The process, end to end

How PCI DSS certification works

Every PCI DSS certification — whether it ends in a ROC signed by a QSA or a SAQ you sign yourself — follows the same five phases. This is the full journey, with realistic durations, who does what, and where the money goes.

First: which path are you on?

Your merchant or service-provider level decides. Level 1 (6M+ transactions/year for most card brands; 300K+ for service providers) means an on-site QSA assessment producing a Report on Compliance (ROC). Everyone else typically completes a Self-Assessment Questionnaire (SAQ). Your acquirer confirms — and can require more than the minimum. See ROC vs SAQ and merchant levels.

Phase 1: Scoping

What happens: you (ideally with a QSA) map exactly where cardholder data lives, moves, and is processed — systems, networks, people, and service providers. Everything in the cardholder data environment (CDE) is in scope for testing; everything else isn't.

Duration: 1–3 weeks. Who: your team, ideally with QSA guidance.

Why this phase controls your fee. QSA fees scale with scope. Every system you can legitimately exclude — through network segmentation, tokenization, or outsourcing card handling — is fee you don't pay, every year. Scoping done badly is the most expensive mistake in PCI: an underscoped assessment gets re-scoped mid-fieldwork, and the fee follows.

Phase 2: Gap assessment

What happens: your current controls are measured against PCI DSS v4.0.1 (the current standard; v3.2.1 was retired March 31, 2025) before the formal assessment begins. This is a rehearsal, not the exam — findings here don't go on any record.

Duration: 2–4 weeks. Who: a QSA company (often — not always — the same firm that will do the ROC), an ISA, or a strong internal team.

Cost: often bundled with the assessment or priced as a short engagement ($5K–$20K planning estimate). Skipping it to save money is how companies pay for findings during fieldwork instead — at higher rates and under deadline pressure.

Phase 3: Remediation

What happens: you close the gaps the assessment found — fix configurations, write the missing policies, build the logging you never had, segment the network, deploy MFA where v4.0.1 requires it.

Duration: 4–12 weeks for first-timers; often the longest phase. Who: your engineering and security teams.

Budget for this phase explicitly. Remediation is where first-time PCI budgets die: the QSA fee was quoted, but nobody budgeted the engineering time, the new tooling, or the re-testing. A 20–30% remediation reserve on top of the assessment fee is sane planning for first-timers.

Phase 4: QSA fieldwork

What happens: the QSA tests your controls using three procedures — examine (documentation and configurations), interview (the people who operate the controls), and test (observe the control working). Evidence is sampled across systems, and every requirement gets a verdict: in place, not in place, or not applicable.

Duration: 2–12 weeks depending on scope. Who: the QSA's assessment team, with your team providing evidence and access.

Findings (“not in place”) send you back to remediation for those items, then re-testing. See what QSAs actually test and what happens if you don't pass.

Phase 5: Report & attest

What happens: the QSA compiles the Report on Compliance, you review it for factual accuracy, the QSA signs it, and the Attestation of Compliance (AoC) goes to your acquirer — and to the customers and partners who ask for it.

Duration: 2–4 weeks for report writing and review. The ROC is valid for one year from the assessment date.

Your AoC is now a sales asset: put it in your trust center, attach it to security questionnaires, and never let it expire mid-deal. See sharing your AoC.

After certification: the annual cycle

Certification isn't a project, it's a cycle. Renewals re-test everything but skip the discovery: scoping becomes a delta review, evidence reuses last year's package, and planning estimates typically run 40–70% of the first-year fee once the program matures. Engage the QSA 3–4 months before expiry — late bookers wait, and lapsed attestations kill deals. Full playbook: ROC validity and renewals.

Durations and costs on this page are planning estimates (September 2026), not quotes or guarantees. Your timeline depends on scope, readiness, and your QSA's calendar — confirm all three in writing before you commit to a date.

Start with scoped quotes

Tell us your environment once — matched QSA companies send competing quotes for your certification. Free, two minutes.

Get a free quote