PCI Non-Compliance Fee: What It Is, Why It Appears and How to Stop It

A PCI non-compliance fee is a charge your processor adds until you validate PCI compliance. Why it appears, who sets it and how to make it stop.

Fundamentals Sources listed at the end

A PCI non-compliance fee is a charge your card processor adds to your statement when it has no record that your business has validated its compliance with the Payment Card Industry Data Security Standard (PCI DSS). It usually repeats every month until you do. To stop it, complete the validation your processor asks for, most often a Self-Assessment Questionnaire in its compliance portal, and then check that the fee is gone from your next statement.

What PCI DSS is

PCI DSS is a set of security rules for anyone who takes, stores or sends card payments. It is written and maintained by the PCI Security Standards Council, whose policy is set by a committee of American Express, Discover, JCB, Mastercard, UnionPay and Visa. The Council says the standard applies to every business involved in taking card payments, regardless of its size or how many transactions it runs.

Complying means following the standard. Validating means proving it, usually once a year, in the way your processor asks.

Who sets the fee

Not the PCI Security Standards Council. The Council says it does not manage compliance programs and does not impose any consequences for non-compliance. Enforcement belongs to the card brands, which work through acquirers: the banks and processors that sign merchants up for card payments.

  • Visa says acquirers are responsible for making sure their merchants comply with PCI DSS and validate at the right level. If a merchant does not comply, Visa may charge a non-compliance assessment to the acquirer, and the acquirer must not tell the merchant that Visa imposed it.
  • Mastercard says its smallest merchants (Level 4) must comply with PCI DSS, but do not have to validate to Mastercard unless a law or regulation requires it.

So the monthly non-compliance fee on your statement is your processor's own charge. Its amount and the date it starts come from your processing agreement, not from a card brand price list.

Why it appears on your statement

The fee appears when your processor has not received your validation. Common reasons:

  • The account is new and the first validation deadline has passed.
  • Last year's validation has expired. Clover, for example, tells merchants they must verify compliance every year.
  • The questionnaire, or a network scan it called for, was never finished.

Processors label the line differently. Clover's help center says its fee may appear as "non-receipt of PCI validation" on processing statements.

PCI fee and PCI non-compliance fee are not the same

Many processors charge a PCI compliance or PCI program fee for the tools and support they provide, whether or not you validate. The non-compliance fee is separate, a charge for not validating, and you can see both in the same month. Merchant Statement Fees Glossary: Every Line Item Defined lists both.

How to stop a PCI non-compliance fee

  1. Find the line. Note its name, the amount and the first statement it appeared on.
  2. Find your processor's compliance portal. Your processor tells you where to validate, often by email or a notice in your dashboard. Clover, for example, sends merchants to its Clover Security Plus site.
  3. Complete the Self-Assessment Questionnaire (SAQ). The PCI Council describes SAQs as validation tools for eligible merchants. There are several versions, each for a different way of taking cards. Your processor or acquirer decides which one applies to you, so ask if the portal does not choose it.
  4. Finish any scans. Depending on your answers, you may also need a quarterly network scan. Clover notes this happens for some merchants based on their answers.
  5. Submit the attestation. The Attestation of Compliance is the document that confirms the questionnaire was completed and states your business's compliance status.
  6. Check the next statement. Make sure the non-compliance line is gone. If it is still there, ask your processor whether it received your validation and from which date the fee stops.
  7. Put the renewal date on your calendar. Validation is usually yearly, and the fee comes back if it lapses.

What it costs

There is no standard amount: each processor sets its own in its agreement. Check your agreement or fee schedule for the amount, the grace period before it starts and how it is billed. On your own statement, the line's amount times the number of months it has appeared is what it has cost you so far.

FAQ

Does the PCI Security Standards Council charge this fee?

No. The Council writes the standard. It says it does not manage compliance programs or impose any consequences for non-compliance; the card brands and acquirers do.

Do small businesses have to be PCI compliant?

Yes. The PCI Council says the standard applies to businesses of every size. Whether a small business has to validate, and how, is decided by the card brands and its acquirer.

Will the fee stop on its own?

Not usually. It is charged because your processor has no record of your validation, so it continues until you validate through your processor.

Which questionnaire do I fill out?

The one your processor or acquirer says fits how you take cards. The PCI Council tells merchants to ask the company they submit the questionnaire to.

Find every fee on your statement

Merchant Statement Analyzer is free. Upload last month's statement to the analyzer and see every line named and explained, including PCI fees.

Sources

See it on your own statement

Upload last month's processing statement. Your card sales, total fees and effective rate come first, then a free report that explains every fee line. You can also put your own logo and name on it, free.

Analyze a statement