Processor fee
The PCI fee on your statement
It arrives every month, it has PCI in the name, and it is neither a fine nor proof of compliance. There are two different versions of this charge and only one of them comes off when you do the work. Here is how to tell which one you have.
Updated July 2026
What it is
A line on your monthly processing statement, usually called something like 'PCI Program Fee', 'PCI Compliance Fee' or 'PCI Non-Compliance Fee'. It is your processor's charge under your merchant agreement. It is not a card brand fine, and paying it does not make you PCI compliant.
The two charges, and why the difference matters
This is the whole page, really. Merchants file an SAQ, watch the charge stay on the statement, and conclude the process is rigged. Usually they just had the other fee.
PCI programme or compliance fee
Charged whether or not you are compliant. Usually bundles a compliance portal, an SAQ tool and sometimes ASV scanning or breach insurance. Completing your SAQ does not remove it.
PCI non-compliance fee
Charged because you have not completed your SAQ. This one you can remove, by completing the SAQ through whichever portal your processor names on the statement or in the letters it has been sending you.
Finding yours, in about a minute
- Open the last monthly statement and read the fee schedule, not the summary total
- Identify which of the two charges above it is; the wording on the statement usually says
- If it is a non-compliance fee, complete the SAQ in your processor's portal, then check the next one or two statements to confirm it has dropped off
- If it is a programme fee, it is a contract term, so it is a negotiation or a renewal conversation rather than a form to fill in
- Read the indemnity clause of your merchant agreement while you are in there; that clause, not any card brand schedule, is what sets your exposure if you are breached
Platforms that carry the certification themselves
Some platforms take card data onto their own systems and their own PCI certification. That changes what you have to do, which is worth more than what it changes about what you pay. Quoted from the vendor's own documentation rather than described from memory.
Stripe
Stripe states it "is certified annually by an independent PCI Qualified Security Assessor (QSA) as a PCI Level 1 Service Provider meeting all PCI requirements", and that SAQ A applies to merchants using Checkout, Payment Links, or Stripe.js and Elements, because those "host all card data collection inputs within an iframe served from Stripe's domain (not yours), so your customers' card information never touches your servers".
docs.stripe.com/security/guide and stripe.com/guides/pci-compliance, checked July 2026
Other processors describe similar arrangements, but this page lists only those whose wording we have read on the vendor's own site and can quote. If your processor is not here, that is a gap in our checking, not a verdict on the processor.
Work out which SAQ you owe
The fee comes off when the SAQ goes in, and which SAQ you owe depends on how card data reaches you. If your checkout keeps card data off your servers entirely, the questionnaire is the short one.
Frequently asked
It is a charge from your payment processor under your merchant agreement. It is not a card brand fine, it is not set by PCI DSS, and paying it does not make you PCI compliant. There are two distinct versions and they behave differently. A PCI programme or compliance fee is charged whether or not you are compliant and usually bundles a compliance portal, an SAQ tool and sometimes scanning or breach insurance; completing your SAQ does not remove it. A PCI non-compliance fee is charged because you have not completed your SAQ, and that one does come off when you file.
Continue reading