What PCI compliance actually requires
PCI DSS (Payment Card Industry Data Security Standard) is a real security framework that every card-accepting business has to follow, covering things like not storing raw card numbers and keeping payment systems reasonably secure. For the overwhelming majority of small businesses, actually satisfying PCI compliance means completing a short annual self-assessment questionnaire (SAQ) through your processor's portal — usually a 10–15 minute task, not an audit.
The PCI non-compliance fee is what processors charge merchants who haven't completed that questionnaire — and it's specifically designed to be avoidable. It's not a cost of doing business; it's a penalty for an unfinished form.
How to eliminate it
If you're currently paying a monthly or annual PCI non-compliance fee, log into your processor's merchant portal (or call and ask directly) and complete the compliance questionnaire — most processors will remove the fee within a billing cycle or two once you're marked compliant. If you've already completed it and the fee is still showing up, that's worth a direct call, since it may simply not have been updated on the billing side.
Some processors also charge an ongoing 'PCI compliance fee' even to merchants who are compliant, framing it as a program cost rather than a penalty — that version is closer to a standard junk fee and worth pushing back on directly.
Common questions
What is a PCI non-compliance fee?
How do I stop being charged a PCI fee?
Is PCI compliance itself expensive?
See how this shows up on your statement.
Free, anonymous calculator — check your effective rate in 30 seconds. No statement needed.
Check my fees — free100% anonymous · Nobody will call you