What Is a PCI Compliance Fee? Costs, Requirements, and Penalties

A PCI compliance fee is a recurring charge from your payment processor that covers its cost of administering your business’s compliance with the Payment Card Industry Data Security Standard. It is not a tax, and it is not a charge from Visa, Mastercard, or the government. Your processor keeps it. Most processors bill it monthly, commonly between $5 and $35, or as an annual lump sum in the range of $79 to $150.

Who Charges It and Why

When you accept credit or debit cards, your processor takes on some responsibility to the card brands for making sure the merchants in its portfolio handle card data safely. The compliance fee funds that work on the processor’s side.

In practical terms, you’re paying for access to the online portal where you complete your annual Self-Assessment Questionnaire, the ability to schedule and receive quarterly vulnerability scans, the processor’s internal team that tracks your compliance status, and the reporting the processor sends to card brands and acquiring banks to confirm its merchants meet security requirements.

The fee does not cover your own security costs. If you need to hire a consultant, buy a firewall, or upgrade your point-of-sale terminals, those expenses are separate. The compliance fee is purely the processor’s overhead for administering the program, and it applies to every card-accepting business regardless of size or current compliance status.

How Much You Should Expect to Pay

Fee amounts vary by processor and merchant size, but the ranges are fairly predictable. Monthly PCI compliance fees for small and midsize businesses typically run between $5 and $35. Annual billing options fall roughly between $79 and $150 per year. If your processor charges significantly more than these ranges without offering additional security services, that’s worth questioning.

Some processors fold the compliance cost into their overall rate structure and don’t break it out. Others list it explicitly, sometimes labeled “PCI Fee,” “PCI Compliance Fee,” or “Data Security Fee.” Check your merchant services agreement and your monthly statement to see exactly what you’re paying.

One line item to watch for is “PCI Non-Compliance Fee.” That is a different, higher charge that shows up when you haven’t completed the compliance work your processor is asking for. More on that below.

Where the Requirement Comes From

The compliance fee exists because of the Payment Card Industry Data Security Standard, usually called PCI DSS. Visa, Mastercard, American Express, Discover, and JCB created this framework in 2006 when they founded the PCI Security Standards Council. It is not a federal or state law. It is a contractual requirement baked into every merchant agreement. If you accept cards, you’ve agreed to follow it.

PCI DSS sets rules for how businesses must protect cardholder data, including account numbers, expiration dates, and security codes. The current version is PCI DSS 4.0.1, which became the sole active version after PCI DSS 4.0 was retired at the end of 2024. Fifty-one requirements that had been optional best practices became mandatory on March 31, 2025.

Your specific obligations depend on how many card transactions you process each year and how card data flows through your business. Most small businesses fall into Level 4 (fewer than 20,000 e-commerce transactions, or up to one million total transactions per year), which means the compliance process is manageable without outside help. Manageable still means you have to do it.

What You Have to Do to Earn the Fee

For most small and midsize merchants, staying compliant involves two recurring tasks: completing the right Self-Assessment Questionnaire once a year, and running quarterly vulnerability scans if your payment setup touches the internet.

The Self-Assessment Questionnaire

The Self-Assessment Questionnaire (SAQ) is a checklist where you attest that your business meets the applicable PCI DSS requirements. There are several versions, and which one you use depends entirely on how you process payments. Filling out the wrong one is a common mistake that can leave you technically non-compliant even after you’ve done the work.

  • SAQ A applies if you outsource all cardholder data handling to a PCI-compliant third party, like an online store that redirects customers to a hosted payment page.
  • SAQ B covers standalone, dial-out card terminals with no electronic storage and no internet connection.
  • SAQ B-IP is the same idea, but for standalone terminals that connect over the internet instead of a phone line.
  • SAQ C-VT is for merchants who manually key card numbers into an internet-based virtual terminal, common in call centers and mail-order businesses.
  • SAQ C covers payment systems connected to the internet that don’t store card data electronically.
  • SAQ D is the most comprehensive version. Required for any merchant that stores, processes, or transmits cardholder data and doesn’t fit into the categories above.

Your processor’s compliance portal usually walks you through a short set of questions to determine the right one.

Quarterly Vulnerability Scans

Any merchant with internet-facing systems in their card data environment must also pass an external vulnerability scan at least once every three months. The scan probes your public-facing IP addresses and web servers for known weaknesses. It must be performed by an Approved Scanning Vendor certified by the PCI Security Standards Council, and it must return a passing result for you to be considered compliant for that quarter.

Not every merchant needs these scans. If you use a standalone terminal with no internet connection, or if you fully outsource payment handling through a redirect, the scan requirement may not apply. But if any part of your payment environment faces the internet, assume you need it until your questionnaire tells you otherwise.

You should also have basic internal security policies in place: employee training on how to handle card data, an incident response plan, and documented procedures for granting and revoking access to payment systems. An investigator will ask about these first if a breach ever occurs.

What the Non-Compliance Fee Is and How to Stop It

If you haven’t completed your Self-Assessment Questionnaire or passed a required vulnerability scan, your processor will start billing a monthly non-compliance fee. This charge is separate from and higher than the standard compliance fee. For small businesses, the penalty commonly ranges from $20 to $100 per month, though some processors charge more.

The fee appears on your statement every month until you finish the outstanding compliance task. In most cases, completing the questionnaire and submitting it through your processor’s portal stops the charge immediately.

If you’re already seeing a non-compliance fee and you’ve actually completed the requirements, call your processor. The charge often appears because the processor’s system didn’t register your completed questionnaire, and a phone call gets it reversed.

Can You Negotiate or Avoid the Fee?

PCI compliance fees are not set in stone. They’re an administrative charge your processor decides to impose, and many processors will negotiate the amount or waive it entirely under the right circumstances.

Higher-volume merchants have the most leverage. If your business processes several million dollars annually, you represent enough revenue to the processor that asking for a fee reduction or waiver is a reasonable conversation. Come prepared with your last few months of processing statements, your current effective rate (total fees divided by total sales), and a clear picture of your transaction volume and chargeback history.

Smaller merchants have options too. Some processors don’t charge a separate PCI fee at all, bundling the cost into their base rates. When comparing processors, look past the headline transaction rate and add up all the ancillary charges. A processor with a slightly higher per-transaction rate but no PCI fee, no monthly minimum, and no annual fee may cost you less overall. Requesting interchange-plus pricing instead of tiered pricing also makes it easier to see exactly what you’re paying.

You can also shrink the compliance work itself, which sometimes lowers the fee attached to it. Tokenization replaces actual card numbers with meaningless substitute values immediately after authorization, so your systems reference the token for refunds and recurring billing while the real card number lives only with the token provider. Point-to-point encryption (P2PE) encrypts card data at the moment of swipe or tap inside a certified terminal and keeps it encrypted until it reaches the processor. A merchant using both may qualify for SAQ A or a similarly minimal questionnaire rather than the much longer SAQ C or D. Ask your processor about P2PE-certified terminals and tokenized payment solutions if your current setup requires a burdensome questionnaire or expensive quarterly scans.

Deducting the Fee on Your Taxes

PCI compliance fees, along with your other payment processing charges, qualify as ordinary and necessary business expenses and are deductible on your federal tax return. The IRS defines an ordinary expense as one that is common and accepted in your field of business, and a necessary expense as one that is helpful and appropriate for your operations. Card processing fees meet both tests for any business that accepts card payments.

Sole proprietors deduct these fees on Schedule C. Partnerships and corporations deduct them as business expenses on their respective returns. Keep your monthly processing statements as documentation, since they itemize PCI compliance fees, transaction fees, and any other processor charges.