PCI DSS is the payment card industry’s data-security standard. Your payment setup affects which requirements and validation steps apply to your business.
Processors may bill a PCI program fee, a non-compliance fee, or both. A program fee can relate to services your provider offers. A non-compliance fee can indicate that the provider has not recorded the validation it requires. Neither label alone tells you whether the charge is correct or whether your business meets the applicable requirements.
Ask your provider what the fee covers, which contract term authorizes it, and what validation status it has recorded for your account. If it says validation is missing, ask for the specific next step and confirmation after completion.
Paying a fee does not replace completing the applicable security work. Start with the PCI Security Standards Council’s merchant resources and your provider’s requirements.
Analyze your statement to see the fee in the context of your other charges.
Questions about how this applies to your business?
Talk it through