Security · Payment Processing

Two lines about PCI turn up on merchant statements. One is a program fee: a monthly or annual charge for the processor's compliance portal, scanning and, often, some breach cover. The other is a non-compliance fee, charged every month until you prove you meet the Payment Card Industry Data Security Standard, usually by filling in a self-assessment questionnaire. Both are easy to mistake for a card network penalty. Neither is one.
We read what the processors the site has reviewed publish about both fees, their merchant program guides, and the card networks' own rules, as they stood on 3 October 2026. Where a processor does not publish an amount, we say so.
Visa does impose assessments for PCI non-compliance, but not on merchants. Its Core Rules, in the April 2026 edition, say a non-compliance assessment is imposed by Visa on a member, which means a bank, and that the member is responsible for paying it 'regardless of whether it absorbs them, passes them on, or increases them in billing its customer'. The next sentence is the one to remember when you read your statement: 'A Member must not represent to its customer that Visa imposes any non-compliance assessment on its customer.' Visa adds, on its compliance program page, that assessments may be waived if a forensic investigation finds no evidence of non-compliance before and at the time of a data breach.
Mastercard works the same way. Its Security Rules and Procedures list assessments for failing to comply with its data security program of up to $25,000 for a first violation by Level 1 and Level 2 merchants and up to $10,000 for a first violation by a Level 3 merchant, rising with each repeat, and they are levied on Mastercard's customers, the banks.
Most small businesses sit in the lowest tier. Visa counts merchants processing more than 6 million Visa transactions a year as Level 1, 1 million to 6 million as Level 2, and everything below as Level 3; it merged its old Levels 3 and 4 on 25 April 2024 without changing what they must do. Mastercard still has four levels and its rulebook says neither its Level 3 nor its Level 4 merchants are required to validate compliance to Mastercard. The PCI Security Standards Council, which writes the standard, says whether a business must validate is at the discretion of the card brand or the acquirer, and tells small merchants to ask their acquirer. In practice, the acquirer is the one asking, and the processor's fee is how it enforces the question.
So the monthly non-compliance fee is a price, set by your processor, and it is a profitable one. EVO Payments, now part of Global Payments, listed PCI non-compliance fees among the fees whose decline 'could have a material adverse effect' on its business in its annual report for 2022.
Prices below are what each company, or a partner that resells its processing, publishes. A processor whose agreement says the amount is 'as set forth in the Application' has a fee; it just will not print it.
One case is unresolved. Payment Depot's own blog says it charges no PCI compliance fee, while NerdWallet's review, updated in January 2026, says it charges one, and our review reports $10 a month, rising to $19.99 for non-compliance, from independent reporting. Ask Payment Depot to put the answer in writing.
A non-compliance fee is charged every month until you validate. At Gravity's $19.95 that is $239.40 a year; at Dharma's $39.95, $479.40; at $59.95, $719.40; and at the $99.95 in PaySimple's Worldpay notice, $1,199.40. A business that stays unvalidated for two years pays it twice. For comparison, Gravity's annual program fee for the portal and scans is $115.
These fees are easy to miss because they are small next to the processing charges, and they often appear under a name that does not say PCI. If your statement carries a line such as 'non-receipt of PCI validation', 'PCI non-validation' or a compliance fee you do not recognise, our guide to reading a merchant processing statement shows where to look for it.
A monthly PCI program fee is easier to justify when it comes with something. Wells Fargo's $10 includes $100,000 in breach insurance, and PaySimple's Worldpay notice says validated merchants get up to $50,000 of breach costs waived: card brand audits, fines from those audits and card replacement costs. Heartland describes up to $100,000 of breach cover inside its monthly fee.
The cover matters because a breach is when the networks' assessments become real. Visa's What To Do If Compromised guide, in its June 2026 edition, sets a non-compliance assessment for each breach where the guide's incident-response steps are missed, such as reporting to Visa within three days, investigating and hiring a forensic investigator. For a Level 3 merchant it starts at $5,000, $10,000 or $25,000 depending on annual Visa transactions, and Visa can raise it to $100,000; for Level 1 and 2 merchants it is $100,000. Those are assessed on the acquiring bank, and your merchant agreement decides how much of it reaches you. A program fee that buys breach cover is insurance against costs like these. A non-compliance fee buys nothing at all.
Our guide to SAQ A eligibility for e-commerce covers what the shortest questionnaire now asks of online merchants, and our piece on fee increases and early termination covers what you can do when a new fee appears on a contract you have already signed.


