What Happens If You Fail a PCI Assessment
Nobody passes on the first try. How findings, remediation, and re-testing actually work — and why “not yet compliant” isn't the disaster it sounds like.
Not compliant — yet
Here's the industry's open secret: most first-time assessments don't result in a clean ROC on the first pass. The assessment produces findings, you remediate, the QSA re-tests, and then the ROC is signed. “Not compliant” is a stage in the process, not a verdict — what matters is having time and budget for the fix cycle.
Findings vs observations
Findings ("not in place") block the ROC until remediated and re-tested. Observations are weaknesses the QSA flags without failing the requirement — worth fixing, but they don't hold up the report. Know which is which before you panic: a report with observations and no findings still gets signed.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesThe remediation cycle
For each finding: the QSA documents what's missing, you implement the fix, you provide evidence the fix works, the QSA re-tests. Simple findings (a missing policy, an unreviewed log) close in days. Architectural findings (segmentation that doesn't exist, logging that was never built) take weeks to months — which is why the remediation phase owns most of the calendar.
Re-testing
Re-testing isn't a formality: the QSA applies the same testing procedures to the remediated control. Confirm your engagement letter covers re-testing — some firms include a round, others bill it separately, and that changes the true cost of findings.
Planning for the fix
- Budget a remediation reserve. 20–30% of the assessment fee is a sane planning figure for first-timers.
- Don't schedule fieldwork against a hard deadline without buffer for the fix cycle.
- Fix systemic findings first — one broken process can generate findings across dozens of requirements.
- Keep the same QSA for re-testing. A new assessor re-tests everything, not just the fixes.
Keep reading
ROC vs SAQ: Which PCI Validation Path Are You On?
The two roads through PCI DSS certification — what happens on each, who decides, and the expensive mistake of picking the wrong one.
SAQ Types A Through D, Explained
Eight questionnaires, one choice that shapes your whole PCI workload. Which SAQ type fits your payment setup — and what each one demands.
What QSAs Actually Test: Inside ROC Fieldwork
Phase 4 demystified — the testing procedures, the evidence requests, and how to walk into fieldwork with everything ready.
Questions
Can we still get certified with findings?
Yes — findings get remediated and re-tested, then the ROC is signed. Only unremediated “not in place” findings block the report.
What if we can't remediate in time?
Talk to your QSA and acquirer early. Compensating controls exist for requirements that genuinely can't be met as written — but they need QSA agreement and documentation, not improvisation.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.