What is the PCI Compliance Fee on your merchant statement?

PCI Compliance Fee shows up under more than one name depending on your processor. Here is what it actually is, who charges it, and whether you can get rid of it.

The short answer

A PCI compliance fee is a recurring charge, usually monthly or annual, that processors bill to cover the cost of the Payment Card Industry Data Security Standard (PCI DSS) program, the security requirements every business that accepts card payments must follow. It funds the questionnaire, scanning tools, and administrative tracking behind that program.

Also appears on your statement as
PCI Fee PCI Program Fee Data Security Fee Compliance Service Fee

Processor markup

Charged byCost typeTypicallyNegotiable
Processor or ISOProcessor markup$79-$120/yrSometimes

Who charges it, and is it a pass-through cost or a markup?

Your processor or ISO sets and collects this fee. PCI DSS itself is a real, industry-wide security standard maintained by the PCI Security Standards Council, so the underlying compliance requirement is legitimate. But the specific dollar amount your processor charges you for administering it is not set by the council or the card networks. It's a business decision by your processor, which makes the fee a processor markup even though the security program behind it is real.

What the fee is supposed to fund

In principle, this fee pays for real things: hosting the online questionnaire portal, running the vulnerability scans some businesses are required to complete, and, at some processors, a baseline of breach assistance or insurance if cardholder data is ever compromised on your systems. Whether what you're charged reflects that actual cost is a separate question, and it's one worth asking your processor directly, since the answer varies enormously between providers. A single-location retail business using a standard terminal creates very little compliance administration work, and there's a reasonable argument that a fee sized as if you were a large, complex business isn't proportionate to that. Processors that build compliance support into their base pricing rather than billing it separately are effectively arguing this shouldn't be its own profit center, which is worth keeping in mind if you're comparing quotes from multiple processors side by side.

What it typically costs

Processors bill this fee monthly or annually, and the amount is set by each processor's own program rather than a standard rate published anywhere. Industry sources commonly cite this fee in the $79 to $120 a year range, or roughly $7 to $13 a month if billed monthly. Because the underlying compliance requirement is the same regardless of which processor administers it, this is a fee worth comparing directly if you ever request quotes from other processors. A wide difference between quotes for the same requirement is a useful data point.

Can you get rid of it?

Sometimes. A handful of processors, especially newer, flat-rate platforms, build compliance support into their base pricing and don't charge separately for it. If yours does charge separately, it's worth asking whether the fee can be waived, particularly if you're a low-volume or single-location business where the administrative cost of tracking your compliance is minimal. Even where it can't be removed entirely, confirming you're not also being charged a separate non-compliance penalty on top of it is worth checking.

What to check on your own statement

  1. Confirm this charge is the standard, recurring compliance fee and not the separate non-compliance penalty.
  2. Check whether it bills monthly or annually, since some processors mask an annual charge as a period line item.
  3. Ask your processor exactly what the fee covers beyond the PCI questionnaire itself.
  4. Ask directly whether it can be waived or reduced for your account.
  5. If shopping other processors, ask each one for their PCI compliance fee as a specific line item so you can compare them directly.

Frequently asked questions

What is a PCI compliance fee?

A recurring charge, usually monthly or annual, that processors bill to cover administering the PCI DSS security program that all card-accepting businesses must follow.

Is the PCI compliance fee required by law?

The underlying PCI DSS security standard is an industry requirement from the card networks, not a law. The specific fee your processor charges for administering it is a business decision, not a legal mandate.

Can I avoid a PCI compliance fee entirely?

Some processors, particularly flat-rate platforms, include compliance support in their base pricing with no separate line item. Others charge it separately and may or may not waive it on request.

What's the difference between a PCI compliance fee and a PCI non-compliance fee?

The compliance fee is the standard recurring charge for the program itself. The non-compliance fee is an additional penalty charged only when you haven't completed the required questionnaire.

Does a bigger business pay a higher PCI compliance fee?

Not necessarily, and that's part of what makes the fee worth questioning. The underlying PCI DSS requirement scales with how you handle card data, not with your revenue, so a small business using a simple terminal and a much larger business using the same terminal setup can face similar underlying compliance obligations. If your fee seems to scale with your processing volume rather than your actual compliance complexity, that's a sign it may be structured more as a percentage-based revenue fee than a genuine cost-recovery charge, which is worth raising directly with your processor.

We'll read it for you - free

Send us a recent statement and we'll calculate your effective rate, flag the junk fees, and tell you honestly whether you can do better.

Get My Free Rate Review