Many card statements include a line for PCI, and some include a more expensive one for PCI non-compliance. These charges are easy to ignore because they look like an unavoidable admin cost. Often, at least the non-compliance part is avoidable. This guide explains what PCI DSS is, why providers charge for it and what you can do.
Key points
- PCI DSS is the card industry's security standard for protecting payment card data. It applies to all businesses that accept cards, whatever their size.
- The current version is PCI DSS v4.0.1, published in June 2024.
- Most small businesses show they comply by completing a self-assessment questionnaire (SAQ). Which one depends on how you take payments.
- Providers may charge a fee for compliance services, and an extra fee if you have not confirmed compliance. Completing your SAQ is usually the way to stop the second one.
What PCI DSS is
The Payment Card Industry Data Security Standard (PCI DSS) is, in the words of the body that maintains it, "a set of baseline technical and operational requirements designed to protect payment account data" (PCI Security Standards Council). The council says it is intended for all entities involved in payment processing, "including merchants, regardless of their size or transaction volume" (PCI SSC).
It still applies if you use a provider that handles card data for you. The council's guidance is that PCI DSS applies to any entity that stores, processes or transmits cardholder data, whether directly or through a third-party service provider, and that you remain responsible for making sure your provider is compliant for the services it gives you (PCI SSC FAQ). In practice, outsourcing usually makes your own questionnaire much shorter.
Which version applies now
PCI DSS v4.0.1 was published on 11 June 2024 as a limited revision of v4.0, with no new or deleted requirements (PCI SSC blog). The previous version, v3.2.1, was retired on 31 March 2024, and the requirements in v4.x that were initially "future-dated" became effective on 31 March 2025 (PCI SSC blog). PCI DSS v4.0 itself was retired on 31 December 2024 (PCI SSC bulletin).
The council has started work on the next version. It ran a request for comments on v4.0.1 from 3 June to 20 July 2026 (PCI SSC blog). Until a new version is published and takes effect, v4.0.1 is the standard to work to.
Who checks compliance, and who sets fees
The PCI Security Standards Council writes the standard, but it does not enforce it. Each of the founding card brands (American Express, Discover, JCB, Mastercard and Visa) runs its own compliance programme, and the council tells businesses to contact their acquirer (merchant bank) or the card brand to find out their validation and reporting requirements (PCI SSC).
So in practice, your card provider is the one asking you to prove compliance, and any PCI fee on your statement is set by your provider, not by the council.
Self-assessment questionnaires (SAQs)
SAQs are, in the council's words, "validation tools intended to assist SAQ-eligible merchants and service providers in performing and reporting the results of their PCI DSS self-assessment" (PCI SSC bulletin). There are several types, and each covers a different way of taking payments. The council lists, for merchants, SAQ A, A-EP, B, B-IP, C, C-VT, D, P2PE and SPoC (PCI SSC blog). Some examples of how they differ:
- SAQ C-VT is intended only for standalone computers used with a virtual terminal.
- SAQ B-IP is intended only for standalone PCI-approved payment terminals that are not connected to other types of devices in the same network zone.
- SAQ SPoC is for merchants using a phone or tablet with a secure card reader that is part of a validated software-based PIN entry solution.
- SAQ D for Merchants applies to merchants who are eligible for an SAQ but do not meet the criteria for any other type.
The council advises confirming you meet every eligibility criterion before starting, and contacting the organisation you submit the SAQ to, usually your acquirer, to confirm which one you should complete (PCI SSC bulletin). Many providers have an online portal that asks questions about how you take payments and selects the SAQ for you.
Why providers charge PCI fees
When the Payment Systems Regulator (PSR) reviewed the card-acquiring market, it found two kinds of PCI-related charge:
- Compliance service fees. Services that help a business certify, and in some cases achieve, PCI DSS compliance usually carry a fixed monthly or yearly fee (PSR final report, para 3.69). The PSR also noted that acquirers typically charge a monthly fee for these services (para 4.20).
- Non-compliance fees. PCI DSS non-compliance is one of the events that can trigger an additional fee under standard pricing (para 3.64).
When an acquirer takes a business on, it "assumes responsibility for the risks associated with granting them access to the card payment system" (PSR, para 3.22), so it has a reason to want evidence that its merchants are compliant. A non-compliance fee is, in effect, a charge for not having provided that evidence.
How to avoid non-compliance fees
- Check your statement. Look for lines labelled PCI, PCI DSS, data security or non-compliance, and note the amounts.
- Log in to your provider's PCI portal, or ask your provider how to access it. Find out what it has on record for you and when your validation is due.
- Complete the right SAQ. Answer the questions about how you take payments honestly. If something is unclear, ask your provider before submitting.
- Do any required scans or fixes. Depending on your set-up and SAQ, there may be extra steps such as vulnerability scans. Your provider's portal should tell you.
- Keep proof. Save a copy of your completed SAQ and any confirmation.
- Diary the renewal. Validation is not a one-off. Ask your provider how often it needs you to revalidate, and set a reminder.
- Check the next statement. If the non-compliance fee is still there after you have validated, contact your provider and ask for it to be removed and, where appropriate, refunded.
You can also reduce your PCI workload by how you take payments. Using a provider's hosted payment page for online sales, or a standalone approved terminal in-store, generally keeps more card data away from your own systems, which can mean a shorter SAQ. Ask your provider how your set-up affects the SAQ you need.
Compare the whole cost, not just the rate
PCI charges are part of your total cost of taking cards, along with transaction charges, terminal rental and other fees. Our guide to reading your card machine statement shows how to roll them into one effective rate. If you would like help, you can upload a recent statement for a free comparison. A UK advisor at The Rate Dropper will work out your effective rate and show what the same volume would cost with Worldpay, Dojo, SumUp, Zettle, takepayments, Barclaycard, Elavon and Square. It is free for businesses; we are paid a commission by the provider you choose.



