PCI non-compliance penalties: what the card brands actually publish
Most of what circulates as the PCI fine schedule is not published by anyone. One brand does print its numbers, one publishes only part, and the figure that decides your bill is in a contract you already signed. Here is each, separated, with the rulebook it came from.
Card brand rules checked 17 July 2026
Mastercard, published in full
The one schedule a card brand actually prints
Mastercard publishes its Site Data Protection noncompliance assessments as Table 2.2 of its Security Rules and Procedures, Merchant Edition. Read the axis carefully, because it is the detail most summaries get wrong: these are per violation, per calendar year, and every figure is an "up to" ceiling. They are not monthly, and they are not ranges.
Classification
1st violation
2nd
3rd
4th
Level 1 and Level 2 merchants
Up to USD 25,000
Up to USD 50,000
Up to USD 100,000
Up to USD 200,000
Level 3 merchants
Up to USD 10,000
Up to USD 20,000
Up to USD 40,000
Up to USD 80,000
Level 1 and Level 2 service providers
Up to USD 25,000
Up to USD 50,000
Up to USD 100,000
Up to USD 200,000
Source: Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026, section 2.2.5, Table 2.2. Mastercard adds that noncompliance may also result in merchant termination.
Visa, published in part
What Visa publishes, and the schedule it does not
Visa does not publish a fine schedule for PCI DSS non-compliance. Its rule on the subject says only that a member deemed non-compliant "is subject to a non-compliance assessment as set out in the Account Information Security (AIS) Program Guide" and Visa does not publish that guide. The same guide holds Visa's merchant level criteria. That is the whole of the public record on it, and it is why no honest source can tell you Visa's number.
What Visa does publish are assessments for mishandling a breach. These are a different thing, and worth knowing precisely because they are the ones with real ceilings attached:
Entity
Annual transactions
Assessment
Issuers, Acquirers, VisaNet Processors
Not applicable
USD $100K
Level 1 merchants
> 6,000,000 annual transactions
USD $100K
Level 2 merchants
1,000,001 - 6,000,000
USD $100K
Level 3 merchants
500,000 - 1,000,000
USD $25K
Level 3 merchants
100,000 - 500,000
USD $10K
Level 3 merchants
1 - 100,000
USD $5K
Source: Visa, What To Do If Compromised, Visa Supplemental Requirements v10.0, effective 25 June 2026, section 9. Visa notes these became tiered for Level 3 merchants on 9 February 2025, and that it may raise a Level 3 assessment to the 100,000 dollar threshold at its discretion where the facts warrant it.
Visa also charges for a slow forensic investigation
Four full calendar months from Visa's notice are fee-free. Partial months do not count. After that:
Level 1 and Level 2 merchants, VisaNet Processors, Members, Agents: USD $10,000 per month until the investigation is properly completed
Level 3 merchants: USD $3,000 one-time flat fee
Source: Visa WTDIC v10.0, section 8. Invoiced after the fifth full calendar month of an open investigation.
How enforcement actually reaches you
Four steps, each taken from the rules themselves rather than from received wisdom.
1
The card brand assesses the bank, not you
Visa's rule is explicit that the assessment lands on the Member: if Visa determines that a Member, its agent, or a merchant has been deficient in securely maintaining account information, "Visa may impose a non-compliance assessment on the Member". Mastercard's Table 2.2 assesses the Customer. Neither brand has a contract with you.
Visa Rules 12.5.1.2 (ID# 0001753); Mastercard SPME 2.2.5
2
Your acquirer passes it on under your merchant agreement
What you actually pay is set by the indemnity clause in the contract you signed with your acquirer, not by a card brand schedule. Two merchants hit by identical assessments can owe very different amounts. This contract is the document to read, and it is the only place your number exists.
Merchant agreement (yours; not published by anyone)
3
Your acquirer must report your status twice a year
Visa requires Members to report and verify their merchants' PCI DSS compliance status at least every 6 months. Mastercard requires semiannual SDP Acquirer Submission and Compliance Status Forms, due 31 March and 30 September. This is why acquirers chase SAQs.
Visa Rules 12.5.1.2; Mastercard SPME 2.2.2
4
Non-compliance can end card acceptance
Mastercard states that noncompliance "also may result in Merchant termination", deregistration of service providers, or termination of the acquirer as a Customer. This is the tail risk that does not appear on any fee schedule.
