PCI DSS Compliance Cost for Small Businesses
PCI DSS compliance cost for small businesses runs from about $300 a year to $20,000 or more. What moves you across that range isn't headcount or revenue. It's scope, meaning how card data touches your systems and which Self-Assessment Questionnaire you qualify for. One eligibility change published in January 2025 can push an e-commerce merchant from 19 controls to 128 without a dollar of revenue changing.
Table of Contents
Small businesses typically spend $300 to $20,000 a year on PCI DSS compliance. The range is that wide because cost follows scope, not company size. Your SAQ type sets the bill, not your revenue.
Your CFO wants one number. There isn't one. Ask five vendors what PCI compliance costs and you'll get five ranges, most of them priced off the cheapest possible version of your business. Search the question and the same $300-to-$70,000 spread comes back on a dozen pages, sourced to nobody. The spread is real. It's also useless, because it tells you what the category costs instead of what you cost. Not the same question.
Your merchant level only decides how you validate. It does not decide what you spend. Scope decides that, and scope is one of the few things on this list you actually control. Get the scope question right and PCI DSS compliance services stay a line item. Get it wrong and they become a project.
What does PCI compliance actually cost a small business?
Small businesses spend roughly $300 to $20,000 a year. Merchants who fully outsource checkout land near the bottom. Merchants who touch card data directly land near the top, and the jump between them is not gradual.
It's a cliff. The Self-Assessment Questionnaire you qualify for determines how many controls you have to satisfy, and the control counts don't rise in a smooth line. They step. SAQ A sits around 19 controls. SAQ D sits above 250. Nothing about your revenue moves you between those two numbers, and nothing about your headcount does either, which is why a 30-person retailer and a 300-person distributor can file the same questionnaire while a competitor half their size files one six times longer.
Here's where a small merchant actually lands. Organized by the only variable that matters.

Those bottom two rows carry a caveat worth stating plainly. The $300 and $3,200 figures come from published vendor pricing at SecurityMetrics and Thoropass, and the SAQ D figure comes from Thoropass modeling a mid-market merchant at roughly $127,700 in year one. The card-present band is component math, not a single published source, because nobody publishes one. Add your scanning, your terminal remediation, and your segmentation work and you land in that range.
Why the number you found online won't match your quote
Three problems with the published figures. They pull in different directions.
The most-cited authority number in this category is a Gartner estimate putting Level 1 merchant compliance at $2.7 million and Level 2 at $267,000. It appears on at least eight vendor pages. None of them date it. We went looking for the underlying study across a full page of current search results and could not find it, which means the figure anchoring enterprise PCI cost across the category has no verifiable publication attached. Treat it as folklore. Someone should produce the report.
The $300 floor has the opposite problem. It's honest. SecurityMetrics builds it from a $50 to $200 questionnaire, $100 to $200 per IP address in scanning, and roughly $70 per employee in training, and every one of those numbers is defensible on its own. What the total quietly leaves out is the person at your company who has to sit down and do it.
And vendor cost pages have a structural reason to quote low, which is that the page exists to move somebody toward a product, and the version of you that fits inside the product's happy path is always cheaper than the version of you that walks in with 14 public IP addresses, a legacy payment portal, and a shared mailbox full of PDFs. The cheapest version of you is the version that converts.
The seven things you're actually paying for
Seven line items make up almost every PCI budget. The self-assessment or audit, quarterly external scans, penetration testing, remediation, tooling, training, and internal staff time. Remediation is usually the largest and the least predictable.

