PCI Non-Compliance Fee: What It Is and How to Remove It
The short version: it's a monthly penalty from your processor, not a card-network charge โ and in most cases you can make it stop with about an hour of paperwork.
The 30-second answer
A PCI non-compliance fee is a recurring penalty your payment processor charges because your business hasn't completed โ or the processor hasn't recorded โ its annual PCI DSS compliance validation. For most small businesses that validation is a Self-Assessment Questionnaire (SAQ), sometimes paired with a quarterly network scan.
Typical fees run $19.95 to $124.95 per month across the industry, with most merchants seeing charges in the $19.95โ$99 band. The fee is billed every month until your compliance status is on file, so a forgotten questionnaire quietly turns into hundreds of dollars a year.
To remove it: complete the SAQ in your processor's PCI portal, run the scan if your setup requires one, and confirm the processor recorded your compliant status. The fee should stop the next billing cycle. The step-by-step walkthrough is below.
Who Actually Charges the PCI Non-Compliance Fee
Here's the part most merchants never hear: the fee comes from your processor, not from Visa, Mastercard, or the PCI Security Standards Council. The card networks created the PCI DSS security standard, but they don't bill you a monthly penalty for missing a questionnaire โ your processor does, under a line item its own contract created. None of that money goes to the networks or the Council.
Processors defend the fee as an incentive to get merchants compliant, and there's some truth to that. But for many processors it functions as a profit line โ one that pays best when merchants stay confused, which is why it tends to sit unexplained on statements for years. It shows up in our guide to hidden processing fees for a reason: it's one of the most common junk charges we find, and one of the easiest to eliminate.
A quick effective-rate check makes the damage concrete: a $49.95 monthly penalty is nearly $600 a year before you've processed a single dollar. Run your own numbers through our processing fee calculator and you'll see how a couple of fixed monthly fees quietly inflate the rate you actually pay.
How to Get Rid of a PCI Non-Compliance Fee
You don't negotiate this fee away โ you remove its reason for existing. Five steps, and for most small businesses the whole thing fits inside an afternoon:
Find your processor's PCI portal
Most processors run compliance through an online portal, often operated by a third-party compliance vendor. Check your statement, welcome paperwork, or account dashboard for a "PCI" or "compliance" link โ or call the support number on your statement and ask exactly where to complete PCI validation.
Complete the Self-Assessment Questionnaire (SAQ)
The SAQ is a yes/no security questionnaire, and the version you file depends on how you take cards. Businesses using standalone terminals or a hosted online checkout get one of the short forms, and most finish in 30โ60 minutes. Answer honestly โ the questions map to real security practices, not trick wording.
Run the vulnerability scan, if your setup requires one
Some configurations โ mainly payment systems that touch the internet directly โ also require a quarterly network scan by an approved scanning vendor (ASV). The portal will tell you if this applies. Many terminal-based businesses skip this step entirely.
Confirm the processor recorded your compliance
Finishing the questionnaire isn't the finish line โ the processor's system marking you compliant is. Save your certificate of compliance and confirm your account shows a compliant status, especially if the portal is run by a third party.
Watch your next one or two statements
The fee should stop the next full billing cycle after your validation is recorded. If it appears again, call and reference your compliance date and certificate. It's also worth asking for a refund of recent charges โ some processors will credit a month or two when asked, though many won't volunteer it.
PCI Compliance Itself Is Worth Doing
Being annoyed at the fee shouldn't turn into ignoring the requirement. PCI DSS is a real security standard, created by the card networks, that every business accepting cards agrees to follow โ and it exists because cardholder data breaches are genuinely catastrophic for small businesses. A breach can mean forensic investigation costs, card-network fines, customer notification expenses, and liability for fraud losses, any one of which dwarfs a monthly fee.
So the move isn't to fight PCI โ it's to complete it. The questionnaire walks through common-sense practices you mostly already follow: protecting card data, securing your network, controlling who can access payment systems. For the definitions behind the acronyms โ SAQ, PCI DSS, tokenization โ our merchant services glossary covers each one in plain English.
Red Flags Around PCI Fees
The fee itself is common. These patterns around it are the ones that should make you look harder at your processor:
A compliance process that's hard to complete
A portal you can't find, a questionnaire that resets, support reps who can't tell you which SAQ applies. A recurring penalty only keeps billing while you stay non-compliant, so friction in the process isn't always an accident.
"PCI program" fees charged even when you're compliant
Some processors bill a separate monthly "PCI compliance," "PCI program," or "security" fee whether or not you've validated. That's not a penalty โ it's a service charge, and it deserves scrutiny of its own. If you're paying both a compliance fee and a non-compliance fee at once, something is wrong.
A fee that survives your compliance date
If you validated in March and the fee is still on your June statement, the processor is billing a penalty for a condition that no longer exists. Call with your certificate in hand โ and if it still doesn't stop, that statement belongs in front of a second set of eyes.
How Payment USA Handles PCI Compliance
We think compliance should be something your processor helps you finish, not something it profits from you missing. Payment USA gives every merchant guided Self-Assessment Questionnaire completion and quarterly security scan assistance at no additional cost, so compliance actually gets done โ and unlike many processors, we never charge inflated PCI non-compliance penalty fees.
That's part of a broader pricing philosophy on our credit card processing accounts: every fee on the statement should have a name, a purpose, and a number you can verify. A penalty that exists because paperwork was made confusing fails all three tests.
PCI Non-Compliance Fee Questions, Answered
Is a PCI non-compliance fee legal?+
Generally, yes. The fee is authorized somewhere in the merchant agreement you signed โ but it's not mandatory in any card-network sense. Visa and Mastercard don't require it and don't receive it. Because it's a contract term rather than a regulation, the practical fix isn't a dispute โ it's completing your validation so the trigger goes away.
Can I get past PCI non-compliance fees refunded?+
Sometimes, partially. Once you're validated, it's worth calling and asking for a credit โ some processors will refund a month or two of charges to keep the relationship. But most treat past charges as final, which is why the fee gets expensive: merchants commonly discover it years in, after hundreds or thousands of dollars have already gone out.
How long after I become compliant does the fee stop?+
Typically the next full billing cycle after your compliant status is recorded in the processor's system. Completing the questionnaire and the processor registering it are two different events, so confirm your account status rather than assuming. If the fee appears on the second statement after your compliance date, call and escalate.
What's the difference between a PCI compliance fee and a PCI non-compliance fee?+
A PCI compliance fee is a recurring service charge some processors bill for running their compliance program โ portal access, scan tools, sometimes breach insurance. A PCI non-compliance fee is a penalty for not completing validation. Completing your SAQ removes the penalty, but a compliance fee may remain โ and its size varies wildly between processors, so it's worth comparing what you pay against what you actually get.
Wondering What Else Is Hiding on That Statement?
A PCI penalty rarely travels alone. Send us one recent statement and we'll find this fee and every other junk fee on it โ statement fees, batch fees, downgrade surcharges, "regulatory" charges โ each one named, priced, and explained. If your statement is clean, we'll tell you that too.