Cost reduction

Seven ways to cut PCI compliance cost

The cheapest dollar spent on compliance is the one you removed from scope. These seven strategies are the proven levers, ordered by typical impact.

Updated July 2026

The cheapest PCI path, in one line

The cheapest way to be PCI compliant is to stop touching card data. Route every payment to a hosted checkout (Stripe Checkout, PayPal, Square) so you validate with SAQ A, the shortest questionnaire at around 24 controls, instead of SAQ D and its roughly 251. That is about a tenth of the questions, and it is the closest thing to a free lunch in PCI, because it costs you an integration rather than a control programme. Nobody publishes what either side costs, so we will not pretend to price the gap. What is certain is the direction: every system you remove from the cardholder data environment is a system you no longer pay anyone to assess, evidence or test.

01

Strategy

Tokenization

Replace stored card numbers with non-sensitive tokens. Removes storage systems from PCI scope entirely.

What it does to scope

Removes card-data storage systems from scope entirely. What is left in scope is the tokenization boundary, not the datastore behind it.

What it is priced against

Usually priced per token or per transaction by the gateway, and often already included in what you pay it. Check before you buy it twice.

Trade-off

Vendor dependency. Tokens are not portable between providers.

Common providers: Stripe, Braintree, Basis Theory, VGS, TokenEx

02

Strategy

Hosted Payment Pages

Redirect customers to a fully hosted payment page. Card data never touches your servers.

What it does to scope

Moves an e-commerce merchant from SAQ D (~251 controls) to SAQ A (~24 controls). The largest single control reduction available to an online merchant.

What it is priced against

Integration engineering time, which is yours rather than a vendor's. The hosted page itself is typically included in the gateway's processing fee.

Trade-off

Less UX control over the payment experience. Redirect may increase cart abandonment. Since v4.0.1, SAQ A eligibility also requires confirming your site is not susceptible to script attacks.

Common providers: Stripe Checkout, PayPal, Adyen Drop-in, Braintree Hosted Fields

03

Strategy

Network Segmentation

Isolate your cardholder data environment (CDE) from the rest of your corporate network using firewalls and VLANs.

What it does to scope

Removes out-of-scope systems from the assessment, so the QSA tests a smaller estate. It also adds segmentation penetration testing under Requirement 11.4.5, at least every 12 months, and every six months for service providers under 11.4.6.

What it is priced against

Network engineering effort against your existing estate, plus the recurring segmentation test. The test bill arrives because you segmented, and it is still usually smaller than assessing the estate you removed.

Trade-off

Adds a recurring segmentation test. Requires ongoing maintenance of the segmentation controls, and a segmentation change triggers a retest.

Common providers: Cisco, Palo Alto, Fortinet, pfSense (open-source)

04

Strategy

P2PE Terminals

Use PCI-validated Point-to-Point Encryption terminals for in-person payments. Dramatically reduces scope.

What it does to scope

Moves a card-present merchant to SAQ P2PE at 33 controls, against ~251 for SAQ D. The terminal takes the card data onto the validated solution rather than your network.

What it is priced against

Per-terminal hardware, quoted by your terminal vendor or acquirer. Multiply by your terminal count and by your refresh cycle.

Trade-off

Must be a PCI-validated P2PE solution from the PCI SSC list, not merely an 'encrypted' terminal. That distinction is the whole benefit and is easy to get wrong.

Common providers: Bluefin, Verifone (select models), Ingenico (select models)

05

Strategy

Compliance Automation Platforms

Automate evidence collection, policy management, and continuous monitoring. Does not replace the QSA or ASV.

What it does to scope

Does not reduce your control count. It automates the evidence collection and monitoring around the controls you already have, and does not replace the QSA or the ASV.

What it is priced against

Four of these publish list prices on AWS Marketplace, which is the rare published number in PCI. Each vendor's page on this site quotes its listing.

Trade-off

An annual subscription on top of the assessment, not instead of it. Most useful where the same evidence serves several frameworks.

Common providers: Sprinto, Vanta, Drata, Secureframe, Thoropass

06

Strategy

Right-Size Your SAQ

Many merchants complete SAQ D when they qualify for SAQ A, B-IP, or C. Switching to the correct SAQ reduces both the control count and the effort.

What it does to scope

Completing SAQ D when you qualify for SAQ A means answering ~251 controls instead of ~24. Confirming the right SAQ costs you a conversation and changes nothing about your architecture.

What it is priced against

Free to check. PCI SSC FAQ #1158 covers the route if your processor disagrees: confirm the payment flow in writing, share architecture diagrams, escalate via your acquirer.

Trade-off

None if you genuinely qualify for a simpler SAQ. Real risk if you self-select a simpler one you do not qualify for, which surfaces at exactly the wrong moment.

Common providers: Your acquirer, your processor's portal, or a QSA for a scoping opinion

07

Strategy

Internal Security Assessor (ISA)

Train an internal employee as a PCI ISA. They can conduct your annual assessment instead of hiring an external QSA.

What it does to scope

Changes who signs the assessment rather than how many controls it has. Mastercard's SPME accepts a certified ISA in place of a QSA for the Level 2 SAQ validation it requires, and for Level 1 ROC signing.

What it is priced against

PCI SSC publishes ISA programme fees on its own site; check the current year's figure there rather than trusting a number from a page like this one. Weigh it against the QSA quote you actually hold.

Trade-off

Only works if you have staff who can hold the qualification and stay independent of the systems they assess. It is a standing headcount commitment against a recurring fee, so it turns on your own numbers.

Common providers: PCI SSC Official ISA Programme

Before

Mid-size e-commerce on direct-post checkout

  • SAQ D, roughly 251 controls to answer and evidence
  • Requirement 6.4.3 applies: every payment page script inventoried, authorised and integrity-checked
  • Your servers are in the cardholder data environment, so they are in the assessment
  • Internal and external penetration testing, at least annually (11.4.2, 11.4.3)

~251 controls

After scope reduction

Same merchant, hosted checkout plus tokenization

  • SAQ A, roughly 24 controls
  • Card data never reaches your servers, so they leave the assessment
  • No stored PAN to protect, because the token is not card data
  • You still attest annually, and your provider does not file it for you

~24 controls

Both counts are published, in the SAQ A and SAQ D documents in the PCI SSC document library. There is no money on this comparison because the only honest way to put it there is to price both sides with real quotes for your own scope, which is what the worksheet is for. The control delta is the part that is true for everyone.

Ready to map your scope?

A scoping workshop typically takes one to three days and identifies which systems can be removed from PCI scope. The PCI SSC publishes a free scoping and segmentation guidance document used by most QSAs.

PCI SSC scoping guidance

Frequently asked

Seven main levers. Tokenize stored card data to remove storage from scope. Move from a hosted iframe to a full redirect to drop from SAQ A-EP to SAQ A. Segment your network so only the cardholder data environment is in scope. Switch to validated P2PE terminals for in-person flows. Automate evidence collection. Right-size your SAQ if you are on SAQ D unnecessarily. For Level 1-2, train an Internal Security Assessor instead of hiring an external QSA every year.

Continue reading