Payments Glossary · Risk & Compliance
PCI Non-Compliance Program
Also called PCI non-compliance fee, PCI non-validation fee, card brand PCI fines
The enforcement architecture behind PCI: a punitive monthly fee from your processor, and separately, card brand fines through your acquirer.
What it is
The PCI non-compliance program is the enforcement side of PCI DSS, and it has two distinct layers that merchants routinely conflate. Layer one is the processor's own monthly non-compliance fee, assessed when a merchant has not completed and filed a current Self-Assessment Questionnaire and Attestation of Compliance. Reported amounts range from roughly 10 to 300 dollars per month, with industry-typical figures around 20 to 30 dollars. It is separate from the PCI compliance or program fee, which is usually around 10 dollars a month and is meant to pay for scanning, a validation portal, support and sometimes a breach warranty. That distinction is the entire point. The program fee is a service charge, defensible when services genuinely attach. The non-compliance fee is punitive. No service attaches to it, and it is almost always triggered not by a security failure but by paperwork: the merchant never logged into a portal they were never told about. Layer two is card brand PCI fines, which are a different animal. These are levied by the networks through your acquirer for serious or unresolved failures, and reported ranges run from 5,000 to 10,000 dollars for one to three months of non-compliance, 25,000 to 50,000 dollars at four to six months, and 50,000 to 100,000 dollars beyond seven months. Those are rare and reserved for genuine failures. The monthly fee is routine. Behind both sits the actual risk, which is breach cost: forensics commonly reported at 20,000 to 100,000 dollars or more, card reissuance at 50 to 90 dollars per card, and major assessments running far higher.
Why it matters to your business
This is the single easiest line item to remove from your statement. Complete the questionnaire, file the attestation, and the fee stops, usually the following month. Some processors will credit back recent months if you ask and complete promptly, though they are not obligated to. If you are shopping processors, ask directly what the PCI program fee is, what it includes, what the non-compliance fee is, and whether anyone will help you complete the questionnaire. A provider that will not answer those four questions in writing is telling you something. This is education, not legal advice; your fee obligations are set by your merchant agreement.
Where it gets contested
The uncomfortable structure is that the same party that sells you compliance services also assesses the penalty for not having them, and profits either way. The industry defense is that the fee exists to motivate validation and to price the risk the acquirer carries for an unvalidated merchant, which is a real risk. The merchant-side view is that a fee that changes no behavior because the merchant does not know why it is there is not motivation, it is revenue. There is litigation precedent in the neighborhood. A class action alleged that a major acquirer charged unauthorized data-security fees. Nothing in the reporting we relied on establishes that non-compliance fees generally are unlawful, and we do not claim that. The gray area is disclosure quality. Many merchants can tell you their rate to two decimals and have no idea what their monthly fees total. A non-compliance fee that runs for three years is a four-figure transfer for a form that takes two hours.
How to check it yourself
Look at the fees section of your most recent statement for any line containing PCI, then log into your processor's compliance portal and check the date of your last attestation. If the attestation is expired or missing, complete it this week and watch next month's statement.
Receipts
Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.
-
PCI non-compliance fees run roughly 10 to 300 dollars per month with no services attached
securetrust.com ↗ -
Typical PCI compliance fee amounts and what they cover
merchantmaverick.com ↗ -
Class action allegations regarding unauthorized data-security fees
classaction.org ↗