How long does a PCI DSS assessment take?
A realistic end-to-end range for a first Level 1 ROC: 3–6 months. Here's where the time goes -- and how to compress it.
A first Level 1 ROC realistically takes 3 to 6 months end to end: 2–4 weeks of scoping and assessor selection, 4–8 weeks of gap assessment and remediation, 4–12 weeks of fieldwork, and 2–4 weeks for report writing and QA. SAQ engagements are faster: 4–12 weeks all in.
- Confirm level & select assessor -- 2–4 weeks
Confirm your merchant level and validation type with your acquirer in writing. Get 2–3 scoped quotes; the statement of work defines everything downstream. - Scoping -- 1–2 weeks
The QSA maps your cardholder data environment: systems, data flows, locations, service providers. Scoping errors discovered later restart testing -- get this right. - Gap assessment (recommended for first-timers) -- 2–4 weeks
A dry run against the requirements produces your remediation list. Skip only if you've passed before in the same environment. - Remediation -- 4–12 weeks
Fix the gaps: MFA rollout, logging, segmentation, script inventory, policies, vendor AOCs. This is the phase most companies underestimate. - Fieldwork -- 4–12 weeks
The QSA tests controls, reviews evidence, interviews staff, and observes processes. Clean evidence = the short end of this range. - Reporting & QA -- 2–4 weeks
The QSA writes the ROC, it goes through the firm's internal QA, then you get the signed report and Attestation of Compliance.
What causes delays
- Scope creep mid-assessment. New in-scope systems found during fieldwork restart testing on those areas.
- Evidence archaeology. Controls existed but nobody kept artifacts. Reconstructing evidence takes longer than the assessment itself.
- v4.x new requirements. Script inventories, payment-page tamper detection, and targeted risk analyses catch first-timers off guard -- budget them early.
- Key-person bottleneck. One engineer owns all evidence and goes on vacation during fieldwork. Assign a backup.
Beware the too-fast promise: anyone selling a credible first Level 1 ROC in 3 weeks is skipping steps your acquirer will spot.
Fastest realistic path
Already operating with strong controls and a tight CDE? Scoping (1 week) + 4-week fieldwork + 2-week reporting ≈ 7–8 weeks to a signed ROC. Starting from scratch with a sprawling environment? Plan for 6+ months.
After year one
Renewal assessments reuse your scoping and evidence habits -- most programs settle into an annual rhythm with the fieldwork window as the main active effort. See the step-by-step process for keeping year-two scope tight.
Timeline questions
Can I shorten the assessment timeline?
Somewhat. The fieldwork window (4–12 weeks for a ROC) is driven by your evidence readiness -- companies with clean artifacts, assigned owners, and pre-organized evidence routinely land at the short end. Remediation, not the assessor, is what stretches timelines.
Do I need a gap assessment first?
Not always, but first-timers usually benefit. A gap assessment finds the failures before the QSA does, when they're cheaper to fix. If you've passed before with the same environment, you can often go straight to the assessment.
What slows PCI assessments down most?
Scoping surprises and evidence archaeology. Discovering in-scope systems mid-assessment restarts testing on those areas; controls that existed without artifacts take longer to evidence than the assessment itself.
Start the clock
Tell us your deadline -- we'll match you with assessors who can hit it.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.