
Quick Answer: A PCI non-compliance fee is a recurring monthly charge, typically $10 to $100 for most small merchants, added to your statement when your processor has not received confirmation that you completed your required annual PCI compliance steps. For the large majority of small businesses, this means the PCI DSS Self-Assessment Questionnaire has not been completed for the current period. The fee is removed, usually starting the next billing cycle, once compliance is confirmed. It is separate from, and far smaller than, the much larger penalties card networks can levy for serious or prolonged violations.
You are scanning your monthly statement and a line item catches your eye: "PCI non-compliance fee." It has probably been there for a few months. Most merchants who see this for the first time assume it is a mistake or a scare tactic. In most cases, it is neither. It is a real, recurring charge tied to a specific, usually simple, outstanding requirement.
What Exactly Is a PCI Non-Compliance Fee?
It is a monthly charge your processor or acquiring bank adds to your account when you have not confirmed compliance with the Payment Card Industry Data Security Standard, commonly called PCI DSS. This is different from a PCI compliance fee, which is a separate, smaller charge, often $79 to $120 a year or roughly $7 to $13 a month, that some processors charge simply for providing compliance tools and portal access, regardless of your status.
The non-compliance fee is specifically punitive. It exists to prompt action, and it continues every month the underlying requirement remains unmet. For the overwhelming majority of small merchants, that requirement is a single annual document: the PCI Self-Assessment Questionnaire, or SAQ.
How Much Does a PCI Non-Compliance Fee Actually Cost?

For most small businesses, which fall into PCI compliance Level 4, the fee is smaller than the internet's more alarming headlines suggest.
What most small merchants actually see:
Typical PCI non-compliance fees for small merchants run $10 to $100 per month, occasionally up to $250 for certain processors or account types. This is the number that shows up on the statement of a Level 4 merchant who simply has not completed their annual SAQ.
What is often confused with this:
Separately, card networks can levy much larger monthly penalties, ranging from $5,000 to $100,000 or more, that escalate the longer a violation goes unresolved. These are enforcement fines reserved for serious or prolonged non-compliance, typically at higher merchant volume levels, or following an actual data breach. A small retail store that has simply not clicked through its SAQ this year is not looking at this category of fee. Conflating the two creates unnecessary alarm; they are genuinely different mechanisms aimed at very different situations.
Why Does This Fee Keep Showing Up Every Month?
Because the underlying requirement has not been satisfied, and the fee is designed to recur until it is. It is not a one-time penalty. Every billing cycle your processor checks your compliance status, and every cycle it remains unresolved, the fee is applied again.
This is why merchants often report the fee "appearing out of nowhere," when in reality it has usually been quietly recurring for months before it was noticed. Completing the SAQ stops future charges from being applied, though it typically does not retroactively refund fees already charged for prior periods, since those covered periods when the requirement genuinely was not met.
What Changed With PCI DSS in the Last Two Years?
As of March 31, 2025, PCI DSS version 4.0.1 became the only accepted standard, with all previously "future-dated" requirements now fully enforceable rather than optional best practices. For most small Level 4 merchants using a modern, properly configured POS system or payment gateway, this shift has been largely invisible day to day, since much of it concerns technical controls that a compliant system already satisfies. The practical requirement for a small merchant, completing the annual SAQ and, where applicable, a quarterly vulnerability scan, has not fundamentally changed in structure, even as the underlying standard behind it has been updated.
How Do I Actually Remove a PCI Non-Compliance Fee?

Step 1: Log in to your processor's compliance portal. Most processors provide a dedicated PCI compliance section showing your current status and a direct link to the outstanding questionnaire.
Step 2: Complete the Self-Assessment Questionnaire. For most small merchants using a standard POS or terminal setup, this takes 15 to 45 minutes and covers straightforward yes-or-no questions about how your business handles card data.
Step 3: Confirm submission and watch your next statement. Once submitted, the fee typically stops being applied starting with the next billing cycle. It is worth confirming with your processor directly whether any fee already charged for the current period will be reversed, since policies vary.
Step 4: Call your processor if the fee persists. If the fee continues appearing after you have completed the questionnaire, contact your processor directly. This is sometimes a processing delay on their end rather than an issue with your submission.
Ready to Get This Fee Off Your Statement?
If you have a PCI non-compliance fee on your statement, resolving it is usually a fast, straightforward fix, not a complicated process. Rapid Payments helps merchants confirm their current compliance status and get it resolved correctly.



