Skip to content
All insights

PCI Compliance Fees: What You Are Paying For

The line item is often a processor program, not a PCI SSC invoice. Separate the fee from the obligation.

A PCI compliance fee on your merchant statement is a processor or acquirer program charge, not an invoice from the PCI Security Standards Council. A PCI non-compliance (or non-validation) fee is a different line: a penalty for not completing the annual self-assessment your provider requires. Paying either amount does not, by itself, mean you have met PCI DSS. The standard is the obligation. The fee is how your provider bills for a portal, a scan, a questionnaire, or for your failure to use them.

The fee is not the standard

PCI DSS is the Payment Card Industry Data Security Standard: technical and operational requirements for any entity that stores, processes, or transmits cardholder data, or that could affect the security of that data. The PCI Security Standards Council writes and maintains the standard. It does not send you a monthly bill.

The founding payment brands (American Express, Discover, JCB International, Mastercard, and Visa) each run their own compliance programs. Your acquirer, the bank or ISO/MSP that boarded you, is usually the party that tells you how to validate and what happens if you do not. PCI SSC's merchant FAQ is explicit: questions about who must validate, and how, go to the payment brands or the acquirer, not to the Council.

That split is why the statement line is so easy to misread. "PCI compliance fee" sounds like a tax or Council dues. It is neither. It is program pricing in the same family as statement fees and batch fees: a fixed line that belongs in how you read the statement, not a pass-through from PCI SSC.

Two line items that get confused

Statements use a zoo of names. Group them into two buckets before you argue about the amount.

Program or "compliance" fees. Labels include PCI compliance fee, PCI DSS compliance admin fee, PCI program fee, or annual PCI. This is usually the charge for access to a self-assessment portal, sometimes a vulnerability scan, sometimes a managed questionnaire the provider files on your behalf. It can be monthly, annual, or both.

Non-compliance or non-validation fees. Labels include PCI non-compliance, PCI non-validation, non-receipt of PCI validation, or PCI non-compliance after 90 days. This is a penalty for not completing the Self-Assessment Questionnaire (SAQ) or Attestation of Compliance (AOC) on the provider's calendar. It is not a finding that you were breached. It is a finding that the paperwork did not land.

Some books bill only the program fee when you are current, and swap it for a larger penalty when you lapse. Some bill the program fee every month and add the penalty on top. Ask which waterfall you are on. Do not assume the cheaper line replaced the expensive one.

Two PCI lines, two jobs
Program / compliance fee
  • Processor or acquirer program charge, not a PCI SSC invoice.
  • Often billed monthly or annually for a portal, SAQ tool, or scan.
  • Paying it does not prove you met PCI DSS.
Non-compliance / non-validation fee
  • A penalty for missing the annual self-assessment or attestation.
  • Usually larger than the program fee, and sometimes billed on top of it.
  • Ask in writing what filing status stops it.

What the program fee covers, and what it does not

Ask for the inclusion list in writing. A useful program fee buys access to the correct SAQ, a place to submit the AOC, sometimes an Approved Scanning Vendor (ASV) scan if your SAQ requires one, and reminders when the annual window opens. It does not buy a PCI SSC certificate, a Qualified Security Assessor (QSA) on-site review unless that work is separately contracted, immunity from a breach, or proof that your terminals, e-commerce scripts, or remote-access vendors meet the current standard.

PCI DSS Self-Assessment Questionnaires are validation tools for SAQ-eligible merchants, with several SAQs matched to how you store, process, or transmit cardholder data (PCI SSC FAQ 1215, April 2024). Which SAQ you are eligible for is a question for the acquirer, not a guess from the statement line. A shop on a point-to-point encrypted terminal and an e-commerce shop with an iframe checkout are not filling out the same form.

What the non-compliance fee is

The non-compliance line is the one that should make you stop scrolling. Paying PCI non-compliance fees is one of the nine signs you are overpaying: it is a paperwork penalty, and for most small merchants it is avoidable.

It is not a published PCI SSC fine schedule. Payment brands and acquirers set the commercial consequence of missing validation. The processor then expresses that as a monthly or annual fee on your statement. Completing the SAQ through the provider's portal, and getting confirmation that the AOC was accepted, is the usual off-switch. If you have filed and the line is still there, treat it as a billing error until someone shows a rejected questionnaire or a mismatched legal name.

Do not confuse this fee with forensic work or brand-imposed assessments after an account-data compromise. Those are a different conversation, and they do not show up as a routine "PCI" line.

How the lines move effective rate

Fixed PCI lines look small next to interchange. They are not small if they sit there twelve months and you never file.

Illustrative. A merchant processes $40,000 a month in card volume. The statement shows a $9.95 PCI program fee and a $39.95 PCI non-validation fee in the same month.

