Why Your Card Machine Provider Charges a PCI Fee — and How to Stop It
That PCI charge on your card machine statement is usually two different fees in disguise — and the larger one can normally be removed. Here is why providers charge it and how to stop paying.
If you have ever read your card machine statement line by line, you have probably spotted a charge labelled something like 'PCI DSS fee', 'PCI management charge' or 'non-compliance fee'. Most business owners have no idea what it is for, whether it is optional, or why it seems to creep upwards. The short version: it is usually two different charges hiding under one confusing name — and the larger of the two can normally be removed altogether. This article explains why your provider charges it, and exactly how to stop paying more than you need to.
What is the PCI fee on your statement?
When you signed your card processing agreement, you agreed to comply with PCI DSS — the Payment Card Industry Data Security Standard, the set of security rules covering every business that stores, processes or transmits card data. Our complete PCI compliance guide explains the standard itself in plain English. The fee on your statement, though, is not set by Visa, Mastercard or the PCI Security Standards Council. It is set by your acquirer or terminal provider, and it relates to how they administer — and enforce — that compliance obligation.
That distinction matters. Because the charge is set by your provider rather than by the card schemes, different providers charge different amounts, label the charge differently, and apply different rules for when it can be removed. Working out which type of charge you are paying is the first step to reducing it.
Are you paying one PCI charge — or two?
Look closely at your statement and you will usually find one — or both — of two distinct charges:
- A compliance programme fee — sometimes labelled 'PCI management fee', 'PCI DSS service charge' or 'security programme fee'. This pays for the provider's compliance portal, annual reminders and reporting to the card schemes. Programme fees commonly sit in the £3–£10 per month range and are typically charged whether you are compliant or not.
- A non-compliance fee — sometimes labelled 'PCI non-validation charge' or 'non-compliance service charge'. This is charged only while your provider holds no valid compliance record for you. Non-compliance fees typically run £5–£25 per month, and some providers charge more. Crucially, this one is designed to be avoidable: it stops once you validate your compliance.
The second charge is the one to focus on, because it is effectively a penalty for paperwork that has never been filed — money spent on nothing. We unpack both charges line by line in our guide to the PCI compliance fee on your statement.
Why does your provider charge PCI fees at all?
There are two honest reasons, and one less flattering one. The first is administration. The card schemes hold acquirers responsible for making sure their merchants validate compliance every year. That means running portals, chasing questionnaires, storing evidence and reporting numbers upstream — real work, which the programme fee funds.
The second is risk transfer. If a merchant suffers a card data breach while non-compliant, the acquirer faces assessments and penalties from the card schemes, which it will look to pass down the chain. A merchant with no valid compliance record is a riskier customer, so the monthly non-compliance fee both prices that risk and nudges you to sort the paperwork.
The less flattering reason: non-compliance fees are quietly lucrative. Plenty of small businesses never validate — often because nobody ever explained the process — and simply pay the penalty month after month, year after year. Providers are rarely in a hurry to point that out.
What do PCI charges look like on real statements?
Every provider words it differently, which is partly why the charge causes so much confusion. Whether your statement comes from Worldpay, Barclaycard, takepayments, Paymentsense (now part of DNA Payments), Global Payments or a provider still using older First Data paperwork, the pattern is the same even though the labels vary. Typical line items include:
- 'PCI DSS compliance fee' or 'PCI programme fee' — usually the standing programme charge.
- 'PCI non-compliance fee' or 'PCI non-validation fee' — the avoidable penalty.
- 'Safer payments fee', 'security management charge' or a similar branded name — check your terms to see which type it really is.
- A single combined 'PCI charge' that quietly steps up when your compliance lapses.
We are deliberately not quoting figures for named providers here — pricing varies by contract and changes over time. Whatever the label, the test is simple: ask your provider which part of the charge is a fixed programme fee and which part would stop if you validated. A straightforward question — 'what exactly makes this charge go away?' — usually gets a straightforward answer.
How do you stop the non-compliance charge?
The fix is to validate your compliance: confirm which Self-Assessment Questionnaire (SAQ) matches how you take payments, complete it accurately, run a vulnerability scan if your setup requires one, and file the signed Attestation of Compliance with your provider. Once their records show you as compliant, the non-compliance fee stops — usually from the next billing cycle. Left undone, the penalties simply continue, and they are only part of the risk: our article on PCI non-compliance fines covers what happens if a breach lands while you are unvalidated.
You do not have to wrestle with your provider's portal alone. Our fully managed PCI compliance service completes the correct SAQ with you over the phone, handles any required scans, and files the evidence with your provider — for a flat £100 + VAT per year, usually within 24 hours. The programme fee may remain, because it is a standing charge rather than a penalty, but the avoidable portion of your PCI costs disappears.
Can you get rid of the programme fee too?
Sometimes. Programme fees are a contractual term, so they are worth challenging when your agreement comes up for renewal — providers keen to keep your transaction volume will often trim ancillary charges if asked. Some newer providers advertise no PCI fees at all, though it always pays to compare the whole price card: a missing PCI line can quietly reappear as a higher transaction rate or terminal rental. Judge the total annual cost, not one line item.
What could you save? A worked example
Take a small independent shop paying a £4.95 monthly programme fee plus a £20 monthly non-compliance charge. That is £299.40 a year in PCI-related charges — £240 of which is pure penalty. Validate compliance and the £20 charge stops: an immediate saving of £240 every year. Even using a managed service at £100 + VAT (£120), the shop finishes £120 a year better off — and, unlike before, it is actually compliant, with evidence on file if the bank, an insurer or a corporate customer ever asks.
Scale that over time and the numbers get uncomfortable. Three years of unvalidated trading at £20 a month is £720 handed over for nothing. Some businesses have been paying penalties for far longer without realising — and a ten-minute statement check is all it takes to find out whether you are one of them.
Key takeaways
- The 'PCI fee' on your statement is usually two charges: a standing programme fee and a non-compliance penalty.
- Programme fees (commonly £3–£10 a month) fund your provider's compliance administration and usually remain.
- Non-compliance fees (typically £5–£25 a month) apply only while you are unvalidated — they are avoidable.
- Validating means completing the right SAQ and filing your Attestation of Compliance with your provider.
- A managed service can handle the whole process for £100 + VAT a year and stop the penalty for good.
Related Guides
SAQ A vs SAQ A-EP: What's the Difference and Which Do You Need?
SAQ A and SAQ A-EP sound alike but are worlds apart: around 30 questions against roughly 190, decided entirely by how your checkout is built. Here is how to tell which one your website needs — and how to move to the simpler one.
Read ArticleHow to Complete SAQ A: Step-by-Step for UK Businesses (2026)
SAQ A is the shortest route to PCI compliance — around 30 questions for businesses whose card handling is fully outsourced. Here is who qualifies under v4.0.1, what the form contains, the evidence to gather, and how to file it without the common mistakes.
Read ArticlePCI Compliance for Phone Payments (MOTO): What UK Businesses Need to Know
Taking card details over the phone is one of the trickiest areas of PCI DSS — especially if you record calls. Here's how MOTO payments work under PCI and how to stay compliant.
Read Article