Assessment plan
From $12,500
QSA-Led ROC & AOC
Powered by ValueMentor
Preparing for a PCI DSS Level 1 assessment can involve hundreds of requirements, technical controls, policies, evidence requests and remediation activities. Secusy simplifies the journey. Every program starts with a ValueMentor-led PCI DSS assessment — you then choose how much help you want from us.
Fixed prices from $12,500.
The definition
From $12,500
$17,500
Remote, delivered globally
ValueMentor
Every program starts with a ValueMentor-led PCI DSS assessment, a non-compliance report and a remediation tracker. You then choose how much help you want from us.
PCI-ready startups with a capable security or compliance team
$12,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Teams that can implement controls but want PCI expertise guiding them
$17,500one-time
Timeline depends on your readiness, scope complexity and team availability.
Startups that want ValueMentor working alongside them throughout
$25,000one-time
Timeline depends on your readiness, scope complexity and team availability.
| Feature | Assessment | Guided | Complete |
|---|---|---|---|
| Remediation ownership | Customer | Customer with VM guidance | Customer with VM handholding |
| PCI advisory | Assessment clarification | Biweekly | Weekly |
| Policy support | — | Templates | Up to 15 customized policies/procedures |
| Implementation guidance | — | Guided | Hands-on support |
| Evidence preparation guidance | Requirements provided | Guided | Hands-on support |
| Evidence readiness review | During assessment | Continuous | |
| Compliance program management | — | — | |
| Scope confirmation | |||
| Initial PCI DSS assessment | |||
| Non-compliance report | |||
| Remediation tracker | |||
| Secusy compliance workspace | |||
| Cywareness subscription | |||
| Formal QSA assessment | |||
| ROC | |||
| AOC |
If your team already understands PCI DSS and is largely compliant, choose Assessment. If your technical team can implement the controls but needs PCI expertise, choose Guided. If you want a PCI team actively working alongside you throughout the program, choose Complete.
There are no separate assessment fees added at the end of the program for the agreed fixed scope. PCI SSC recognizes official reporting documents such as the ROC, AOC and applicable SAQs as PCI DSS validation documents rather than separate PCI DSS “certificates.”
How it works
You do not have to know exactly what is missing before you start. Our process begins by establishing your PCI DSS scope and assessing your current environment against the applicable requirements.
We understand your payment environment, cardholder-data flows, cloud architecture, applications, third-party dependencies and existing security controls, then confirm the environment included in the fixed-price program.
ValueMentor assesses your environment against the applicable PCI DSS requirements — documentation reviews, technical configuration reviews, interviews, process reviews, evidence examination and system/architecture reviews.
We document identified gaps and explain the areas that must be addressed before successful completion of the assessment.
Every identified non-compliance is added to a structured tracker covering the requirement, finding, required action, responsible owner, evidence required, status and target date — the working compliance plan for the engagement.
Assessment customers remediate independently. Guided customers get periodic ValueMentor advisory support. Complete customers get hands-on support throughout the remediation program.
Once remediation is complete and sufficient evidence is available, the formal QSA assessment is completed.
Following successful completion of the assessment, the applicable PCI DSS Report on Compliance and Attestation of Compliance are finalized.
PCI DSS compliance is not only a documentation exercise. Your environment also needs recurring vulnerability management and security testing. Add the PCI Security Testing Bundle to any Assessment, Guided or Complete program.
$7,500/year
Additional security testing required because of significant infrastructure, application or architectural changes is outside the bundle and can be purchased separately. PCI DSS requires vulnerability scanning at least once every three months, and external scans under the applicable requirement are performed by an Approved Scanning Vendor.
Our fixed-price PCI DSS Level 1 programs are designed for relatively straightforward, cloud-native startup environments. To qualify, your PCI environment must generally fit within the following boundaries.
The third-party providers' own environments are not included in the ValueMentor assessment scope. If a third-party provider itself requires assessment, this is treated as a separate engagement. Environments involving multiple CDEs, multiple cloud providers, complex payment infrastructure, large physical estates, PIN environments or significantly larger technical scope require a custom PCI DSS engagement.
Included
Regardless of the plan selected, the objective is clear: give your startup a structured route from its current PCI posture to successful assessment.
Your program includes
There are no separate assessment fees added at the end of the program for the agreed fixed scope.
PCI DSS requires organizations to maintain a security awareness program. Every Secusy PCI DSS Level 1 package therefore includes 12 months of Cywareness security awareness training for up to 100 users. Additional users can be added separately.
One journey from assessment to ROC and AOC. Many startups pursuing PCI DSS Level 1 coordinate QSA assessment, remediation support and compliance tooling separately — Secusy and ValueMentor bring the program together in one fixed-price engagement.
Your compliance program, remediation tracking, security awareness, optional vulnerability scanning, penetration testing and QSA assessment can be coordinated through one engagement.
Know the cost of your PCI DSS program before you begin — no open-ended consulting engagement for environments that remain within the agreed scope.
We first assess your current environment. You receive documented findings and a structured remediation tracker before deciding how much implementation support your team requires.
Already PCI-ready? Choose Assessment. Have a capable internal team but need expertise? Choose Guided. Need someone working closely alongside you? Choose Complete.
Use Secusy to organize findings, responsibilities, remediation and evidence rather than managing the entire PCI program through spreadsheets and email.
Secusy is the digital sales and service-delivery platform for ValueMentor cybersecurity services. ValueMentor is a member of the PCI Security Standards Council's 2026–2028 Global Executive Assessor Roundtable.
Questions
Start with a defined scope, clear pricing and an assessment-led approach. PCI DSS compliance delivered through Secusy, powered by ValueMentor.
$12,500one-time
$17,500one-time
$25,000one-time
Optional PCI Security Testing Bundle — $7,500/year, addable to any plan above.