the platform to your real infrastructure, not a sandbox, and pull evidence for five specific requirements you know are messy. Take that evidence export to the QSA you plan to use and ask, straight out, whether they would accept it as-is. That single conversation predicts more of your audit experience than any feature comparison.
Run one real ASV scan against your actual external footprint and read the failure list. Then time the remediation loop, because the quarterly cycle is what you will live inside, not the dashboard.
Red flags that should end an evaluation
Some findings are exits, not point deductions. A vendor that says its software makes you “PCI compliant” or “PCI certified” is either careless or hoping you are. A vendor that will not share its own current AOC or a written responsibility matrix. An assessor or scanning vendor you cannot find on the Council’s QSA or ASV list.
A bundled audit with no named assessor and no named deliverable. A refusal to state which SAQ type you will qualify for after implementation. Scope-based pricing with no written definition of scope, and a renewal uplift they will not cap. Any one of these tells you how the relationship goes once the invoice is paid.
Questions buyers ask before they sign
Does PCI DSS compliance software make you PCI compliant?
No. Compliance automation platforms map controls and collect evidence. Validation happens through a Self-Assessment Questionnaire with a signed Attestation of Compliance, or a Report on Compliance signed by a Qualified Security Assessor, filed with your acquirer or the payment brands.
Treat any vendor claim of making you compliant or certified as a reason to scrutinise everything else they told you.
Which SAQ type should we be aiming for?
Aim for the shortest one your architecture can honestly support, then design toward it. SAQ A applies to ecommerce merchants who have fully outsourced card handling to a compliant third party, SAQ A-EP where your site controls the payment mechanism without touching card data, and SAQ D where card data lands in your environment.
Since January 2025, SAQ A also requires quarterly ASV scans under Requirement 11.3.2 and an eligibility confirmation that your site is not susceptible to script attacks, so the shortest questionnaire is no longer a zero-work option.
How much does PCI DSS compliance cost in total?
Model six lines: platform license, ASV scanning, validation (SAQ support or a QSA-led ROC), penetration and segmentation testing, remediation engineering, and internal program hours. Published anchors exist at the small end, with SecurityMetrics listing $399/yr for a one-IP scan plus SAQ portal and Strike Graph listing $10,000/yr for its Certify plan as of July 2026.
QSA assessment fees are quote-only across the market, so insist on a fixed-fee written proposal rather than a day rate, and get the year-three renewal number capped in the first contract.
What is the difference between a QSA and an ASV?
A Qualified Security Assessor is a company qualified by the PCI Security Standards Council to perform assessments and sign a Report on Compliance. An Approved Scanning Vendor is qualified to run the external vulnerability scans required at least once every three months.
They are separate qualifications and separate purchases. Some firms hold both, which is convenient, and you should still verify each listing on the Council’s own assessor lists rather than a vendor page.
Which PCI DSS version applies in 2026?
PCI DSS v4.0.1, which has been the active version since v4.0 was retired at the end of December 2024. The 51 future-dated requirements introduced in v4.x became mandatory on 31 March 2025, so any vendor demo or template still built around v3.2.1 is stale.
The Council opened a request for comments in June 2026 to begin the next iteration, but that changes nothing about what you owe your acquirer this year.
Can tokenization take us out of PCI DSS scope entirely?
It reduces scope, it does not remove the obligation. Tokenizing at capture keeps raw card numbers out of your systems, which can move an ecommerce merchant from SAQ D toward SAQ A, and you still validate whatever environment remains.
Read the vault vendor’s Attestation of Compliance for what it actually covers, which is their platform, and confirm the resulting scope with your assessor before you tell a CFO you saved the cost of a full assessment.
How long does a PCI DSS software evaluation take?
Plan six to ten weeks for a mid-market buyer, and note that the sequence matters more than the duration. Spend the first two weeks on scope and SAQ type with your assessor, two on scoring platforms against a locked scorecard, two on a hands-on trial that produces real evidence, and the rest on the security gate and negotiation.
If a deadline from your acquirer compresses that, cut the vendor shortlist rather than the scope work. Getting scope wrong is the expensive mistake, and it is the hardest one to undo later.