The short answer: there are two different fees hiding behind the name “PCI,” and confusing them costs businesses $240–$480 a year. The PCI program fee ($8–$15/month) is the processor’s charge for running its compliance program. The PCI non-compliance fee ($20–$40/month) is a penalty for not completing your annual security questionnaire — and it disappears the moment you complete it. One is a cost of doing business; the other is a fee you chose to pay.
See what these fees cost you per year — enter your statement in the Payment Processing Cost Analyzer and it breaks down every fee’s annual impact.
What PCI DSS actually is
The Payment Card Industry Data Security Standard is the card networks’ security rulebook: don’t store unencrypted card numbers, use secure passwords, keep software patched, and so on. If you take cards, you’re subject to it — there’s no opt-out.
For a typical small business (a card terminal, maybe a website), compliance mostly means completing an annual Self-Assessment Questionnaire (SAQ) — a yes/no checklist about how you handle card data — plus a quarterly network scan if you take cards online. It’s paperwork, not an engineering project.
Fee #1: The PCI program fee ($8–$15/month)
This is the processor’s charge for administering its PCI program: providing the SAQ portal, the vulnerability scans, breach assistance coverage, and the compliance tracking. It appears as “PCI compliance fee,” “PCI program fee,” or “data security fee.”
Is it legitimate? Mostly — it’s a real service with real costs behind it, and nearly every processor charges some version. Is it negotiable? Sometimes: processors will occasionally bundle or waive it to win an account, especially at higher volumes. It’s worth one ask during negotiation, but don’t burn leverage on it — bigger game exists elsewhere. How to Lower Credit Card Processing Fees
Fee #2: The PCI non-compliance fee ($20–$40/month) — kill this one
This penalty appears when you haven’t completed the annual SAQ. Different name, different nature: it’s not a service charge, it’s a fine — and it’s avoidable in under an hour.
The playbook that creates it:
1. You sign up. The processor mentions the questionnaire once, in the onboarding packet.
2. You never complete it — nobody follows up in a way you’d notice.
3. The $20–$40/month penalty quietly appears on your statement and stays there for years.
$30/month × 12 = $360/year for a 45-minute form. Across the industry, this is one of the most-paid and least-necessary fees in existence.
How to kill it: log into your processor’s compliance portal (it’s usually linked from your statement or dashboard — if you can’t find it, call and ask; they must provide it), complete the SAQ for your business type, and confirm the fee drops off the next statement. Set a calendar reminder for 11 months out.
Fee #3 (watch for it): The “PCI protection” upsell
Some processors and ISOs sell a separate breach protection / PCI insurance product — $100–$300/year — marketed as covering forensic investigation costs if you’re breached. What to know:
- It is not the same as being PCI compliant. You still have to do the questionnaire.
- The coverage caps are often low relative to real breach costs, and the exclusions are broad.
- If you have a general business liability/cyber policy, check for overlap before buying a second one.
Not always a bad product — but it’s frequently sold with urgency (“you’re exposed!”) to merchants who’d be better served by the free questionnaire and their existing insurance.
The 15-minute PCI audit
- Find both lines on your statement: the program fee and — critically — any non-compliance fee.
- If the non-compliance fee is there, complete the SAQ this week. That’s $240–$480/year back.
- Ask whether the program fee is waivable — one ask, during your next negotiation or annual review.
- Check for a separate “breach protection” charge and compare it against your existing business insurance before renewing.
The analyzer’s statement mode totals every fee on your statement — including both PCI lines — so you can see exactly what compliance paperwork is worth to you per year.
Methodology
Fee ranges reflect commonly published processor schedules as of 2026. The SAQ process described is the standard PCI SSC self-assessment flow for small merchants (SAQ types A/B/B-IP depending on how you accept cards). This page is educational, not legal or security advice.
Frequently asked questions
I’m on Square/Stripe. Do I pay PCI fees?
Generally no separate PCI fees — the platforms handle PCI compliance within their flat rate (that’s part of what the margin covers). This page is mainly for merchants on interchange-plus or tiered contracts.
What happens if I ignore PCI compliance entirely?
Beyond the monthly penalty: in a breach, non-compliance can mean higher fines from the card networks and weaker standing with your insurer. The questionnaire is 45 minutes; the downside of skipping it is asymmetric.
My processor says they’ll “handle PCI for me” for $199/year. Worth it?
That usually means they’ll walk you through the SAQ — the same form you can complete yourself in under an hour. Unless you have a complex setup (multiple locations, integrated POS, e-commerce with stored cards), do it yourself.
Does completing the SAQ make me fully secure?
No — it’s a compliance attestation, not a security audit. Real security (patched systems, strong passwords, not storing card data) is separate and more important. But the fee disappears either way.
I completed the questionnaire and the fee is still there. Now what?
Call your processor and ask for the fee’s removal effective the completion date — and a credit for months charged after compliance. Get the confirmation in writing; check the next two statements.