PCI non-compliance fees: Costs, triggers, and how to clear them

Payments

Accept payments online, in person, and around the world with a payments solution built for any business – from scaling startups to global enterprises.

Learn more 
  1. Introduction
  2. Key takeaways
  3. What is a PCI non-compliance fee?
  4. Who pays PCI non-compliance fees and why?
  5. How much do PCI non-compliance fees cost?
  6. What triggers a PCI non-compliance fee?
  7. What are the steps to stop paying PCI non-compliance fees?
  8. Is paying for PCI compliance worth avoiding non-compliance fees?
  9. How Stripe Payments can help

If you haven't completed your merchant agreement's Payment Card Industry Data Security Standard (PCI DSS) validation, you may be liable for a PCI non-compliance fee. This is an extra monthly charge your acquiring bank or payments provider adds to your processing costs. It recurs every billing cycle and stays on your statement until you submit proof that you've met the PCI DSS compliance standard. PCI non-compliance fees can range from US$25–US$100K per month depending on how long your business has been non-compliant.

Below, we'll cover who ultimately pays these fees and why, how their typical costs compare to the penalties they're meant to prevent, and what can trigger a charge.

Key takeaways

  • PCI non-compliance fees are charged by acquiring banks, not card networks. They're a way to offset the liability they carry for unvalidated businesses.

  • The fee itself is minor compared with the card network penalties and breach costs it's designed to protect against.

  • Completing the right Self-Assessment Questionnaire (SAQ) and reducing how much cardholder data touches your own systems are the fastest ways to clear the charge.

What is a PCI non-compliance fee?

A PCI non-compliance fee is a monthly charge that a business's acquiring bank or payments provider adds when that business hasn't completed the PCI DSS validation its merchant agreement requires.

Different businesses have different validation requirements. Card networks sort businesses into four levels based on annual transaction volume: a business processing millions of transactions a year faces stricter documentation than one processing a few thousand. Businesses that handle card data directly on their own servers carry more compliance responsibility than those routing payment fields through a hosted or tokenised solution, since the scope of what needs auditing shifts with each setup.

Who pays PCI non-compliance fees and why?

The business pays PCI non-compliance fees. Even though the card networks set the standard, acquiring banks carry the liability when a non-compliant business gets breached, so they push that risk downstream through the merchant agreement.

Some payment processors bundle compliance monitoring into the standard agreement and start billing automatically after a grace period, while others require an opt-in program and only charge businesses that ignore repeated notices.

How much do PCI non-compliance fees cost?

Acquiring banks typically charge somewhere between US$25 and US$50 per month for the first few months or until the business validates compliance. If the issue isn't resolved after six months, fines can jump up to US$5,000–US$100,000 per month.

If a breach occurs while the business is non-compliant, the business can face far more serious consequences. Card networks can levy penalties ranging from US$5,000–US$100,000 depending on the network, the severity of the breach, and how long the business went without validating compliance. A business found non-compliant after a breach can also lose the ability to accept certain card types, face forensic investigation costs running into the tens of thousands, and cover the cost of reissuing cards to every customer affected.

What triggers a PCI non-compliance fee?

PCI non-compliance fees are tied to documentation and process, not to whether a breach has occurred.

The following scenarios can trigger a fee:

  • Missed SAQ deadline: Acquiring banks or their compliance vendors typically set a deadline for submitting a completed Self-Assessment Questionnaire (SAQ). Once that date passes with no submission, the fee activates on the next billing cycle.

  • Expired attestation of compliance: PCI compliance is revalidated annually. Letting an Attestation of Compliance lapse triggers the same fee as never having completed one.

  • Failed vulnerability scan: Businesses in higher compliance levels need quarterly network scans from an Approved Scanning Vendor. A failed or skipped scan can trigger the fee on its own, independent of the SAQ status.

