PCI DSS Compliance Cost for Small Businesses

Last updated: 08/13/2026
Compliance

PCI DSS compliance cost for small businesses runs from about $300 a year to $20,000 or more. What moves you across that range isn't headcount or revenue. It's scope, meaning how card data touches your systems and which Self-Assessment Questionnaire you qualify for. One eligibility change published in January 2025 can push an e-commerce merchant from 19 controls to 128 without a dollar of revenue changing.

Small businesses typically spend $300 to $20,000 a year on PCI DSS compliance. The range is that wide because cost follows scope, not company size. Your SAQ type sets the bill, not your revenue.

Your CFO wants one number. There isn't one. Ask five vendors what PCI compliance costs and you'll get five ranges, most of them priced off the cheapest possible version of your business. Search the question and the same $300-to-$70,000 spread comes back on a dozen pages, sourced to nobody. The spread is real. It's also useless, because it tells you what the category costs instead of what you cost. Not the same question.

Your merchant level only decides how you validate. It does not decide what you spend. Scope decides that, and scope is one of the few things on this list you actually control. Get the scope question right and PCI DSS compliance services stay a line item. Get it wrong and they become a project.

What does PCI compliance actually cost a small business?

Small businesses spend roughly $300 to $20,000 a year. Merchants who fully outsource checkout land near the bottom. Merchants who touch card data directly land near the top, and the jump between them is not gradual.

It's a cliff. The Self-Assessment Questionnaire you qualify for determines how many controls you have to satisfy, and the control counts don't rise in a smooth line. They step. SAQ A sits around 19 controls. SAQ D sits above 250. Nothing about your revenue moves you between those two numbers, and nothing about your headcount does either, which is why a 30-person retailer and a 300-person distributor can file the same questionnaire while a competitor half their size files one six times longer.

Here's where a small merchant actually lands. Organized by the only variable that matters.

Table of PCI compliance annual cost ranges by SAQ type for small businesses

Those bottom two rows carry a caveat worth stating plainly. The $300 and $3,200 figures come from published vendor pricing at SecurityMetrics and Thoropass, and the SAQ D figure comes from Thoropass modeling a mid-market merchant at roughly $127,700 in year one. The card-present band is component math, not a single published source, because nobody publishes one. Add your scanning, your terminal remediation, and your segmentation work and you land in that range.

Why the number you found online won't match your quote

Three problems with the published figures. They pull in different directions.

The most-cited authority number in this category is a Gartner estimate putting Level 1 merchant compliance at $2.7 million and Level 2 at $267,000. It appears on at least eight vendor pages. None of them date it. We went looking for the underlying study across a full page of current search results and could not find it, which means the figure anchoring enterprise PCI cost across the category has no verifiable publication attached. Treat it as folklore. Someone should produce the report.

The $300 floor has the opposite problem. It's honest. SecurityMetrics builds it from a $50 to $200 questionnaire, $100 to $200 per IP address in scanning, and roughly $70 per employee in training, and every one of those numbers is defensible on its own. What the total quietly leaves out is the person at your company who has to sit down and do it.

And vendor cost pages have a structural reason to quote low, which is that the page exists to move somebody toward a product, and the version of you that fits inside the product's happy path is always cheaper than the version of you that walks in with 14 public IP addresses, a legacy payment portal, and a shared mailbox full of PDFs. The cheapest version of you is the version that converts.

The seven things you're actually paying for

Seven line items make up almost every PCI budget. The self-assessment or audit, quarterly external scans, penetration testing, remediation, tooling, training, and internal staff time. Remediation is usually the largest and the least predictable.

Seven-line PCI compliance budget breakdown with cost ranges for small merchants

Remediation deserves a note. Thoropass puts it at 40 to 60% of a total compliance budget, which makes it larger than the assessment, the scanning, and the tooling combined. You can't price it from a template, because it's a function of what your environment already does correctly, and nobody in the room knows that answer yet. That's the entire argument for running a gap assessment before you accept a program quote. A quote written without one is a guess wearing a number.

The one change that can multiply your PCI bill

In January 2025 the PCI Security Standards Council published a new version of SAQ A, and it replaced the old one on March 31, 2025. On the surface it looked like relief for small e-commerce merchants. The Council removed requirements 6.4.3 and 11.6.1, the two client-side script controls that had been giving everyone trouble, along with 12.3.1.

Then it added an eligibility criterion. To use SAQ A at all, the merchant has to confirm their site isn't susceptible to attacks from scripts that could affect their e-commerce systems.

Read that twice. The controls didn't disappear. They moved out of the list of things you have to do and into the list of things you have to be true before you're allowed to use the short form. Chris Camejo at TrustedSec laid this out in February 2025. SAQ A drops from 21 controls to 19. Miss the eligibility criterion and you're filling out SAQ A-EP instead, which carries 128 requirements for the e-commerce environment plus another 8 for paper record handling.

