PCI Non-Compliance Fee on Merchant Statement: How to Spot and Stop It
Found a PCI non-compliance fee on your merchant statement? This expert guide reveals how to identify these junk charges and eliminate them permanently.

The Cost of Silence: Understanding the PCI Non-Compliance Fee
A PCI non-compliance fee is a monthly penalty, typically ranging from $19.95 to $125, charged by payment processors when a merchant has not verified their adherence to the Payment Card Industry Data Security Standard (PCI DSS). This fee is entirely avoidable; it is not a government tax or a mandatory network cost, but rather a service-level penalty that functions as high-margin revenue for your processor. To eliminate it, you must complete a Self-Assessment Questionnaire (SAQ) or provide proof of a successful vulnerability scan through an Approved Scanning Vendor (ASV).
If you have been scanning your monthly merchant statements and noticed a recurring line item labeled "PCI Non-Compliance," "Monthly Non-Validation Fee," or simply "PCI Fee," you are likely paying for the privilege of being considered a security risk. In the industry, we often categorize these as "junk charges"—not because PCI compliance isn't important, but because the fee itself does nothing to improve your security posture. It is a penalty for administrative inaction, and for many processors, it is a significant profit center.
What Exactly is a PCI Non-Compliance Fee?
To understand the fee, you must understand the mandate. Every business that accepts, stores, or transmits credit card data is required to comply with the PCI DSS. This set of standards was created by the major card brands (Visa, Mastercard, AMEX, Discover) to reduce fraud and protect the ecosystem.
However, the card brands do not charge you a "non-compliance fee." Your payment processor does. When you sign a Merchant Service Agreement (MSA), you agree to maintain compliance. If you fail to provide proof of that compliance—usually on an annual basis—the processor triggers an automated monthly penalty.
From the processor's perspective, this fee offsets the risk they take by processing transactions for an unverified merchant. From a practical perspective, it is a nudge (or a shove) to get you to complete your paperwork. From a financial perspective, it is a drain on your bottom line that provides zero ROI.
How to Identify the Fee on Your Statement
Processors are rarely transparent about these charges. They often bury them in the "Fees" or "Other Charges" section of your statement, far away from your interchange costs or discount rates. Look for the following descriptions:
- PCI Non-Compliance Fee: The most direct label.
- Non-Validation Fee: Implies you haven't validated your SAQ.
- PCI Monthly Fee: Note that some processors charge a "PCI Program Fee" (which covers the cost of the compliance portal) alongside a "Non-Compliance Fee." You want to eliminate the latter.
- Monthly Maintenance/Security Fee: Sometimes used as a catch-all for various junk charges.
- Data Security Non-Comp: A common shorthand in legacy reporting systems.
If you see a flat fee between $19.95 and $125 that appears every month regardless of your processing volume, and it carries any of the above keywords, you are being penalized.
The Hidden Impact on Your Effective Rate
Most merchants focus on their "discount rate" (e.g., 2.5%), but the effective rate—the total cost divided by total volume—is the only metric that matters. For a small business processing $20,000 a month, a $99 PCI non-compliance fee adds roughly 0.50% to their effective rate. That is a massive hike for a charge that provides no actual service.
In high-risk processing sectors, these fees can be even more predatory. Because high-risk merchants already face higher barriers to entry, some processors tack on non-compliance fees as an expected part of the overhead, assuming the merchant won't find a better deal elsewhere. This is a mistake. Even in high-risk environments, compliance is manageable and fees are avoidable.
Why You Are Being Charged (Even if You Think You're Compliant)
There are three primary reasons a merchant sees a PCI non-compliance fee on their statement despite believing they have done everything right:
- Expiration: PCI compliance is not a one-time event. Your SAQ expires exactly one year from the date of completion. If you forget to renew, the fees resume automatically.
- Failed Scans: If your business is required to perform quarterly network scans (common for e-commerce or IP-connected terminals) and a single scan fails due to a vulnerability, you are considered non-compliant until the issue is patched and a clean scan is recorded.
- The Wrong SAQ: If you completed SAQ-A but your business model requires SAQ-D, the portal may flag you as incomplete.
