Skip to main content
PCI non-compliance fee discovered by physician — young Indian-American internist in white coat with stethoscope, the kind of first-time solo-practice owner who discovers the monthly PCI non-compliance fee on her statement after her CPA flags it during tax prep
Human Nature

Fifteen Months of $19.95: The PCI Non-Compliance Fee Priyanka Didn’t Know She Was Paying

Priyanka Shah opened her solo internal medicine practice in Frisco, Texas in February 2025. She was thirty years old, four years out of residency, and tired of being told by hospital administrators which patients she could spend time with. The first year was lonely and financially terrifying and exactly what she wanted. The second year, her CPA found a $19.95 PCI non-compliance fee that had been billing her practice every month since the third statement she ever received.

Fifteen months. Two hundred and ninety-nine dollars and twenty-five cents. Quietly leaving the operating account on the fifth of every month, buried in a section of her statement labeled “Other Fees” that Priyanka had never opened because the dollar amounts were small and the labels were technical and she was busy treating patients.

This is what a PCI non-compliance fee actually is, why almost every small practice has one at some point, how Priyanka resolved hers in twenty-two minutes once she understood the mechanism, and why finding the fee usually means there’s more on your statement worth a second look.

What the Fee Actually Is

What a PCI Non-Compliance Fee Is and Why It’s on Your Statement

Every merchant that accepts credit cards is required to be compliant with the Payment Card Industry Data Security Standard — PCI DSS. The standard is set by the PCI Security Standards Council, a body jointly governed by Visa, Mastercard, American Express, Discover, and JCB. The current version is PCI DSS 4.0.1, which we covered in detail in our guide to PCI DSS 4.0 small merchant requirements.

For most small merchants, “compliant” means completing one document — a Self-Assessment Questionnaire, usually SAQ A for businesses that fully outsource card handling to a compliant processor. The SAQ is a checklist. You answer the questions, you attest that your business meets the requirements, you submit it through your processor’s PCI portal, and you’re done for the year. The whole thing typically takes twenty to forty minutes.

The PCI non-compliance fee is what your processor charges you when you haven’t completed that SAQ — or, more commonly, when you don’t know it exists. The fee is not a penalty from the card networks. It is not a fine. It is a monthly charge from your processor, typically $19.95 to $39.95, that they bill you because they are required to track your compliance status and they are absorbing risk on your behalf when you aren’t validated.

The fee exists whether or not you’re notified

Some processors send merchants a clear welcome email with PCI portal instructions during onboarding. Others bury the instructions in a setup PDF nobody reads. Either way, the merchant agreement language allows the processor to begin charging the PCI non-compliance fee after a grace period (typically 60-90 days) if validation hasn’t been completed. The fee continues monthly, indefinitely, until the SAQ is submitted and approved. Priyanka’s processor sent her a single email about PCI compliance the day after her account opened. She missed it. The fee started on month three and never stopped.

Why It Took Fifteen Months

How the PCI Non-Compliance Fee Hides in Plain Sight

Priyanka’s CPA was doing year-end tax prep when she pulled the practice’s processing statements into the work papers. She is methodical. She categorizes every recurring expense by vendor, then sub-categorizes by line-item label so anomalies surface. The $19.95 line item showed up on every statement from May 2025 forward.

“Have you been getting charged this PCI fee every month?” she asked.

Priyanka had not opened the section of her statement labeled “Other Fees” because she trusted that her processing rate was the only number that mattered. She knew her effective rate (2.94%, slightly elevated for healthcare but acceptable). She knew her monthly volume ($42K average). She did not know about a $19.95 line item appearing seventeen layers deep in a multi-page statement, because the line item was small and the label was technical and she was a doctor, not an auditor.

This is the structural reason most merchants never catch the PCI non-compliance fee. It is small enough to feel like a service fee — comparable to a $25 monthly minimum or a $15 statement fee — but it is not a service fee. It is a charge that disappears the moment you complete a free twenty-minute online questionnaire. Most small merchants who pay this fee are paying it not because of negligence but because nobody told them clearly what the questionnaire was, where to find it, or that completing it was both quick and free.

How to Resolve It

The Twenty-Two Minutes That Eliminated Priyanka’s PCI Non-Compliance Fee

Once Priyanka understood what the fee was, the resolution was straightforward. She emailed her processor’s support address requesting the link to their PCI compliance portal. The reply arrived in twelve hours with a URL, her merchant ID, and a temporary password.

The portal walked her through the SAQ A questionnaire. The questions were narrow because she fully outsources card processing — she does not store cardholder data, does not transmit it through her own systems, and uses a payment terminal her processor provisioned. The questionnaire took twenty-two minutes. She submitted it, received an immediate validation email, and the PCI non-compliance fee disappeared from her next statement.

What did not happen, and what merchants should know to expect:

  1. The fifteen months of fees were not refunded. Priyanka asked. The processor’s position, supported by her merchant agreement, was that the fee was billed correctly during periods of non-validation. She did not press the question because the agreement language was clear and the time to litigate $299 was not worth the savings.
  2. The validation is not permanent. SAQ A must be renewed annually. If Priyanka doesn’t complete next year’s SAQ within the grace window, the PCI non-compliance fee will return. Her processor sends a reminder, but the reminder is one email and easily missed.
  3. The PCI portal is a moving target. Different processors use different vendors for PCI portal management — Trustwave, ControlScan, SecurityMetrics. Some are intuitive. Others are not. Priyanka’s was usable but not designed for clinicians.
Quick check: are you paying a PCI non-compliance fee right now?