LineAmount
PCI program fee$9.95
PCI non-validation fee$39.95
Combined PCI lines$49.90
Share of $40,000 volume0.12%
Annualized if both persist$598.80
Key figure
$598.80/yr
Illustrative: $9.95 program fee plus $39.95 non-validation fee, billed every month, on a merchant who never files the SAQ.
$49.90 x 12. Confirm the actual lines on your statement.

That $598.80 is not interchange and not a network assessment. It is program pricing plus a penalty. Put it in the total-fees numerator when you compute effective rate. Then ask which of the two lines you can turn off this month. If only the program fee remains after you validate, the same merchant is looking at $9.95 x 12 = $119.40 a year: still a real cost, still part of effective rate, but no longer a silent 12-basis-point leak on top of a skipped questionnaire.

Paying the fee is not being compliant

PCI DSS is intended for all entities involved in payment processing, including merchants, regardless of size or transaction volume (PCI SSC merchant resources). Whether a small merchant must validate (file an SAQ or a Report on Compliance) is a payment-brand and acquirer decision. Being billed a PCI fee is evidence of neither.

You can pay the program fee and still be out of compliance if you never completed the SAQ. You can pay the non-compliance fee while running a tighter shop than a merchant who clicked through the wrong questionnaire. You can be current on the processor's portal and still in scope for requirements the questionnaire missed, because the wrong SAQ was used. Encryption, tokenization, and a listed point-to-point encryption (P2PE) solution can reduce how many PCI DSS requirements apply. They do not take you out of PCI DSS. PCI SSC is clear: encryption alone does not remove the need for the standard in that environment.

What changed on 31 Mar 2025

PCI DSS 4.0 added 64 new requirements, of which 51 were future-dated and became mandatory on 31 Mar 2025 (PCI Security Standards Council, 20 Aug 2024). The limited revision PCI DSS v4.0.1 did not move that date, and it added no new requirements (PCI SSC, 11 Jun 2024). PCI DSS v4.0 itself was retired on 31 December 2024; v4.0.1 is the active version of the standard.

None of that is a new statement line by itself. If your processor raised a PCI fee in 2025 or 2026 and blamed "PCI 4.0," ask which extra work they now perform. A portal refresh is not 51 requirements. The operational change lives in how you take cards, not in a renamed admin fee. We walk through the mandate itself in PCI DSS 4.0 for merchants.

What to do this month

  1. Find every PCI-named line on the last twelve statements. Note monthly versus annual, and whether two PCI lines ran in the same period.
  2. Ask the provider, in writing: what the program fee includes, which SAQ they have you on, and what filing status stops the non-validation line.
  3. Complete the SAQ that matches how you actually take cards. If the portal's default does not match your environment (card-present versus keyed versus e-commerce), say so before you attest.
  4. Recompute effective rate with those lines in the numerator. If you want the as-billed sheet instead of a highlighter, run the analyzer.

The goal is not a $0 PCI line. The goal is to stop paying a penalty for skipped paperwork, to know what the remaining program fee actually buys, and to keep the security work (the part PCI DSS is for) separate from the billing work.

FAQ

What is a PCI compliance fee on a merchant statement? It is a processor or acquirer program charge, usually monthly or annual, for a self-assessment portal, a scan, or a managed questionnaire. It is not an invoice from the PCI Security Standards Council. Paying it does not, by itself, mean you have met PCI DSS.

Is paying a PCI fee the same as being PCI compliant? No. PCI DSS is the security standard. The statement line is how your provider bills for a validation program, or for your failure to complete it. You can pay the fee and still be out of compliance, or complete the SAQ and still owe a program fee for the portal.

What is a PCI non-compliance fee? A penalty line for missing the annual Self-Assessment Questionnaire or Attestation of Compliance on your provider's calendar. It is not a finding that you were breached. Completing the matching SAQ, and getting written confirmation that the AOC was accepted, is the usual way the line stops.

Does the PCI Security Standards Council bill merchants directly? No. PCI SSC writes and maintains the standard. The founding payment brands run their own compliance programs, and your acquirer tells you how to validate. The PCI-named lines on a merchant statement are commercial program fees or penalties, not Council dues.

Do I still have to complete a Self-Assessment Questionnaire if I already pay a monthly PCI fee? Almost always, yes, if your acquirer requires validation. The fee is usually access to the tool, not a substitute for the attestation. Confirm which SAQ they have you on, and that it matches how you actually take cards.

How do I get a PCI non-compliance fee off my statement? File the SAQ and AOC the provider is waiting on, then ask in writing which validation status stops the penalty. If you have already filed and the line is still billing, treat it as a billing error until they show a rejected questionnaire or a name mismatch.

Sources

Questions about how this applies to your business?

Talk it through

Your next move

Clarity looks good
on your business.

Analyze a statement