Nineteen to 128. Same business, same revenue, same transaction count, same merchant level.

Two details keep this from applying to everyone. The Council's FAQ 1588 confirms the new criterion targets merchant pages that host an embedded payment page or form, meaning an iframe. Full redirects and plain links to a payment page aren't affected. So if your customer leaves your domain entirely to pay, this section costs you nothing. If your checkout renders inside your own page, it's the most expensive sentence in your compliance program. One rendering choice.

Worth noting that the published control counts disagree. TrustedSec says 19. HUMAN Security says 27 for SAQ A and 151 for A-EP. Other published breakdowns land on 24. The counts vary depending on how sub-requirements are tallied and which document revision is being read, and the disagreement doesn't change the shape of the problem. Every source describes roughly a six-fold jump. Budget the shape. The decimal can wait. If you want the underlying control set, we walked through the 12 requirements and the 51 controls behind them separately.

What it costs to hold your SAQ A eligibility

So how do you stay on the short form? TrustedSec documents four ways to satisfy the criterion. They are not equally priced.

  • Implement 6.4.3 and 11.6.1 anyway, as if the change never happened. Script inventory, written authorization for every script, tamper detection, and payment page monitoring. Script-monitoring vendors put the tooling at 15 to 25% of total PCI spend. Consider the source. And the free tiers stop being free the moment you have real traffic.
  • Get written attestation from your processor that their iframe resists script attacks. Free, if they'll give it to you. Many won't.
  • A web application penetration test that shows the page holds up. Call it $8,500.
  • Deploy a WAF, a web application firewall that filters traffic before it reaches your payment page. Cheapest on paper. Somebody still has to tune it, and an untuned WAF is a line item, not a control.

Notice what none of those four depend on. Your size.

The line nobody invoices you for

Two vendors, same merchant profile, same questionnaire. Thoropass budgets roughly 20 hours of internal staff time and prices it at about $2,000. Paytia budgets 80 to 300 hours for the SAQ alone.

That's a 15-fold disagreement on the largest soft cost in the project, published by two companies that both sell into it. Neither is lying.

So which one is right? Both, on different years. Twenty hours is what the questionnaire takes when every answer is already true and the evidence already exists. The 80-to-300 range is what it takes when the questionnaire surfaces a list of small gaps nobody knew were there, and someone has to chase each one down, fix it, document it, and produce a screenshot proving it. Year one is almost always the second number. Year three, if somebody actually owns the program, drifts back toward the first. Budget for the second and you'll be right more often than you're wrong.

Check your merchant statement before you budget anything

Pull last month's merchant statement. Look for a line item called PCI non-compliance fee.

Processors add it when you haven't filed your annual questionnaire, and it runs $19.95 to $99.95 a month depending on who processes your cards. It bills until you validate. At the low end that's $240 a year. At the high end, $1,199.

Which means a fair number of merchants are paying more each year to avoid the questionnaire than the questionnaire costs. SecurityMetrics prices the SAQ itself at $50 to $200. So the fee is often four to six times the price of the thing it exists to penalize you for skipping, it renews silently every month, and almost nobody on the finance side has ever been told to look for it. Check the statement.

What non-compliance actually costs

Fines run $5,000 to $100,000 a month. The PCI Security Standards Council doesn't set them and doesn't collect them. Card brands fine your acquiring bank, and your acquirer contract passes the cost down to you.

That distinction matters. More than it sounds. There is no published PCI fine schedule you can look up anywhere, because the amount isn't set by the standard at all, it's contract territory between you and the bank that gave you a merchant account. Secureframe and Thoropass both describe the same enforcement chain. The brands do publish ceilings of their own, and those ceilings escalate with repeat violations rather than staying flat, but the number that actually lands on your account is the one your acquirer agreed to in a contract somebody at your company signed years ago and probably never read again.

Real exposure lives in the merchant agreement. All of it. Read that before you decide the risk is theoretical.

Four ways to cut the bill that actually work

Which of these actually moves the number down? Four things, and only one of them is a purchase.

  • Redirect instead of embed. The change that moves the most money for an e-commerce merchant in 2026, and it's a conversation with whoever maintains your site rather than a purchase.
  • Count your public IP addresses and domains, then cut the ones that don't need to be there. ASV scanning is priced per IP, from about $80 a year at the low end of the market. Ten stale subdomains is a real number on a real invoice, and quarterly scanning of everything in scope is not optional.
  • Put card-present terminals on their own network segment. Segmentation is the difference between the terminals being in scope and the entire office being in scope.
  • Stop storing card numbers. Not the CRM notes field. Not the recorded sales call. Not the emailed PDF that has been sitting in a shared mailbox since 2021 because somebody needed it once and nobody ever went back to delete it. Every one of those pulls a system into scope that has no business being there.

Three budgets, three businesses

Modeled from the published component costs above, not from client invoices. Use them to place yourself, then get real quotes.

