How Much Does PCI Compliance Cost?
Scans, questionnaires, processor fees and the IT work to isolate card systems. What drives the cost.
PCI compliance costs come from four places: fees your processor charges, external vulnerability scans, the time or consulting needed to complete the SAQ, and the IT work to segment and secure the systems that touch card data. Non-compliance costs more: monthly non-compliance fees from the processor, and after a breach, fines, forensic investigations and card replacement costs.
Recurring costs
- Processor PCI fees. Many processors charge a monthly or annual PCI program fee, and a separate, higher non-compliance fee if you have not validated.
- Approved scanning vendor (ASV) scans. Quarterly external vulnerability scans, required for several SAQ types.
- Annual SAQ and attestation. Staff time, or a consultant's time, to answer the questionnaire accurately.
- Ongoing IT controls. Patching, logging, MFA, firewall management and monitoring that keep you compliant between assessments, usually part of a managed IT agreement.
One-time costs
- Scoping and gap assessment. Determining what is in scope and what is missing.
- Remediation. Segmenting the network, replacing unsupported systems, hardening firewalls, deploying MFA and logging.
- Penetration testing, required for some SAQ types and after significant changes. See what is penetration testing.
- Payment method changes. Moving to validated terminals or a hosted payment page has a cost, but often reduces scope enough to lower everything else.
What moves the number
Your merchant level and SAQ type (PCI levels and SAQs), how many systems touch card data, whether you store card numbers (avoid it), how many locations you have, and the current state of your network.
The cost of not doing it
Processor non-compliance fees accumulate monthly. After a breach, card brands can levy fines, require a forensic investigation at your expense, and increase your processing rates or terminate your account. For a small business, that is frequently the most expensive outcome of all.
Mentis Group's PCI compliance consulting in Dallas-Fort Worth focuses on reducing scope first, then implementing the controls that remain. See what is PCI compliance for the requirements.
Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.