Mastercard SPME 2.2.5
Card brand programmes: who publishes what
Brand
Programme
Publishes a schedule?
What that means
Visa
Account Information Security (AIS)
Partly
Visa publishes assessments for breach-response failures in What To Do If Compromised, and a general escalating schedule for Visa Rules violations. Its assessment schedule for PCI DSS non-compliance itself is routed to the AIS Program Guide, which Visa does not publish. Merchant level criteria also live in that guide.
Mastercard
Site Data Protection (SDP)
Yes
The most transparent of the four. Mastercard prints its SDP noncompliance assessments as Table 2.2 of its public Security Rules and Procedures: escalating ceilings per violation per calendar year, split by merchant level. It also publishes its merchant level criteria in the same document.
American Express
Data Security Operating Policy (DSOP)
No
American Express sets its own merchant thresholds and validation requirements and enforces them through the merchant agreement. It does not publish an assessment schedule.
Discover
Discover Information Security and Compliance (DISC)
No
Discover sets its own thresholds and validation requirements and enforces them through the merchant agreement. It does not publish an assessment schedule.
What a breach actually costs
Assessments are rarely the biggest line. These are the drivers the rules impose on you directly, with what each brand does and does not publish about them. Where a rulebook describes a mechanism but withholds the rate, that is said rather than filled in.
PCI Forensic Investigator (PFI)
Where Visa requires a PFI, the entity has five business days to execute a contract retaining one and name the lead investigator, must supply a preliminary report within five business days of signing, and a final report within ten business days of the investigation completing. The PFI cannot be a firm that has previously served the entity as QSA or PFI, so this is usually a new vendor at short notice with no prior scope knowledge. No PFI publishes a rate.
Visa WTDIC v10.0 section 5
Visa investigation fees for a slow PFI
Four full calendar months from Visa's notice are fee-free. After that, Level 1 and Level 2 merchants are charged USD $10,000 per month until the investigation is properly completed; Level 3 merchants pay a USD $3,000 one-time flat fee. Partial months do not count toward the grace period.
Mastercard may invoke operational reimbursement for an event affecting 50,000 or more Mastercard accounts. The method is published: count at-risk accounts, multiply by an amount Mastercard fixes from time to time, subtract a deductible for cards that would have expired anyway, and in the US and Canada halve the result if at least 75 percent of the merchant's transactions ran through hybrid (chip) POS terminals. The multiplier itself is not published, so the size of the bill cannot be derived from public documents.
Mastercard SPME 10.6.3, 10.6.4
Fraud recovery
Separate from reissuance. Mastercard debits the fraud recovery amount from the acquirer's account and credits the issuer. The merchant sees it through the acquirer.
Mastercard SPME 8.4.8
Mandatory remediation to full PCI DSS compliance
After a compromise Mastercard requires the entity or its acquirer to return an Account Data Compromise Information Form within 30 calendar days naming the forensic investigator, QSA and ASV, stating the current compliance level, and supplying a gap analysis; then to evidence full PCI DSS compliance by a set deadline. Mastercard may also deem any merchant with a confirmed compromise a Level 1 merchant regardless of volume, which forces an annual QSA-signed ROC.
Mastercard SPME 2.2.2, 2.2.6
Failure to notify
A Member is subject to an assessment of up to USD 100,000 per incident for failing to report a suspected or confirmed compromise to Visa within three calendar days, to state PCI DSS compliance status within three calendar days, or to provide an initial incident report within three calendar days of identification. This is the one Visa penalty with a published ceiling, and it is charged per incident.
Visa Rules 12.5.1.3 (ID# 0003524); Visa WTDIC v10.0 section 9
The order the bill arrives in
Roughly by size, largest first. No dollar ranges: none of these are published by anyone, and a range invented for this table would be worth less than the ordering itself.
PCI Forensic Investigation (PFI)
Mandatory where Visa requires one, on a five business day clock to sign a PFI, and it cannot be a firm that has worked for you before.
Card reissuance
Mastercard publishes the method but not the multiplier. Triggered at 50,000+ affected accounts.
Fraud recovery
Debited from your acquirer and credited to the issuers. Reaches you through your merchant agreement.
