PCI charges on merchant statements

PCI Compliance Fees Explained for Business Owners

Learn the difference between PCI DSS security requirements, processor PCI program fees, and PCI noncompliance charges on a merchant statement.

The short answer

PCI DSS is a security standard. A “PCI compliance fee” or “PCI noncompliance fee” on a merchant statement is an account charge administered through the processor, acquirer, or service provider. Those are related concepts, but they are not the same thing.

PCI DSS is about protecting payment account data.

The PCI Security Standards Council describes PCI DSS as a baseline of technical and operational requirements for protecting payment account data. It applies to entities involved in payment processing, including merchants, processors, acquirers, issuers, and service providers.

The Council also states that PCI DSS is intended for merchants regardless of size or transaction volume. A small merchant may have a simpler environment, but small size does not automatically remove the security responsibility.

A processor’s PCI fee is a separate account charge.

Processors and acquirers may run PCI programs directly or through a service provider. A statement may show a compliance-program fee, annual PCI fee, scanning fee, or another PCI-related charge. The merchant should ask exactly what service the charge covers and where it appears in the agreement or fee schedule.

The label alone does not establish whether the amount is reasonable, negotiable, required by the processor, or tied to an optional service.

A noncompliance fee may signal an unfinished validation step.

If the account is marked noncompliant, the processor may assess a recurring charge until the required questionnaire, scan, or other validation step is completed. The correct response is to identify the missing requirement and resolve it through the processor’s approved process.

Completing validation may remove a noncompliance charge, but it does not guarantee that every separate PCI program fee will disappear.

Can PCI fees be negotiated?

A processor-controlled PCI program or account fee may be open to discussion. A noncompliance fee may be avoidable once the merchant completes the applicable validation. No advisor should promise to eliminate a legitimate security requirement or tell a merchant to ignore PCI DSS.

What should a merchant ask?

  • Is this a compliance-program fee, a noncompliance fee, or a separate service charge?
  • What specific service or unfinished validation step does it represent?
  • Is the charge monthly, annual, or one time?
  • Where is it disclosed in the merchant agreement or fee schedule?
  • What changes after the merchant completes the required validation?

A free SPA statement review can identify how the charge appears within the broader processing account. Questions about technical PCI compliance should be directed to the merchant’s acquirer, approved compliance provider, or a qualified security professional.

Direct answers

Frequently asked questions

What is a PCI compliance fee?

A PCI compliance fee is generally an account charge from a processor, acquirer, or service provider for a PCI-related program or service. It is separate from PCI DSS itself, which is a payment-data security standard.

What is a PCI noncompliance fee?

A PCI noncompliance fee is an account charge that may be assessed when the processor or acquirer records the merchant as not having completed its required validation. The merchant should confirm what is missing and how the provider defines the charge.

Do small businesses have to comply with PCI DSS?

The PCI Security Standards Council says PCI DSS is intended for merchants regardless of size or transaction volume. Validation and reporting requirements are determined by the applicable payment brands, acquirer, or compliance program.

Can PCI fees be negotiated or removed?

A processor-controlled program or account fee may be negotiable, and a noncompliance fee may stop after required validation is completed. The underlying responsibility to protect payment data should never be treated as optional.

Primary sources