Comparison of first-year and recurring PCI compliance budgets for a retailer, distributor, and manufacturer

Stare at the middle column. That business is smaller than a Level 1 merchant by every measure a card brand tracks, and it's carrying a bill five to ten times the retailer's because of a rendering decision made by a web developer who was never told it counted as a compliance decision. Nobody told him. That's the whole story.

When you should stop spending on this

Some of you are finished and don't know it.

Full redirect to your processor's hosted page. No card data stored anywhere, and that includes the CRM notes field and the recorded calls. Written attestation from your processor on file. Annual SAQ A filed and quarterly scans running. If that's an accurate description of your environment, then your PCI cost is a few hundred dollars and one afternoon a year, you do not need a compliance platform, you do not need a QSA, and you do not need the remediation program somebody quoted you last quarter.

Buying one anyway is common. It tends to follow a sales conversation rather than a scoping conversation, and the difference between those two conversations is the difference between a few hundred dollars a year and a program you'll be renewing for the rest of the decade.

Price the scope before you price the program

Boil it down to two things.

Merchant level tells you how to validate. Scope tells you what it costs. Those are separate questions and only one of them shows up on the invoice, which is why so many PCI budgets are built backward. Every PCI compliance cost estimate you'll be handed is really an estimate of your scope, whether the person handing it to you says so or not.

And the largest cost lever available to an e-commerce merchant right now isn't a vendor you pick or a platform you license. It's whether your payment page uses a redirect or an embedded form, and that's a 20-minute conversation with whoever built your site.

Consilien is a nationwide IT and cybersecurity firm working with companies of 20 to 500 users across manufacturing, distribution, professional services, and real estate. Compliance is a standalone offering here, deliberately kept out of the managed IT contract, which means the scoping work happens before anyone quotes you a number. If you're building a PCI budget and you aren't certain which questionnaire you qualify for, settle that first. Speak to a compliance expert.

Price the scope before you price the program

Your merchant level tells you how to validate. Your scope tells you what it costs. Only one of those shows up on the invoice, which is why so many PCI budgets get built backward.

Consilien is a nationwide IT and cybersecurity firm working with companies of 20 to 500 users across manufacturing, distribution, professional services, and real estate. Compliance is a standalone offering here, deliberately kept out of the managed IT contract, so the scoping work happens before anyone quotes you a number.

If you are building a PCI budget and you are not certain which questionnaire you qualify for, settle that first.

What finance teams ask about PCI cost

Is PCI compliance a one-time cost or does it repeat every year?
Every year, without exception. Validation expires 12 months after you file, external scans are quarterly, and penetration testing is annual plus after any significant change to your environment. The shape of the spend changes though. Year one carries the remediation, which Thoropass puts at 40 to 60% of the total, and that portion should shrink dramatically by year three if someone owns the program.
Our processor says we are covered. Are we?
Partly, and the part they cover is not the part that drives your bill. A PCI-validated provider reduces your scope. It does not transfer your obligation. Stripe auto-generates an SAQ A for you to attest to, which is helpful and still requires you to attest. Square tells sellers they do not need to complete a questionnaire at all. Both statements are accurate for the merchant they describe, and neither one says anything about what happens on your own website, which is exactly where the eligibility criterion bites.
Can we skip the SAQ and just eat the non-compliance fee?
$240 to $1,199 a year, so the math looks tempting for roughly a minute. Then you notice the fee does not buy you anything. You are still non-compliant, still exposed to the acquirer fine schedule, and still paying more than the $50 to $200 questionnaire would have cost.
How much of the budget goes to fixing things versus proving things?
Roughly 40 to 60% goes to remediation, the actual fixing. The rest is assessment, scanning, tooling, and documentation. That ratio surprises finance teams who assumed compliance meant paperwork, and it is the strongest argument for a gap assessment before a program quote, because the fixing portion is the part nobody can estimate from a phone call. The split is not unique to PCI either. It tracks closely with what ISO 27001 certification costs, where the remediation work also dwarfs the audit fee.
Do we need a QSA, or can we self-assess?
Merchant level decides this, not preference. Level 1 merchants, generally those above 6 million transactions a year, need a Qualified Security Assessor and a Report on Compliance. Below that, self-assessment is the normal route, though some acquirers require QSA validation for certain SAQ types regardless of volume. Ask your acquirer. Not a vendor.
What happens to the bill if we get breached?
It stops resembling the numbers on this page. A suspected compromise triggers a forensic investigation by a PCI Forensic Investigator, which you pay for, followed by card reissuance costs passed through by the issuing banks, potential fines through your acquirer, and in many cases a bump to Level 1 validation going forward regardless of your transaction volume. The card brands also penalize late breach reporting as its own separate matter, so the clock starts the moment you suspect a compromise rather than the moment you confirm one. The compliance budget is the cheap version of this conversation.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.