Card brand assessments
Levied on your acquirer, not on you. Mastercard publishes its ceilings; Visa publishes only its breach-response ones.
Mandatory remediation to full PCI DSS compliance
A confirmed compromise can also make you a Mastercard Level 1 merchant, which forces an annual ROC.
State law liability to issuing banks
Minnesota and Washington both make you liable to banks for reissuance. Washington has a PCI compliance safe harbour.
Breach notification and class action exposure
Set by state law and litigation, not by the card brands.
Business interruption
Mastercard states that noncompliance may result in merchant termination. Losing card acceptance is the tail risk.
Where PCI is actually law
PCI DSS is a contract, not a statute. But two states put card data handling into law with real liability attached, and one of them gives you a compliance safe harbour worth knowing about.
Minnesota
Minnesota Statutes 325E.64
Prohibits retaining the card security code, the PIN verification code number, or the full contents of any track of magnetic stripe data after authorisation of a transaction, and no later than 48 hours after authorisation for PIN debit transactions. A person who violates the section and suffers a breach is liable to the issuing financial institution for its reasonable costs, expressly including card cancellation and reissuance, closing accounts, blocking transactions, refunding unauthorised charges, notifying cardholders, and damages paid to injured cardholders.
Washington
Revised Code of Washington 19.255.020
A processor or business is liable to a financial institution for the reasonable actual costs of reissuing credit and debit cards where its failure to exercise reasonable care proximately caused the breach. Two safe harbours remove that liability: the account information was encrypted at the time of the breach, or the entity was certified compliant with PCI DSS in force at the time of the breach, validated by an annual assessment within the prior year. The statute states that the assessment of compliance is nonrevocable, so a later finding of non-compliance does not retroactively strip the safe harbour.
Massachusetts
201 CMR 17.00
Requires a comprehensive written information security programme (a WISP), encryption of personal information stored on laptops and other portable devices, and encryption of personal information transmitted across public networks or wirelessly. The regulation states that password protection does not satisfy the encryption standard. Not PCI-specific, but it overlaps heavily with PCI DSS requirements 3 and 4 and binds any business holding data on a Massachusetts resident.
Two cases where the numbers are documented
Breach cost totals circulate widely and are mostly untraceable. These two are different: each figure below comes from the company's own filing or the regulator's own order, and each is named.
Target
2013 breach
$292M gross, $202M net of insurance
Target disclosed cumulative expenses since the 2013 breach of $292 million, partially offset by $90 million of expected insurance recoveries, for net cumulative expenses of $202 million. This is the rare case where a merchant published a running total in its own annual report, and it is the best-documented breach cost figure in payments. Note what it includes: legal settlements, investigation, and remediation together. There is no separately disclosed card brand fine.
Target Corporation Form 10-K for the fiscal year ended 28 January 2017
Wyndham Worldwide
2008-2010 breaches
No monetary relief; 20 years of mandated audits
Three breaches led to an FTC action under Section 5 that established the FTC's authority to enforce data security practices, upheld by the Third Circuit in 2015. The settlement is instructive precisely because of what it did not contain: the stipulated order imposed no monetary relief. What it imposed was a comprehensive information security programme and annual third-party PCI-based assessments for twenty years. The cost of that breach was a two-decade compliance obligation, not a fine.
FTC v. Wyndham Worldwide Corp., stipulated order 9 December 2015; Wyndham Worldwide Form 10-K FY2015
If you are in an incident right now
Where Visa requires a PCI Forensic Investigator, the clock is five business days to execute a contract and name your lead investigator, and it cannot be a firm that has previously served you as QSA or PFI. The PCI SSC directory is the list Visa recognises. Fees are quoted per engagement; no PFI publishes a rate.
There is no single answer, and anyone quoting you a monthly schedule is quoting something the card brands do not publish. Two things are documented. Mastercard prints its Site Data Protection assessment ceilings in its public rulebook: up to USD 25,000 for a first violation rising to up to USD 200,000 for a fourth, counted per violation per calendar year, for Level 1 and Level 2 merchants, and up to USD 10,000 rising to up to USD 80,000 for Level 3 merchants. Visa does not publish an equivalent schedule; its rules route PCI DSS non-compliance assessments to the Account Information Security Program Guide, which is not a public document. Both brands assess the acquiring bank, not you. What you pay is set by the indemnity clause in your merchant agreement.