Most merchants who see a "PCI non-compliance fee" on their statement assume it is some kind of government charge they cannot avoid. It is not. It is a fee your processor invented, charges because you have not completed a short annual questionnaire, and keeps collecting for as long as you let them. The good news is that becoming compliant is not expensive or complicated — and once you are, the fee disappears entirely.
What Is PCI Compliance, Actually?
PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of security rules created by the card networks — Visa, Mastercard, and the others — to protect cardholder data. Every business that accepts cards is required to follow these rules. That part is real.
What is not a government mandate is the non-compliance fee. Your processor adds it to your bill as a penalty for not submitting proof that you have completed your annual compliance requirements. The fee does not go to Visa or Mastercard. It stays with your processor. Some processors charge $9.95 a month. Others charge $99 or more. A business that ignores this for three years can easily pay $1,500 or more for nothing.
Compliance for most small businesses has two parts: a Self-Assessment Questionnaire (SAQ) and, for some businesses, quarterly network vulnerability scans.
What Is the SAQ and Do You Have to Fill One Out?
The SAQ is a self-assessment form that confirms your business handles card data securely. There are several versions depending on how you accept payments. Most small businesses that use a hosted payment page, a third-party terminal, or a point-of-sale system that never stores raw card numbers qualify for SAQ A or SAQ B — the shortest versions. SAQ A is as few as 22 yes-or-no questions. It takes most business owners under 20 minutes to complete.
Your processor should give you access to a compliance portal where you log in, answer the questions, and submit. Once submitted, the non-compliance fee stops. If your processor has not told you this portal exists, that is worth noticing.
Quarterly scans are a separate requirement for businesses that process payments through an internet-facing system — meaning a web server or payment gateway that is exposed to the public internet. If you use a fully hosted checkout (the customer leaves your site to pay), you likely do not need scans. If you run your own server or a self-hosted cart, you probably do. Scans are performed by an Approved Scanning Vendor and typically cost very little or are included with your compliance portal access.
How Processors Profit From Non-Compliance
Here is the part most processors would prefer you not think about too carefully. The non-compliance fee is margin, not cost recovery. It does not cost your processor $40 a month to manage your non-compliance. The fee exists because most merchants do not know what PCI compliance is, do not know the fee is avoidable, and do not take the 20 minutes to complete the SAQ.
Some processors make the compliance portal hard to find. Others send a single email buried in onboarding materials and then start billing the fee 90 days later when you have not responded. A few processors charge both a non-compliance fee and a separate PCI compliance fee — meaning you pay a penalty for not being compliant and then pay again once you are. That second fee is sometimes legitimate (it covers portal access and scan services), but the amount should be modest. If you are paying more than $10–$15 a month for the compliance fee after you have completed your SAQ, ask your processor to justify the line item.
The table below shows what the fee landscape typically looks like across processor types.
| Processor Type | Typical Monthly PCI Non-Compliance Fee | Typical Monthly PCI Compliance Fee (after SAQ) | Transparency |
|---|---|---|---|
| Large bank merchant services | $19–$99 | $9–$19 | Low — buried in statement |
| Square / Stripe / PayPal | Not charged separately | Included in flat rate | N/A — flat rate covers all |
| Clover / ISO resellers | $9–$49 | $0–$15 | Varies widely |
| Zend Blue wholesale | $0 when compliant | Minimal, disclosed upfront | Full line-item transparency |
Flat-rate processors like Square and Stripe do not charge a separate PCI fee because their margin is already baked into the rate — you pay for it either way, just less visibly. With interchange-plus pricing, every fee is a separate line item, which is actually better for you because you can see and challenge each one.
What Quarterly Scans Involve
If your business does need quarterly scans, the process is straightforward. An Approved Scanning Vendor runs an automated test against your external IP addresses to check for known vulnerabilities — open ports, outdated software, misconfigured servers. You get a report. If everything passes, you submit the passing scan as part of your compliance documentation. If something fails, you fix it (usually with help from whoever manages your website or server) and run the scan again.
For most small businesses using hosted payment solutions, this step is not required at all. If your processor is charging you for scans you do not need, that is a conversation worth having.
What Does Non-Compliance Actually Risk?
Beyond the monthly fee, there are real consequences for staying non-compliant. If your business experiences a card data breach and you were not PCI compliant at the time, the card networks can fine you between $5,000 and $100,000 per month until you come into compliance. You can also be held liable for fraud losses and the cost of reissuing compromised cards. For a small business, a breach without compliance documentation is a serious financial event.
Compliance does not guarantee you will never have a breach. But it significantly reduces the risk, and it protects you from the worst financial penalties if something does go wrong.
The following chart shows illustrative effective compliance-related cost as a percentage of revenue for different processor relationships. Numbers are illustrative and will vary by business.
How to Get Compliant in One Afternoon
If you are currently paying a non-compliance fee, here is the sequence:
- Log into your processor's compliance portal. If you cannot find it, call support and ask specifically for the PCI compliance portal link.
- Identify which SAQ version applies to your business. For most small businesses using a terminal or hosted checkout, it is SAQ A or SAQ B.
- Answer the questions honestly and submit. Keep a copy of the completion certificate.
- Check your next statement. The non-compliance fee should be gone. If it is not, call and reference your completion date.
If quarterly scans are required, your portal will walk you through scheduling the first one. Most passing scans complete in under an hour.
What to Expect With Zend Blue
When you process through us, we walk you through compliance setup at onboarding — not six months later when the fee has already stacked up. Our statements show every line item in plain language, so if there is a compliance-related charge, you know exactly what it is and why. We do not use non-compliance fees as a revenue stream.
For businesses that want to go further, Pocket Boss (starting at $100/month with no setup fee) includes the kind of operational visibility that keeps your whole business tidy — payments, invoicing, client communication, and automation in one place. When your systems are consolidated, compliance documentation is easier to maintain because your payment flows are cleaner and more consistent.
A worked example: a landscaping company with $30,000 in monthly card volume was paying $49/month in PCI non-compliance fees and had been for two years. That is $1,176 paid for nothing. After a statement review, they completed their SAQ in 18 minutes, the fee dropped to $0, and they redirected that money toward a text invoicing setup that cut their collections time by four days per month. The fee savings alone covered the cost of the tool.
What to Do Next
If you are not sure whether you are paying a non-compliance fee, pull your last three statements and look for any line item with "PCI" in the name. If you see a non-compliance charge, you are likely 20 minutes away from eliminating it.
Run your numbers through our free calculator at https://www.zend.blue/#calculator to see what your full processing cost looks like compared to a clean wholesale setup. Or text us at 580-910-9100 for a free statement review — we will find every fee that should not be there and tell you exactly what to do about it. To see what Pocket Boss can do for your business beyond payments, visit https://www.zend.blue/pricing.
Figures in this guide are illustrative estimates, not a quote. Your rate depends on card mix, ticket size and business type, and is confirmed through a statement review.