How Long Does PCI Certification Take? Timelines by Path
‘How long does PCI certification take?’ has three different answers. Here's each path, phase by phase, plus the delays that blow up schedules.
Timelines at a glance
| Path | Typical total | Active assessment time |
|---|---|---|
| SAQ self-assessment | 4–12 weeks | 2–6 weeks of evidence work |
| QSA-led readiness | 4–8 weeks | 2–4 weeks of assessor fieldwork |
| Full ROC (first time) | 3–6 months | 4–12 weeks of fieldwork |
| ROC renewal | 2–4 months | 3–8 weeks of fieldwork |
SAQ path: 4–12 weeks
Weeks 1–2: confirm your SAQ type with your acquirer and scope the environment. Weeks 2–6: work through the questionnaire, gather evidence, and run ASV scans (failures must be remediated and rescanned -- budget 2–3 scan cycles). Weeks 6–12: QSA validation if you're using one, sign-off, and submission. Clean SAQ A environments finish in a month; SAQ D can take the full quarter.
Readiness: 4–8 weeks
Week 1: scoping and document requests. Weeks 2–4: assessor review -- interviews, control testing, evidence sampling. Weeks 4–8: gap report and remediation roadmap delivery, plus a readout with your team. The clock after that is yours: most organizations need 1–3 months to work the roadmap.
ROC: 3–6 months
Month 1: scoping, statement of work, and evidence collection. Months 2–3: fieldwork -- the QSA tests controls, interviews personnel, and samples locations (4–12 weeks depending on complexity). Month 3–4: remediation of findings and re-testing. Months 4–6: reporting, quality review inside the QSA firm, and the signed ROC/AOC. Renewals skip the learning curve and run 2–4 months.
What causes delays
- Evidence archaeology. The #1 delay: the assessor asks for logs, configs, and policies that don't exist in presentable form. Every missing artifact is a calendar week.
- Scope creep mid-assessment. Discovering in-scope systems during fieldwork restarts testing. Scope ruthlessly in step 3.
- Remediation queues. Findings that need engineering time compete with product roadmaps. Pre-book engineering capacity for the remediation window.
- Service-provider AOCs. Chasing your vendors' attestations late in the cycle stalls reporting. Request them at kickoff.
- v4.x new requirements. Script inventories, tamper detection, and risk analyses are first-cycle work for most organizations -- they don't exist yet and can't be hurried.
How to go faster
Do readiness before the ROC. Assign one internal owner with authority to pull evidence. Confirm scope in writing before fieldwork. And start ASV scans early -- they're on the critical path more often than anyone expects. See the visual timeline.
Related reading
Get quotes from PCI QSA firms
Tell us about your environment once -- matched assessors reply with scoped quotes. Free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.