A Step-by-Step Guide to Eliminating the Fee
Stopping these charges requires about 30 to 60 minutes of administrative work. Follow these steps to clean up your statement:
1. Access Your Compliance Portal
Every major processor partners with a PCI vendor (like Trustwave, ControlScan, or Sysnet). Your statement or welcome email should contain a link to this portal. If you cannot find it, call your processor’s support line and ask specifically for your "PCI login credentials."
2. Determine Your SAQ Type
Most small-to-mid-sized merchants fall into one of these categories:
- SAQ-A: For e-commerce merchants who outsource all card processing to a third party (like a hosted payment page).
- SAQ-B-IP: For merchants using standalone IP-connected terminals.
- SAQ-D: The most comprehensive form for merchants who store card data or have complex environments. Completing the right form ensures the fee is removed.
3. Schedule Your ASV Scans (If Applicable)
If your point-of-sale system or website communicates over the internet, you likely need a quarterly vulnerability scan. Ensure your ASV (Approved Scanning Vendor) has your correct IP addresses and that your firewall is configured to allow the scan.
4. Verify Receipt with the Processor
Once the portal shows "Compliant," do not assume the fees will stop. Take a screenshot of your compliance certificate and email it to your processor's billing department. Explicitly request that the PCI non-compliance fee be removed from the next billing cycle.
5. Request a Refund for Past Fees
This is where many merchants leave money on the table. If you have been non-compliant for six months but can prove you were actually following security protocols during that time, ask for a refund. While processors aren't legally obligated to return these fees, a firm request (especially if you mention looking at other providers) can often result in a 3-month credit.
When the Fee is Actually a Red Flag
If you complete your compliance, provide proof, and the processor continues to charge the fee—or if they charge a "PCI Program Fee" that is higher than $15 a month—it is time to re-evaluate the relationship. Transparent processors like those we recommend at OrbitBNK usually include PCI management in a small, flat annual fee or waive it entirely for compliant merchants. Permanent, high monthly fees are a sign of a provider that prioritizes their own margins over your business's health.
Strategic Advice for High-Risk Merchants
High-risk businesses (nutraceuticals, adult, gaming, etc.) are often told that non-compliance fees are "just part of the industry." This is false. While your underwriting may be more stringent, the PCI DSS requirements are the same for you as they are for a coffee shop. By maintaining strict compliance, you not only save money on fees but also protect yourself from the massive fines the card brands levy in the event of a data breach—fines that can easily reach six figures and lead to the termination of your merchant account.
Conclusion
PCI non-compliance fees are an unnecessary tax on the uninformed. They don't make you safer; they just make your processor richer. By taking an hour this week to log into your compliance portal and update your SAQ, you can instantly boost your bottom line and improve your business's security posture.
At OrbitBNK, we believe in radical transparency. If your statement is cluttered with cryptic fees and non-compliance penalties, let us take a look. We help merchants audit their processing costs to find hidden charges and transition to providers who value partnership over penalties.
Is your processor overcharging you? Upload your recent statement for a free OrbitBNK review and we will identify every junk fee hidden in your rates.
Frequently asked questions
What is a PCI non-compliance fee?+
It is a monthly penalty charged by your payment processor because you haven't provided proof (via an SAQ or scan) that your business follows PCI Data Security Standards.
How much should a PCI fee be?+
A typical non-compliance fee ranges from $19.95 to $125 per month. However, once you are compliant, this fee should be $0. Some processors charge a small annual 'PCI Program' fee of $50-$125, which is standard.
Can I stop paying the PCI fee immediately?+
Yes, by completing your annual Self-Assessment Questionnaire (SAQ) through your processor's compliance portal. Once you are marked 'Compliant,' the processor should stop the monthly penalty.
Is the PCI fee a government tax?+
No. It is a contractual penalty imposed by the payment processor. It is not mandated by the government or the IRS.
Why am I still being charged if I filled out the form?+
Your compliance may have expired (it must be done annually), you may have failed a required network scan, or the processor may not have updated their billing system to reflect your compliant status.
See your real processing math
Upload your merchant statement for a free, line-by-line OrbitBNK review.
Start The Clearing

