A monthly or annual fee charged by some processors for maintaining PCI DSS (Payment Card Industry Data Security Standard) compliance status. This fee may include access to a compliance portal, an annual security questionnaire tool, or compliance monitoring services. Separately, processors may charge a PCI non-compliance fee — typically higher — when a merchant has not completed their required annual PCI self-assessment questionnaire. Always complete the annual PCI assessment to avoid the non-compliance surcharge.
See common payment processing fees — including PCI and gateway fees
The PCI compliance fee is what a processor may charge to support your compliance process, typically by providing access to a portal where merchants complete their annual Self-Assessment Questionnaire (SAQ). The key distinction is between the compliance fee and the non-compliance fee: the compliance fee is the cost of staying current with your assessment; the non-compliance fee is a penalty charged when a merchant has not completed the required assessment. The non-compliance fee is generally higher than the compliance fee and is avoidable by completing the SAQ on schedule.
No. Some processors include PCI compliance support at no additional charge as part of their standard service. Others charge it as a separate monthly or annual fee. When evaluating processors, ask explicitly whether PCI compliance support is included and what the non-compliance fee is if you fall behind on your assessment.
The SAQ is an annual self-assessment tool that merchants use to confirm they meet PCI DSS requirements for their processing environment. SAQ requirements vary depending on how a merchant accepts cards — confirm which SAQ applies to your setup with your processor or compliance provider. Completing the SAQ on schedule is the primary way to maintain compliance status and avoid a non-compliance surcharge.
Explore the full glossary
Browse all 64 payment processing terms A–Z.