Remediation deserves a note. Thoropass puts it at 40 to 60% of a total compliance budget, which makes it larger than the assessment, the scanning, and the tooling combined. You can't price it from a template, because it's a function of what your environment already does correctly, and nobody in the room knows that answer yet. That's the entire argument for running a gap assessment before you accept a program quote. A quote written without one is a guess wearing a number.
The one change that can multiply your PCI bill
In January 2025 the PCI Security Standards Council published a new version of SAQ A, and it replaced the old one on March 31, 2025. On the surface it looked like relief for small e-commerce merchants. The Council removed requirements 6.4.3 and 11.6.1, the two client-side script controls that had been giving everyone trouble, along with 12.3.1.
Then it added an eligibility criterion. To use SAQ A at all, the merchant has to confirm their site isn't susceptible to attacks from scripts that could affect their e-commerce systems.
Read that twice. The controls didn't disappear. They moved out of the list of things you have to do and into the list of things you have to be true before you're allowed to use the short form. Chris Camejo at TrustedSec laid this out in February 2025. SAQ A drops from 21 controls to 19. Miss the eligibility criterion and you're filling out SAQ A-EP instead, which carries 128 requirements for the e-commerce environment plus another 8 for paper record handling.
Nineteen to 128. Same business, same revenue, same transaction count, same merchant level.
Two details keep this from applying to everyone. The Council's FAQ 1588 confirms the new criterion targets merchant pages that host an embedded payment page or form, meaning an iframe. Full redirects and plain links to a payment page aren't affected. So if your customer leaves your domain entirely to pay, this section costs you nothing. If your checkout renders inside your own page, it's the most expensive sentence in your compliance program. One rendering choice.
Worth noting that the published control counts disagree. TrustedSec says 19. HUMAN Security says 27 for SAQ A and 151 for A-EP. Other published breakdowns land on 24. The counts vary depending on how sub-requirements are tallied and which document revision is being read, and the disagreement doesn't change the shape of the problem. Every source describes roughly a six-fold jump. Budget the shape. The decimal can wait. If you want the underlying control set, we walked through the 12 requirements and the 51 controls behind them separately.
What it costs to hold your SAQ A eligibility
So how do you stay on the short form? TrustedSec documents four ways to satisfy the criterion. They are not equally priced.
- Implement 6.4.3 and 11.6.1 anyway, as if the change never happened. Script inventory, written authorization for every script, tamper detection, and payment page monitoring. Script-monitoring vendors put the tooling at 15 to 25% of total PCI spend. Consider the source. And the free tiers stop being free the moment you have real traffic.
- Get written attestation from your processor that their iframe resists script attacks. Free, if they'll give it to you. Many won't.
- A web application penetration test that shows the page holds up. Call it $8,500.
- Deploy a WAF, a web application firewall that filters traffic before it reaches your payment page. Cheapest on paper. Somebody still has to tune it, and an untuned WAF is a line item, not a control.
Notice what none of those four depend on. Your size.
The line nobody invoices you for
Two vendors, same merchant profile, same questionnaire. Thoropass budgets roughly 20 hours of internal staff time and prices it at about $2,000. Paytia budgets 80 to 300 hours for the SAQ alone.
That's a 15-fold disagreement on the largest soft cost in the project, published by two companies that both sell into it. Neither is lying.
So which one is right? Both, on different years. Twenty hours is what the questionnaire takes when every answer is already true and the evidence already exists. The 80-to-300 range is what it takes when the questionnaire surfaces a list of small gaps nobody knew were there, and someone has to chase each one down, fix it, document it, and produce a screenshot proving it. Year one is almost always the second number. Year three, if somebody actually owns the program, drifts back toward the first. Budget for the second and you'll be right more often than you're wrong.
Check your merchant statement before you budget anything
Pull last month's merchant statement. Look for a line item called PCI non-compliance fee.
Processors add it when you haven't filed your annual questionnaire, and it runs $19.95 to $99.95 a month depending on who processes your cards. It bills until you validate. At the low end that's $240 a year. At the high end, $1,199.
Which means a fair number of merchants are paying more each year to avoid the questionnaire than the questionnaire costs. SecurityMetrics prices the SAQ itself at $50 to $200. So the fee is often four to six times the price of the thing it exists to penalize you for skipping, it renews silently every month, and almost nobody on the finance side has ever been told to look for it. Check the statement.
What non-compliance actually costs
Fines run $5,000 to $100,000 a month. The PCI Security Standards Council doesn't set them and doesn't collect them. Card brands fine your acquiring bank, and your acquirer contract passes the cost down to you.
That distinction matters. More than it sounds. There is no published PCI fine schedule you can look up anywhere, because the amount isn't set by the standard at all, it's contract territory between you and the bank that gave you a merchant account. Secureframe and Thoropass both describe the same enforcement chain. The brands do publish ceilings of their own, and those ceilings escalate with repeat violations rather than staying flat, but the number that actually lands on your account is the one your acquirer agreed to in a contract somebody at your company signed years ago and probably never read again.
Real exposure lives in the merchant agreement. All of it. Read that before you decide the risk is theoretical.
Four ways to cut the bill that actually work
Which of these actually moves the number down? Four things, and only one of them is a purchase.
- Redirect instead of embed. The change that moves the most money for an e-commerce merchant in 2026, and it's a conversation with whoever maintains your site rather than a purchase.
- Count your public IP addresses and domains, then cut the ones that don't need to be there. ASV scanning is priced per IP, from about $80 a year at the low end of the market. Ten stale subdomains is a real number on a real invoice, and quarterly scanning of everything in scope is not optional.
- Put card-present terminals on their own network segment. Segmentation is the difference between the terminals being in scope and the entire office being in scope.
- Stop storing card numbers. Not the CRM notes field. Not the recorded sales call. Not the emailed PDF that has been sitting in a shared mailbox since 2021 because somebody needed it once and nobody ever went back to delete it. Every one of those pulls a system into scope that has no business being there.
Three budgets, three businesses
Modeled from the published component costs above, not from client invoices. Use them to place yourself, then get real quotes.

Stare at the middle column. That business is smaller than a Level 1 merchant by every measure a card brand tracks, and it's carrying a bill five to ten times the retailer's because of a rendering decision made by a web developer who was never told it counted as a compliance decision. Nobody told him. That's the whole story.
When you should stop spending on this
Some of you are finished and don't know it.
Full redirect to your processor's hosted page. No card data stored anywhere, and that includes the CRM notes field and the recorded calls. Written attestation from your processor on file. Annual SAQ A filed and quarterly scans running. If that's an accurate description of your environment, then your PCI cost is a few hundred dollars and one afternoon a year, you do not need a compliance platform, you do not need a QSA, and you do not need the remediation program somebody quoted you last quarter.
Buying one anyway is common. It tends to follow a sales conversation rather than a scoping conversation, and the difference between those two conversations is the difference between a few hundred dollars a year and a program you'll be renewing for the rest of the decade.
Price the scope before you price the program
Boil it down to two things.
Merchant level tells you how to validate. Scope tells you what it costs. Those are separate questions and only one of them shows up on the invoice, which is why so many PCI budgets are built backward. Every PCI compliance cost estimate you'll be handed is really an estimate of your scope, whether the person handing it to you says so or not.
And the largest cost lever available to an e-commerce merchant right now isn't a vendor you pick or a platform you license. It's whether your payment page uses a redirect or an embedded form, and that's a 20-minute conversation with whoever built your site.
Consilien is a nationwide IT and cybersecurity firm working with companies of 20 to 500 users across manufacturing, distribution, professional services, and real estate. Compliance is a standalone offering here, deliberately kept out of the managed IT contract, which means the scoping work happens before anyone quotes you a number. If you're building a PCI budget and you aren't certain which questionnaire you qualify for, settle that first. Speak to a compliance expert.