Card processing fees
What Is a PCI Non-Compliance Fee and How Do You Stop Paying It?
Why some processing statements show a monthly PCI non-compliance fee, what PCI DSS asks of a small business, and the steps that usually make the fee stop.
What PCI is
PCI DSS is the security standard for any business that accepts, stores or transmits card data. It is managed by the PCI Security Standards Council, founded by the major card brands (PCI Security Standards Council: merchants). Small merchants usually prove compliance once a year with a Self-Assessment Questionnaire (SAQ), and some also need a quarterly network scan.
Why the fee shows up
Processors are expected to make sure their merchants validate PCI compliance. When no current validation is on file, many processors charge a monthly non-compliance fee until it is. Some also charge a separate PCI program fee for access to their compliance portal; that one may stay even after you validate.
| Line on statement | Usually means | Stops when you validate? |
|---|---|---|
| PCI non-compliance | No current validation on file | Often yes |
| PCI compliance / program fee | Fee for the processor's PCI program | Usually no; ask |
Free statement analysis
Send one recent card processing statement. CELER Merchants will work out your effective rate, explain every fee line, and tell you honestly whether you are already on a good deal.
How to stop paying it
- Call your processor and ask: "Which SAQ do I need, where do I submit it, and do I need a quarterly scan?"
- Log in to the compliance portal they name. Many walk you through the questions.
- Answer honestly. The right SAQ depends on how you take cards (terminal, online, keyed in).
- Save the confirmation and check the next statement. If the fee is still there, ask for it to be removed and refunded for any month after you submitted.
- Set a yearly reminder. Validation expires.
Go deeper
Already past the basics? CELER Merchants' PCI compliance basics covers scope, the self-assessment questionnaire in plain terms, and what changed with PCI DSS v4.0.1.
Frequently asked questions
Is a PCI non-compliance fee a legal requirement?
It is a processor fee, not a government fine. The fee terms come from your merchant agreement.
How long does the questionnaire take?
It depends on which SAQ applies. Simple card-present setups often have a shorter questionnaire than businesses that handle card data online.
Do I need PCI compliance if I use a payment app?
Yes, anyone who accepts cards is covered by PCI DSS, though using a provider that handles card data for you can make your own questionnaire simpler. Ask your provider which SAQ applies.
CELER Merchants. General information, not financial or legal advice. Fee names and terms differ between processors; always check your own merchant agreement.