We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

PCI SSC-qualified QSA Company

PCI DSS QSA assessment timeline

A first-time PCI DSS v4.0.1 assessment typically runs three to six months end to end, in three phases: scoping and gap assessment (3–6 weeks), remediation (the variable bulk), and the on-site QSA assessment plus RoC/AoC production (2–4 weeks). Well-scoped, evidence-ready environments finish faster; sprawling or under-prepared ones take longer. CyberSigma is a PCI SSC-listed QSA Company — we sequence the work so remediation and evidence collection happen in parallel, not after, to compress the timeline.

Get a free timeline & scope →Book a 20-minute QSA call
Phases

The three phases

Scoping & gap — 3–6 weeks
CDE definition, data-flow mapping, gap analysis and a prioritised remediation roadmap.
Remediation — variable
The bulk of the calendar. Driven by how far controls and evidence are from the standard.
On-site & RoC/AoC — 2–4 weeks
Evidence sampling, testing procedures and production of the signed RoC and AoC.
What speeds it up

What compresses the timeline

  • A reduced CDE — fewer systems to assess and evidence
  • Evidence collected in parallel with remediation, not after
  • MFA, logging, ASV scans and pentests already in place
  • A single accountable project owner on your side
What slows it down

What extends it

  • Under-scoped CDE discovered mid-assessment
  • Missing quarterly ASV scans or overdue pentest
  • No targeted risk analyses (a v4.0.1 requirement)
  • Evidence gathered reactively during the on-site
Recurring

After the first RoC

PCI DSS compliance must generally be revalidated annually, with quarterly ASV scans and continuous control operation in between. Subsequent annual cycles are shorter than the first.

Proof

See how we’ve done it before

Relevant case study
How parallel remediation and evidence collection cut months off a first assessment. Read case studies →
Redacted sample deliverable
Inspect a redacted gap report first. Request a redacted sample →

Not sure how close you are to a clean ROC?

Get a free PCI DSS v4.0.1 readiness snapshot from a listed QSA — share your work email and we map your gaps and scope before the assessment.

PCI DSS timeline — FAQs

How long does a PCI DSS assessment take?

A first-time assessment commonly runs three to six months: scoping and gap (3–6 weeks), remediation (variable), and the on-site plus RoC/AoC (2–4 weeks). Reduced scope and ready evidence shorten it.

Can it be done faster?

Yes — reducing the CDE and collecting evidence in parallel with remediation are the biggest accelerators. Annual re-validation after the first RoC is quicker.

How long is the AoC valid?

The Attestation of Compliance is valid for 12 months; PCI DSS compliance must generally be revalidated annually.

Get a realistic PCI DSS timeline

Share your environment and we return a phased timeline with the levers that shorten it. Reply within four business hours.

Book a 20-minute QSA call →

Ready to discuss your PCI DSS assessment timeline requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.