Skip to main content

Independent UK card payment reviews

07735 864 445

Merchant statements & fees8 min read

PCI Compliance Fees: What UK Merchants Should Check

Separate genuine PCI DSS validation requirements from provider charges, then check what your contract says and what action removes any non-compliance fee.

The short answer

There is no standard UK price for ‘PCI compliance’. Your statement may include a fee for a provider’s compliance service, a separate charge while validation is incomplete, or no standalone fee at all. The written agreement and the line description matter more than a market-average figure.

PCI DSS is maintained by the PCI Security Standards Council. Your acquirer or payment provider normally tells you how validation applies to your setup.

Identify the charge before challenging it

Statement wordingWhat to ask
PCI service or programme feeWhat service is included, is it optional and where is it priced in the agreement?
PCI non-compliance feeWhich validation item is outstanding and what exact action removes the fee?
Scanning feeIs an approved scanning vendor required for this payment environment?
Security or data feeIs this genuinely PCI-related or a separate provider service?

Do not choose an SAQ by guesswork

The correct Self-Assessment Questionnaire depends on how card data is handled. PCI SSC publishes several SAQ types and says merchants should confirm eligibility with the acquirer or payment brand that receives the validation.

Changing a terminal, gateway, website integration or call-handling process can change the relevant scope. Describe the complete payment flow before relying on an old answer.

A practical resolution checklist

  • Copy the exact statement description and amount.
  • Ask the provider whether it is a service charge or a non-compliance charge.
  • Request the contract clause and current validation instructions.
  • Confirm the correct SAQ and whether external vulnerability scans apply.
  • Complete the required action through the provider’s genuine portal.
  • Ask when the charge will stop and check the next statement.

Keep the comparison commercial

When comparing providers, include every recurring security, portal and administration charge in the complete monthly cost. A low processing rate can be offset by fixed fees that were not included in the headline quote.

Want to understand what you are actually paying?

Send your latest merchant statement and Card Payment Connect will assess the charges, pricing structure and contract information available.

Get My Statement Reviewed

Official sources

About this guide

Published by Card Payment Connect, an independent card-payment consultancy for UK businesses. Reviewed by Matthew McCarthy, who has worked in UK merchant services for over a decade. Last reviewed 11 September 2026.

Frequently asked questions

Is a PCI compliance fee compulsory?

PCI DSS requirements can apply to merchants accepting cards, but a particular provider fee is a commercial term rather than a universal price set by PCI SSC. Check your agreement and ask what service the fee covers.

How much is a PCI non-compliance fee?

There is no dependable universal amount. Use your current statement and contract, and ask the provider to confirm the action and timetable for removing it.

Can I ignore PCI if my provider handles payments?

Do not assume so. Outsourcing can reduce scope, but the applicable validation depends on the exact payment setup. Confirm it with your acquirer or payment provider.

Does Card Payment Connect provide PCI certification?

No. We can help identify charges and questions for your provider, but PCI validation must follow the route specified by the appropriate acquirer, payment provider or qualified security specialist.

Related reading