Small Business Guides practical, sourced, free

Guides / Card processing fees

Card processing fees

What Is a PCI Non-Compliance Fee and How Do You Stop Paying It?

Why some processing statements show a monthly PCI non-compliance fee, what PCI DSS asks of a small business, and the steps that usually make the fee stop.

Short answer: A PCI non-compliance fee is a charge many processors add when they have no current PCI validation on file for your business, usually a yearly self-assessment questionnaire. Completing and submitting the validation your processor asks for often stops the fee; ask your processor exactly what it needs.

What PCI is

PCI DSS is the security standard for any business that accepts, stores or transmits card data. It is managed by the PCI Security Standards Council, founded by the major card brands (PCI Security Standards Council: merchants). Small merchants usually prove compliance once a year with a Self-Assessment Questionnaire (SAQ), and some also need a quarterly network scan.

Why the fee shows up

Processors are expected to make sure their merchants validate PCI compliance. When no current validation is on file, many processors charge a monthly non-compliance fee until it is. Some also charge a separate PCI program fee for access to their compliance portal; that one may stay even after you validate.

Line on statementUsually meansStops when you validate?
PCI non-complianceNo current validation on fileOften yes
PCI compliance / program feeFee for the processor's PCI programUsually no; ask

Free statement analysis

Send one recent card processing statement. CELER Merchants will work out your effective rate, explain every fee line, and tell you honestly whether you are already on a good deal.

How to stop paying it

  1. Call your processor and ask: "Which SAQ do I need, where do I submit it, and do I need a quarterly scan?"
  2. Log in to the compliance portal they name. Many walk you through the questions.
  3. Answer honestly. The right SAQ depends on how you take cards (terminal, online, keyed in).
  4. Save the confirmation and check the next statement. If the fee is still there, ask for it to be removed and refunded for any month after you submitted.
  5. Set a yearly reminder. Validation expires.

Go deeper

Already past the basics? CELER Merchants' PCI compliance basics covers scope, the self-assessment questionnaire in plain terms, and what changed with PCI DSS v4.0.1.

Frequently asked questions

Is a PCI non-compliance fee a legal requirement?

It is a processor fee, not a government fine. The fee terms come from your merchant agreement.

How long does the questionnaire take?

It depends on which SAQ applies. Simple card-present setups often have a shorter questionnaire than businesses that handle card data online.

Do I need PCI compliance if I use a payment app?

Yes, anyone who accepts cards is covered by PCI DSS, though using a provider that handles card data for you can make your own questionnaire simpler. Ask your provider which SAQ applies.

CELER Merchants. General information, not financial or legal advice. Fee names and terms differ between processors; always check your own merchant agreement.

More in Card processing fees