Payments Glossary · Fees & Pricing
PCI Non-Compliance Fee
Also called PCI non-validation fee, non-compliance surcharge
A monthly penalty for not finishing your annual security questionnaire. No service attaches. It is almost always avoidable in an afternoon.
What it is
The PCI non-compliance fee is charged when a merchant has not completed and attested to a current PCI DSS Self-Assessment Questionnaire. Amounts range from $10 to $300 a month, with industry-typical pricing around $20-$30 a month. Nothing is provided in exchange. It is punitive by design. The trigger is almost never a security failure. It is a merchant who never completed a form. The SAQ for a typical small merchant is a yes/no questionnaire that takes twenty to sixty minutes with someone who knows which version applies, and the fee stops the month after attestation. Which SAQ you need determines how hard this is. A card-present merchant using validated P2PE terminals with no e-commerce generally files SAQ B-IP or SAQ P2PE. An e-commerce merchant using a full redirect to a processor-hosted page files SAQ A with no script requirements triggered. An e-commerce merchant using hosted fields or iframes files SAQ A only with evidence for the v4.0.1 eligibility criterion. A merchant touching card numbers in its own environment files SAQ D, which involves real cost and quarterly external scanning. Most small merchants are in the first two categories and have been billed as though they were in the last. Distinguish this fee from card brand PCI fines, which are a different animal entirely: those escalate from $5,000-$10,000 in months 1-3 to $50,000-$100,000 at seven months or more, and are reserved for serious unresolved failures, not paperwork.
Why it matters to your business
At $29.95 a month this is $359 a year for nothing. Over three years, more than a thousand dollars. It is the single most avoidable charge on a typical merchant statement and one of the most commonly paid. Worse, paying it usually means nobody has ever told you which SAQ applies to your business - which means you may also be carrying compliance scope, and real breach exposure, you don't need. Breach costs are not theoretical: forensics run $20,000-$100,000+ and card reissuance $50-$90 per card.
Where it gets contested
This is the cleanest example in merchant services of a fee that produces revenue without producing anything else. It costs the processor nothing to charge, has no service attached, and is triggered by the merchant's failure to complete a task the processor's own PCI program fee was supposedly funding help with. The pattern that deserves naming: a processor charges $10 a month for a PCI program, sends one automated compliance email a year to an address the owner does not check, and then charges $29.95 a month for non-compliance. Over a year that is $479 for a form. Merchants often discover it during a statement review two or three years in, having paid over a thousand dollars for nothing. The industry defense is that the fee incentivizes compliance and that acquirers face real network pressure to get merchants validated. There is a grain of truth in the second half. But an incentive that works would be accompanied by an outbound phone call, because a fee the merchant does not notice does not incentivize anything - it just accrues. The honest commitment, and one a merchant should demand: we will complete your SAQ with you, annually, so you never pay this fee. It costs a processor one support call a year to eliminate a charge that costs merchants hundreds.
How to check it yourself
Search your statement for the word 'non-compliance' or 'non-validation.' If it's there, call your processor today, ask which SAQ type applies to your setup, and complete it on the call. Then ask for a refund of the last 90 days - many processors will credit it rather than argue, and the ones that refuse have told you something useful.
Receipts
Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.
-
PCI non-compliance fees run $10-$300/month with industry-typical pricing $20-$30/month, are punitive, have no services attached, and are triggered by a merchant never completing the annual SAQ
securetrust.com ↗ -
Card brand PCI fines escalate from $5,000-$10,000 at 1-3 months to $50,000-$100,000 at 7+ months and are reserved for serious unresolved failures
merchantmaverick.com ↗ -
SAQ A applies without script requirements to e-commerce merchants using a full redirect; the new eligibility criterion applies only to embedded payment forms
blog.pcisecuritystandards.org ↗