Payments Glossary · Fees & Pricing

PCI Compliance Fee

Also called PCI program fee, data security fee, PCI service fee

A monthly charge for helping you meet card data security standards. Defensible if real services attach, pure margin if they don't.

What it is

The PCI compliance fee, sometimes called a PCI program fee or data security fee, funds a processor's PCI DSS support offering. Typical pricing is around $10 a month or roughly $120 a year, though it varies widely and some processors bill it annually at $99-$199. What should attach to it: approved scanning vendor (ASV) quarterly external scans for merchants who need them, a portal for completing the annual Self-Assessment Questionnaire, breach warranty coverage, and human support to get you through the questions. Those services have real costs. PCI DSS v4.0.1 raised the stakes. The future-dated requirements became mandatory March 31, 2025, and two of them dominate e-commerce conversations: Requirement 6.4.3 requires an inventory of all payment page scripts with written business justification and integrity assurance, and Requirement 11.6.1 requires change- and tamper-detection on payment pages evaluated at least weekly. Both apply even when card fields are hosted by a third party, because the merchant still controls the top-level browser context. The SAQ A eligibility change is the practically important one for small e-commerce merchants. Per PCI SSC FAQ 1588, a merchant using embedded iframes can satisfy the new eligibility criterion either by implementing 6.4.3 and 11.6.1 themselves or by obtaining written confirmation from a PCI DSS compliant payment processor that its embedded solution includes script attack protections. Merchants using a full redirect are not affected at all.

Why it matters to your business

At $10-$15 a month the fee itself is minor. What matters is whether you are getting the service, because the downside it protects against is existential for a small business. A breach at a ten-table restaurant does not produce a press release; it produces a forensics invoice larger than the annual profit. Equally important: knowing which SAQ applies to you can eliminate most of the work. A card-present merchant on validated P2PE hardware and an e-commerce merchant using a full redirect to a processor-hosted page have dramatically smaller scope than a merchant with a custom checkout - and most merchants have never been told which category they are in.

Where it gets contested

The fee is defensible only if real services attach - ASV scanning, an SAQ portal, breach warranty, support. Otherwise it is pure margin. That is the industry's own standard, and a large number of processors fail it. The two common abuses are worth naming precisely. First, charging the fee while providing nothing but an automated email once a year reminding you to complete an SAQ you will not understand. Second, charging both a PCI compliance fee and a PCI non-compliance fee - one for the program, one for not finishing the questionnaire the program was supposed to help you finish. That combination is the clearest tell of a processor optimizing for revenue rather than security. There is precedent for challenging these charges: a class action alleged that Banc of America Merchant Services charged unauthorized data security fees. And the underlying risk is real - breach forensics run $20,000-$100,000+, card reissuance $50-$90 per card, and major brand assessments $50,000 to $5 million or more. That is what PCI programs exist to prevent, which is exactly why a fee that funds nothing is worse than a rip-off; it is a false sense of security. An honest processor position, and one worth demanding: we will complete your SAQ with you, we will tell you which SAQ you actually need, and you will never pay a non-compliance fee.

How to check it yourself

Ask three questions. Which SAQ type applies to my business and why? Does my fee include ASV scanning and a breach warranty, and what is the warranty limit? Has my SAQ been completed for the current year, and can you send me the attestation? If your e-commerce site uses embedded payment fields, also request the processor's written attestation covering script attack protections under PCI SSC FAQ 1588.

Receipts

Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.

  • PCI compliance/program fees run about $10/mo or $120/yr and are defensible only if real services attach - ASV scanning, SAQ portal, breach warranty, support

    merchantmaverick.com ↗
  • PCI DSS v4.0/4.0.1 future-dated requirements including 6.4.3 and 11.6.1 became mandatory March 31, 2025

    cside.com ↗
  • PCI SSC FAQ 1588 provides two paths to satisfy the new SAQ A eligibility criterion, including written confirmation from a compliant payment processor

    blog.pcisecuritystandards.org ↗
  • A class action alleged Banc of America Merchant Services charged unauthorized data security fees

    classaction.org ↗