PCI DSS non-compliance: fines, fees, and downstream costs
By Sam Rivera, Founder, SentinelPanda · April 30, 2026 · 4 min read · PCI DSS
PCI is enforced through contracts, not statutes. That makes the penalties less visible than a regulatory fine — and often more expensive once you add them up.
How enforcement actually works
PCI DSS is a contractual standard, not a law. The card brands require it in their operating rules; the acquirers (your merchant bank or payment processor) require it in their merchant agreements; and the penalties for non-compliance flow through those contracts. There is no PCI regulator that walks in and writes a citation; there is a card brand that issues a directive to your acquirer, who passes it on to you.
This makes the penalty structure less visible than a regulatory fine, but no less binding. The numbers below are typical ranges seen in published settlements and acquirer rate sheets — exact amounts vary by acquirer, brand, and contractual terms.
Monthly fines for sustained non-compliance
When a merchant or service provider fails to validate annually, the card brands typically issue a non-compliance directive to the acquirer. The acquirer passes the fine through to the merchant. Common ranges: $5,000 to $10,000 per month for the first few months, escalating to $25,000 to $50,000 per month or more for sustained non-compliance, particularly at higher merchant levels.
The fines accrue until validation is brought current. Programs that lapse for two or three quarters routinely find themselves with five or six figures of accumulated penalties — money that would have funded the entire compliance program.
Higher transaction processing fees
A non-compliant merchant is a riskier merchant from the acquirer's perspective. Acquirers respond by raising the processing rate — often by 5 to 20 basis points across the merchant's entire transaction volume — until compliance is restored. For a merchant processing $10 million annually, even a 10 bps increase costs $10,000 a year, on top of any direct fines.
Some acquirers also impose a non-compliance surcharge as a flat monthly fee, or require additional reserves to be held against the merchant account.
Loss of processing privileges
Sustained non-compliance can lead to acquirer termination of the merchant relationship. The merchant is then placed on the card brand's MATCH (Member Alert to Control High-Risk Merchants) list, which makes finding a replacement acquirer significantly harder and more expensive. For a business that depends on card payments, a MATCH listing is materially destabilising.
Service providers face a parallel outcome — removal from the brand's registry of validated service providers, which directly affects their ability to sell into PCI-aware customers.
Post-breach costs for non-compliant merchants
A breach involving cardholder data triggers a forensic investigation by a PCI Forensic Investigator (PFI), which the breached merchant pays for. That alone can run from tens of thousands to several hundred thousand dollars. On top of that:
- Card reissuance costs — the card brands assess the merchant for the cost of reissuing affected cards, typically a few dollars per card. A breach of 100,000 cards lands a six-figure assessment.
- Account Data Compromise (ADC) operations fines — separate brand fines specifically for breaches, scaling with the number of cards affected and the duration of the compromise window.
- Civil liability — class actions and individual claims from affected cardholders, particularly in jurisdictions with strong consumer-protection regimes.
- Contractual indemnification — your acquirer's contract usually requires you to indemnify them against losses they incur as a result of your breach.
- Forensic and remediation costs — the PFI, plus the actual cleanup work.
The compounding factor: non-compliance at the time of breach
The single biggest multiplier on post-breach costs is whether the merchant was PCI compliant at the time of the breach. A compliant merchant has documented evidence that they implemented reasonable controls; the conversation with the card brands and the acquirer is materially different. A non-compliant merchant has no such defence, and brands often levy elevated assessments to send a message.
Even a partially-out-of-date compliance program — an expired AOC, missed quarterly ASV scans, an outdated scope statement — is enough to be characterised as non-compliant for post-breach purposes. The program does not have to fail entirely to lose its defensive value.
The economics, summarised
Running a competent PCI program at most merchant levels costs in the tens of thousands of dollars a year, sometimes more, for tooling, scans, attestations, and time. The expected cost of sustained non-compliance — between accumulated fines, processing fee uplifts, and the tail risk of a breach — is materially higher. The math is almost always in favour of staying compliant; non-compliance is rarely a calculated decision and almost always an operational drift.