  • Change in processing volume or method: Moving into a higher compliance tier, or switching from a hosted checkout to a setup where the business handles more card data directly, can reset compliance requirements and restart the clock on validation.

What are the steps to stop paying PCI non-compliance fees?

Eliminating the fee comes down to completing whichever validation path applies to the business, then keeping it current.

Here's how:

  1. Confirm the merchant level and applicable SAQ: Compliance level is set by annual transaction volume and how directly the business handles card data. The compliance level determines which of the eight SAQ types applies. A business using a fully hosted checkout where card fields never touch its own servers usually qualifies for SAQ A, the shortest form. One handling card data more directly faces a longer questionnaire covering network segmentation, encryption, and access controls.

  2. Reduce scope before filling anything out: The less of the cardholder data environment (CDE) a business touches directly, the simpler the applicable SAQ. Routing payment fields through a hosted iframe or tokenisation service shifts the burden of securing raw card numbers onto the provider handling that data, which often drops a business down to SAQ A.

  3. Complete the SAQ and any required scans: Answer the questionnaire honestly, run a vulnerability scan through an Approved Scanning Vendor if the business's level requires one, and sign the Attestation of Compliance.

  4. Submit it to the processor or acquiring bank, not just the card networks: The fee comes from the bank, so the bank needs the documentation directly, usually through whatever compliance portal it uses to track merchant status.

  5. Set a recurring reminder for revalidation: Compliance expires annually. The fastest way back into non-compliance is treating this as a one-time task instead of a yearly one.

Because Stripe stores and processes cardholder data on behalf of the businesses using it and has a PCI DSS Level 1 certified infrastructure, businesses that route card data entirely through Stripe can reduce their PCI scope. That doesn't remove the business's own responsibility to submit an SAQ. It changes which questionnaire applies and how much of the cardholder data environment falls inside the business's own audit scope.

Is paying for PCI compliance worth avoiding non-compliance fees?

The math almost always favours compliance. Completing an SAQ A, for a business already using a hosted payments setup, often takes under an hour. Stack that against the range of card network penalties after a PCI breach, plus forensic costs and the damage to customer relationships when card details get exposed, and the case for compliance isn't close.

The businesses that stay non-compliant longest usually aren't weighing that trade-off deliberately. They just lose track of a form. That's the actual risk: not that PCI compliance is expensive, but that it's easy to forget about until a fee or a breach forces the issue. Checking merchant level, confirming which SAQ applies, and setting a yearly reminder costs far less than either outcome of letting it slide.

How Stripe Payments can help

Stripe Payments provides a unified, global payments solution that helps any business – from scaling startups to global enterprises – accept payments online, in person and around the world.

Stripe Payments can help you:

  • Optimise your checkout experience: Create a frictionless customer experience and save thousands of engineering hours with prebuilt payment UIs, access to 125+ payment methods and Link, a wallet built by Stripe.

  • Expand to new markets faster: Reach customers worldwide and reduce the complexity and cost of multicurrency management with cross-border payment options, available in 195 countries across 135+ currencies.

  • Unify payments in person and online: Build a unified commerce experience across online and in-person channels to personalise interactions, reward loyalty and grow revenue.

  • Improve payments performance: Increase revenue with a range of customisable, easy-to-configure payment tools, including no-code fraud protection and advanced capabilities to improve authorisation rates.

  • Move faster with a flexible, reliable platform for growth: Build on a platform designed to scale with you, with 99.999% historical uptime and industry-leading reliability.

Learn more about how Stripe Payments can power your online and in-person payments or get started today.

The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accuracy, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent lawyer or accountant licensed to practise in your jurisdiction for advice on your particular situation.

More articles

  • Something went wrong. Please try again or contact support.

Ready to get started?

Create an account and start accepting payments – no contracts or banking details required. Or, contact us to design a custom package for your business.
Payments

Payments

Accept payments online, in person, and around the world with a payments solution built for any business.

Payments docs

Find a guide to integrate Stripe's payments APIs.