PCI DSS frequently asked questions
Straight answers to the questions buyers ask before their first assessment.
What is PCI DSS?
The Payment Card Industry Data Security Standard: 12 requirements for protecting cardholder data, maintained by the PCI Security Standards Council. Any organization that stores, processes, or transmits cardholder data must comply and validate compliance annually.
What are the 12 PCI DSS requirements?
They cover: (1) network security controls, (2) secure configurations, (3) protecting stored account data, (4) protecting data in transit, (5) malware protection, (6) secure systems and software, (7) access restriction, (8) user identification and authentication, (9) physical access, (10) logging and monitoring, (11) security testing, (12) security policies. See our plain-English guide.
What is the difference between a ROC and an SAQ?
A Report on Compliance (ROC) is a full on-site assessment performed by a QSA, required for Level 1 merchants and most service providers. A Self-Assessment Questionnaire (SAQ) is a validation questionnaire for smaller merchants -- you complete it yourself (often with QSA guidance). See ROC vs SAQ.
Who can perform a PCI DSS assessment?
Only a PCI SSC-listed QSA company can sign a Report on Compliance. ASV scans must come from an Approved Scanning Vendor. SAQs are self-assessments, but many merchants hire a QSA to validate them.
How much does a PCI DSS assessment cost?
Published ROC fee ranges run $20,000–$200,000+ for Level 1; QSA-assisted SAQs run $3,000–$15,000. See the cost guide.
How long does it take?
Three to six months end to end for a first Level 1 ROC, including 4–12 weeks of fieldwork; 4–12 weeks for SAQ engagements. Details on the timeline page.
Still have questions? Assessors answer scoping questions free as part of quoting -- tell us your scope once and matched firms respond.
Ask assessors directlyWhat is a QSA vs a QSAC?
A QSA (Qualified Security Assessor) is the certified individual; a QSAC (QSA Company) is the firm authorized by the PCI SSC to perform assessments. When people say 'hire a QSA,' they mean engage a QSAC.
What is an ASV scan?
An Approved Scanning Vendor scan: a quarterly external vulnerability scan of internet-facing systems, required for most merchants and service providers. Only PCI SSC-approved ASVs count; published pricing runs roughly $100–$500 per quarter.
Do I need penetration testing for PCI?
Yes for Level 1 ROCs: PCI DSS requirement 11.4 mandates annual network and application penetration testing plus segmentation validation. Published ranges put pen tests at $5,000–$30,000 per test.
What changed in PCI DSS v4.0.1?
v4.0.1 made 47 previously future-dated requirements fully mandatory as of March 31, 2025 -- including payment-page script inventory (6.4.3), tamper detection (11.6.1), MFA for all CDE access (8.3.6), and targeted risk analyses (12.3.2). See what's new.
How do I choose a QSA firm?
Confirm the firm is a PCI SSC-listed QSA company and ask who the assessment team is, whether the fee is fixed and what breaks it, how multi-location sampling works, and whether you can speak to two reference clients your size. Our nine-question checklist covers it.
Can I switch QSA firms?
Yes. You can change assessors between annual cycles with no penalty beyond a new statement of work. Mid-engagement switches are possible but expect evidence handoff friction.
What happens if the assessor finds issues?
Findings must be remediated before the QSA can issue a passing ROC or validated SAQ. You get time to fix gaps and the assessor re-tests -- which is why gap assessments before the real thing save money.
Is PCI DSS a certification?
Strictly speaking, no -- it's a validation: a ROC or SAQ plus an Attestation of Compliance, renewed annually. In practice buyers treat it like a certification: 'PCI compliant' means 'we hold a current validated AOC.'
How often must PCI be renewed?
Annually. The AOC is valid for one year from signing, and ASV scans, pen testing, and the assessment or SAQ repeat every year.
Can one firm do PCI and SOC 2 together?
Yes -- many firms (Schellman, A-LIGN, 360 Advanced, BARR Advisory, KirkpatrickPrice) offer both, and combined engagements can share evidence and reduce total cost.
Still have questions?
Get matched with assessors who answer scoping questions free -- it's part of how they win business.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.