What is the PCI Non-Compliance Fee on your merchant statement?

PCI Non-Compliance Fee shows up under more than one name depending on your processor. Here is what it actually is, who charges it, and whether you can get rid of it.

The short answer

A PCI non-compliance fee is a penalty charge added to your statement when your business has not completed the annual security questionnaire or scan required to confirm it meets Payment Card Industry Data Security Standard (PCI DSS) requirements. It's separate from, and added on top of, the regular PCI compliance fee.

Also appears on your statement as
PCI Non-Compliance Non-Compliance Fee PCI NC Fee Data Security Non-Compliance

Processor markup

Charged byCost typeTypicallyNegotiable
Processor or ISOProcessor markup$20-$100/moYes by becoming compliant

Who charges it, and is it a pass-through cost or a markup?

Your processor or ISO bills this fee, and it functions as an internal penalty rather than a charge required directly by the card networks or the PCI Security Standards Council. The underlying security standard is real and industry-wide, but the specific dollar penalty for being late or incomplete on your paperwork is set by your processor's own program. That makes the fee a processor markup, and a particularly avoidable one, since it exists specifically to be removed once you take action.

What the questionnaire actually involves

The Self-Assessment Questionnaire has several versions, labeled A through D, depending on how your business takes payments. A business using a modern point-of-sale terminal that never stores card data typically qualifies for one of the shorter versions, while a business with a custom payment integration may need a longer one. Most processors also require a quarterly network vulnerability scan if you store, process, or transmit cardholder data through any internet-connected system. For a typical small brick-and-mortar business using a standard terminal, the whole process is usually a short online form, not an audit, and can often be completed in well under an hour. The fee exists specifically to create urgency around finishing that form, so the fastest way to see it disappear is simply to log in and complete it rather than waiting for it to resolve on its own.

What it typically costs

This is charged monthly for as long as your account is marked non-compliant, and the amount is set entirely by the processor's own program rather than by any card network rule. Processor-level non-compliance penalties are commonly cited in the $20 to $100 a month range, with $20 to $50 the most frequently reported band. That's separate from, and far smaller than, the much larger penalties a card network or acquiring bank can impose directly if non-compliance leads to an actual data breach. Check your statement for how long the fee has been recurring. Because it's billed every cycle until resolved, even a small monthly amount adds up the longer the compliance questionnaire goes unfinished.

Can you get rid of it?

Yes, and this is one of the more straightforward fees to eliminate. Completing your PCI Self-Assessment Questionnaire (SAQ), the short form that confirms how your business handles card data, typically resolves non-compliance status within one billing cycle once it's submitted and accepted. Most processors provide a portal or a partner service to complete this. If you've already completed it and are still being charged, that's worth a direct call, since it usually means the completed questionnaire hasn't been logged on their end yet.

What to check on your own statement

  1. Confirm whether this fee is labeled “non-compliance” specifically, separate from a standard PCI compliance fee.
  2. Log into your processor's PCI portal (often linked from your statement or gateway dashboard) to check your compliance status.
  3. Complete the Self-Assessment Questionnaire if it shows incomplete or expired.
  4. Note how many billing cycles the fee has been charged, since it recurs until resolved.
  5. Call your processor once you've completed the questionnaire to confirm the fee will stop and ask about a refund for cycles charged after completion.

Frequently asked questions

What is a PCI non-compliance fee?

A penalty charge added to your merchant statement when your business hasn't completed the required annual PCI DSS security questionnaire or scan. It's billed on top of the regular PCI compliance fee and recurs until resolved.

How do I stop a PCI non-compliance fee?

Complete your PCI Self-Assessment Questionnaire through your processor's compliance portal. Once it's submitted and accepted, the fee typically stops within one billing cycle.

Is the PCI non-compliance fee the same as the PCI compliance fee?

No. The compliance fee is a standard recurring charge for the compliance program itself. The non-compliance fee is an additional penalty specifically for not completing the required paperwork.

Can I get a refund for PCI non-compliance fees already charged?

Sometimes. It's worth asking your processor directly once you've completed the questionnaire, especially if fees were charged after your completion date but before it was logged.

Does completing the questionnaire once mean I'm compliant forever?

No. PCI compliance is validated annually, not once, so the questionnaire needs to be resubmitted each year to stay current. Some processors will also require a fresh questionnaire if your business changes how it accepts payments, such as adding online ordering to a business that previously only took payments in person. Set a reminder for your compliance renewal date rather than waiting for a non-compliance fee to appear as the signal it's due, since by the time the fee shows up you've usually already missed at least one billing cycle.

We'll read it for you - free

Send us a recent statement and we'll calculate your effective rate, flag the junk fees, and tell you honestly whether you can do better.

Get My Free Rate Review