How Much Does PCI Compliance Actually Cost a Small Online Store?
PCI compliance costs come from four places: non-compliance fees, ASV scans, your own time, and a QSA if your scope grows. Here's the real math for a small store.
There's no PCI compliance price tag, because the standard itself doesn't charge you one. What costs money is what happens around it: a fee if the paperwork is missing, a scan if your SAQ requires one, and a consultant if your setup outgrows self-assessment. For most small merchants, the real number is closer to an afternoon of your own time than a bill.
That's not the story most search results tell you. Here's where the actual costs come from, and which ones apply to you.
What does PCI compliance actually cost?
The Self-Assessment Questionnaire itself is free. PCI SSC doesn't charge merchants to file an SAQ, and for SAQ A it's 29 questions you can complete in well under an hour once you know your integration.
The costs that show up on a statement come from three other places: a non-compliance fee if you haven't filed, a scan fee if your SAQ requires one, and a consultant if your scope is bigger than self-assessment covers. None of the three apply to every merchant, which is exactly why "PCI compliance cost" doesn't have one answer.
Is the PCI non-compliance fee the same as the cost of compliance?
No, and confusing the two is the single most common mistake. A non-compliance fee is a penalty your processor adds when your validation paperwork isn't on file, and it typically runs $20 to $100 a month, with published examples around $29.95 and $94.95 at named processors.
It's a charge for the absence of paperwork, not a substitute for it. Paying the fee every month while never filing the SAQ means paying indefinitely for a problem that a free form would have closed. Our longer explainer on the non-compliance fee covers how to spot it on a statement and get it removed.
How much do quarterly ASV scans cost?
Typically $50 to $300 per quarter for a small merchant, paid to a PCI SSC Approved Scanning Vendor like SecurityMetrics, Trustwave, or ControlScan. This applies if you're SAQ A-EP or SAQ D, where scanning has always been required, and it applies to SAQ A too, since Requirement 11.3.2 added quarterly scanning there starting with PCI DSS v4.0 in April 2024.
Check your processor's compliance portal before buying a separate scan. Shopify Payments, Stripe, and several other processors bundle ASV scanning into what merchants already pay for, and a lot of merchants buy a redundant scan simply because they never looked.
Not sure which SAQ your setup puts you in, or whether scanning applies to you? Our free SAQ selector walks through the same questions a QSA would ask.
Do you need a QSA, and what does that cost?
Most SAQ A and SAQ A-EP merchants never need one. A Qualified Security Assessor becomes relevant mainly for SAQ D merchants, who process or store card data directly, or for a custom build complex enough that self-assessment stops being a reasonable answer.
Where a QSA is warranted, engagements typically start around $15,000 and climb with scope. That number is real, but it's the ceiling most small merchants never reach, not the going rate for filing SAQ A.
What's the real total, for a typical SAQ A merchant?
For a store using a standard hosted or iframe checkout, with no outstanding processor notice: the SAQ itself, free. A scan if your processor doesn't already bundle one, $50 to $300 a quarter. No non-compliance fee, no QSA. The honest total is closer to zero than to the four- and five-figure numbers a search for "PCI compliance cost" tends to surface, because those numbers describe SAQ D scope and enterprise QSA engagements, not a typical small store.
The one place cost creeps in quietly is drift. A checkout that was cleanly SAQ A six months ago can pick up a script or a checkout extension that pushes it toward SAQ A-EP without anyone deciding that should happen, and that's a scope change, not a fee, until someone finds it.
Where to start
If you have a statement line, a processor notice, or a failed scan sitting in your inbox right now, send it through PCI Notice Triage. It's free, a PCI professional reads it and tells you what it actually requires, and some triages end with "you don't need to do anything else."
If nothing has landed yet and you just want to know where you stand, run a free check on your own store, verify your domain, and keep it running.
This is your store today. App updates, theme edits and new agency work change it — usually without anyone telling you.
Technical Overview
Next steps
Subscribe to the Newsletter
PCI compliance guides and ecommerce threat intelligence, straight to your inbox.
No spam, unsubscribe anytime. We handle your address as described in our privacy policy.
Related Articles
Failed Your ASV Scan? A Calm, Step-by-Step Recovery Plan
A failed ASV scan is common and fixable. Here is a calm, step-by-step recovery plan: what a failing result means, what to fix first, and how to rescan to a pass.
Does SAQ A Require Quarterly ASV Scans? Yes, Here's What Changed in PCI DSS v4.x
Many Shopify and Stripe merchants believe SAQ A means no vulnerability scanning. Under PCI DSS v4.x that is no longer true. Requirement 11.3.2 now requires quarterly ASV scans for SAQ A merchants, here's why, and what to do about it.
Your ASV Scan Came Back Failing: How to Read the Report and Prioritise What to Fix
A failing ASV scan report is dense, technical, and easy to misread. Here's how to work through it: what CVSS scores actually mean for your compliance deadline, which findings you must fix, which you can dispute, and how to get to a passing scan as quickly as possible.