Millions of small businesses pay $30–$120 per month in PCI non-compliance fees that are completely avoidable. Here is everything you need to know.
PCI DSS — the Payment Card Industry Data Security Standard — is a set of security requirements established by Visa, Mastercard, American Express, and Discover to protect cardholder data. Any business that accepts credit or debit card payments is required to meet PCI DSS standards.
For most small businesses, PCI compliance simply means completing an annual Self-Assessment Questionnaire (SAQ) — a straightforward online form that asks about your payment environment and security practices. It typically takes 10–30 minutes to complete and is free.
A PCI non-compliance fee is a monthly charge — typically $30 to $120 — that your processor adds to your statement when you have not completed your annual PCI SAQ. It is not a fine from Visa or Mastercard. It is not a government penalty. It is a fee charged by your processor, to you, because you have not filed the free annual questionnaire.
To put it plainly: You are paying your processor $30–$120 every month because you have not filled out a free online form. This fee disappears permanently the moment you complete the questionnaire.
Most business owners who are paying a PCI non-compliance fee have no idea what it is. It appears on their statement under a technical-sounding name, they assume it is a required cost of accepting cards, and they move on. The processor has little incentive to tell them otherwise — this fee is pure profit with zero cost to deliver.
The SAQ is typically completed through a portal your processor provides access to. Many processors send an email with a link when the annual questionnaire is due — but this email often gets filtered as spam or ignored as a routine processor notification.
Businesses that have been paying this fee for 3–5 years without realizing it have paid $1,000–$6,000 in completely avoidable charges. It is one of the most frustrating discoveries business owners make when they finally audit their merchant statement.
If you cannot find the compliance portal, call your processor directly and ask: “How do I complete my PCI SAQ to remove the non-compliance fee?” They are required to provide you access to this process.
Separate from the non-compliance penalty, some processors charge an annual or monthly PCI compliance fee — a charge for the compliance monitoring service itself. This fee is more legitimate but still worth questioning. It typically ranges from $75–$150/year. Ask your processor whether this fee covers an actual service or is simply an administrative charge.
Once you complete your SAQ and achieve compliant status, the monthly non-compliance fee stops immediately. Most processors update your account within one billing cycle. If the fee continues appearing after you have confirmed compliant status, contact your processor in writing and request a refund of any fees charged after your compliance date.
PCI non-compliance fees are one example of a broader pattern in the payment processing industry: fees charged for things merchants do not understand, do not question, and therefore keep paying indefinitely. They are not the largest fee on your statement — but they are among the most avoidable.
When you get a full statement audit, PCI fees are often just the beginning of what gets uncovered.
We will review every line of your merchant statement, identify every avoidable fee, and show you exactly what a zero-fee program would save your business each month.
Get My Free Analysis →