Pull your most recent processing statement. Scroll past the rate summary on page one to the line-item detail (usually pages two through four). Look for line items containing the words “PCI,” “compliance,” “non-validation,” “non-compliance,” or “PCI program.” Typical amounts: $9.95 to $39.95 per month. If you find one, you almost certainly have a PCI portal account you haven’t activated. Email your processor support and ask for the portal URL. The fee comes off after validation, typically within one billing cycle.

What the Fee Often Signals

Why a PCI Non-Compliance Fee Usually Means There’s More Worth Reviewing

The PCI non-compliance fee is not the most expensive line item on a typical small-merchant statement. Priyanka’s $299 over fifteen months is real money for a solo practice but it is not the dominant cost. The reason finding it matters more than the dollar amount suggests is that it is a leading indicator.

Merchants who never noticed the PCI non-compliance fee almost always have other line items they have also never noticed. A statement that contains an uncaught $19.95 fee for fifteen months is a statement nobody is reviewing systematically. The same statement frequently contains:

  1. Tiered pricing creep. The processor quoted a rate that applies to some card categories but downgrades others. The merchant’s effective rate has slowly drifted above the quoted rate. Our piece on qualified and mid-qualified rates walks through how this happens.
  2. Monthly minimum charges. A clause buried in the agreement charges $25 or $50 a month when card volume falls below a threshold the merchant didn’t know existed.
  3. Statement fees and batch fees. Small recurring charges — typically $10 to $20 each — for paper statements the merchant never receives or batch settlements that should be free.
  4. Equipment lease residual. A terminal lease that’s been paid in full but continues to bill. We’ve seen this consistently with healthcare practices that bought terminals during the 2018-2021 wave when leasing was bundled with onboarding.

Priyanka’s full statement review, prompted by the PCI fee discovery, turned up two more line items totaling $34 a month she also hadn’t been tracking. The PCI fee was the discovery vehicle. The full audit was the actual savings.

The honest framing on the PCI non-compliance fee

The fee is not a scam. It is a real charge for a real reason — your processor is required to track compliance status and is exposed to risk when you aren’t validated. The problem is not that the fee exists. The problem is how it gets disclosed. A clearer welcome email, a follow-up sixty days in, a phone call from the rep — any of these would surface the fee before fifteen months pass. Most processors do not do any of these consistently because the fee revenue is part of their margin model.

About This Story

Priyanka Shah is an illustrative composite. The fees, contract terms and mechanics described here are real and documented elsewhere on this site — the person and the business are not. Brookside does not publish real clients’ statements, which is why the sample statement review is a composite too.

Common Questions

Frequently Asked Questions

Can I get a refund for past PCI non-compliance fees?

Usually not. The fee is billed correctly during periods of non-validation per most merchant agreements. A small number of processors will credit one or two months as a gesture if you ask, but most will decline. The practical recovery is forward-looking — complete the SAQ, end the fee, and review the rest of your statement for other line items that may also be addressable.

Is PCI compliance the same as being charged the PCI non-compliance fee?

No. PCI compliance is a state — your business is or is not meeting PCI DSS requirements. The PCI non-compliance fee is a processor’s monthly charge for tracking and managing your compliance status when you aren’t validated. You can be PCI compliant in practice (you don’t store cardholder data, you use a compliant terminal) and still be charged the non-compliance fee because you haven’t formally validated through your processor’s portal.

What is SAQ A and is it the right questionnaire for my business?

SAQ A is the Self-Assessment Questionnaire for merchants that fully outsource card processing — you use a processor-provided terminal or hosted checkout, you don’t store cardholder data, and you don’t transmit cardholder data through your own systems. Most small healthcare practices, restaurants, retail shops, and service businesses qualify for SAQ A. If your business stores card data, runs e-commerce on your own server, or accepts card-not-present transactions through custom integrations, you may need SAQ A-EP, SAQ B, or another variant. Your processor’s PCI portal will walk you through the determination.

Found a PCI non-compliance fee on your statement?

Send Your Statement. We’ll Tell You What Else Has Been Quietly Billing.

If you just found a PCI non-compliance fee on your statement, there’s a good chance other line items have also been quietly billing. Send Brookside one recent statement and we’ll walk you through every line item, identify what’s removable through a portal action versus what’s contractual, and tell you what your effective rate actually is once the noise is stripped out. The PCI fee comes off the moment you complete the questionnaire. The rest of the audit takes us about twenty minutes. Learn more about payment processing consumer protections from the CFPB.

Send Your Statement for Free Review

No obligation • No pressure • Response within one business day

See what a statement review looks like →

Call (833) 382-1992 Email hello@brooksidepayments.com
Share this post
LinkedIn Facebook X
✏️
Lee wrote this. Kevin proofread it. If it's wrong, we'll make it right — and demote Kevin to sharpening pencils. BeBetter@brooksidepayments.com