We’re rated Excellent on:

trust pilot

PCI Compliance Fees UK: What Merchants Pay and How to Reduce Them

Updated July 2026

Exclusive Rates From as Low as 0.26%

PCI compliance fees in the UK typically range from £5 to £40 per month, charged by payment processors and acquiring banks to cover the cost of managing your business's compliance with the Payment Card Industry Data Security Standard. Some providers bundle this into a broader "security" or "compliance management" package, while others charge it as a standalone line item, and a significant number of UK merchants are also being hit with a separate, much larger non-compliance fee (often £20 to £60 extra per month) simply because nobody in the business has completed a short online questionnaire. Understanding what you are actually being charged for is the first step to reducing or eliminating the fee entirely.

Key Takeaways

  • PCI compliance fees typically cost UK merchants between £5 and £40 per month, depending on provider and business size.
  • A separate "non-compliance fee" of £20-£60 per month is often charged on top when a merchant has not completed their annual SAQ (Self-Assessment Questionnaire).
  • Many acquirers and merchant service providers profit from PCI fees by charging more than the actual cost of compliance management.
  • Completing your SAQ, usually a 10-15 minute online form, is often enough to remove the non-compliance fee immediately.
  • Some UK providers, particularly newer fintech-style processors, include PCI compliance support free of charge within their standard package.
  • Reviewing your merchant statement line by line is the fastest way to spot whether you are being charged fairly for PCI compliance.
  • Switching provider can sometimes eliminate PCI fees altogether, especially if your current provider has been charging above-market rates.

What Is PCI DSS and Why Does It Matter to UK Merchants?

PCI DSS stands for Payment Card Industry Data Security Standard. It is a set of security requirements created by the major card schemes, including Visa, Mastercard and American Express, designed to protect cardholder data wherever it is stored, processed or transmitted. Any UK business that accepts card payments, whether in person, online, or over the phone, is contractually required to demonstrate compliance with PCI DSS as a condition of their merchant agreement.

This applies regardless of business size. A single-till café in Leeds and a national e-commerce retailer are both bound by the same underlying standard, although the level of documentation and validation required differs significantly depending on transaction volume and how card data is handled. The standard covers areas such as secure network configuration, restricted access to cardholder data, regular security testing, and maintaining an information security policy.

Who Enforces PCI DSS Compliance?

PCI DSS itself is administered by the PCI Security Standards Council, but enforcement in the UK happens through your acquiring bank or payment service provider. It is your acquirer, not the card schemes directly, who is responsible for ensuring merchants under their umbrella are compliant, and it is your acquirer who applies the compliance fee and any non-compliance penalty to your account.

What Does the PCI Compliance Fee Actually Cover?

In theory, the fee covers the cost of your provider maintaining a compliance management programme: hosting the online portal where you complete your Self-Assessment Questionnaire (SAQ), providing vulnerability scanning where required, and administering the annual re-validation process. In practice, the fee often generates a healthy margin for the provider well above the actual administrative cost involved.

Most small and medium UK merchants fall into SAQ categories that require nothing more than an annual online questionnaire, no external scanning, no penetration testing, and no significant ongoing work from the provider. Yet many are charged the same £15-£25 monthly fee regardless of how straightforward their compliance obligation is.

Typical Inclusions

  • Access to an online SAQ portal
  • Automated reminders to complete annual re-validation
  • Basic guidance documentation on securing card data
  • Quarterly network vulnerability scanning (only for merchants who process data through their own servers, e.g. SAQ D merchants)

Typical PCI Compliance Fees Charged by UK Providers

Fees vary considerably depending on provider type, contract length, and whether you negotiated your rate when signing up. The table below reflects typical ranges seen across UK merchant statements as of current market conditions.

Provider Type Typical Monthly PCI Fee Non-Compliance Fee (if applicable) Notes
Traditional bank-owned acquirer (e.g. legacy high street bank merchant services) £15 - £30 £20 - £60 per month Often bundled into "statement fee" or "security fee" line items
Independent ISO / reseller £10 - £40 £30 - £50 per month Widely variable; some resellers mark up significantly
Modern fintech processor (e.g. SumUp, Zettle, Stripe-style providers) £0 (included free) Rarely applied Usually built into flat-rate pricing structure
Mid-market acquirer (e.g. Worldpay, Elavon, Barclaycard) £5 - £20 £10 - £30 per month Often negotiable, especially for higher volume merchants
E-commerce specific gateway providers £10 - £25 £25 - £40 per month May include additional charges for hosted payment pages

If you are unsure how your current fee compares, our guide to card processing fee terminology can help you decode exactly what each line on your statement means before you query it with your provider.

The Non-Compliance Fee: The Hidden Cost Most Merchants Miss

The single biggest source of unnecessary PCI-related cost for UK merchants is the non-compliance fee. This is a penalty charge, separate from the standard compliance fee, applied when a merchant has not completed their annual SAQ or has failed a required vulnerability scan. It is designed to incentivise merchants to complete their compliance paperwork, but in reality it often functions as a silent revenue stream for providers because completion rates for SAQs are notoriously low across the small business sector.

Many merchants have no idea the fee exists until they scrutinise their statement, and providers are not always proactive about explaining that a simple online form would remove it. It is common to see businesses paying £30-£50 a month in non-compliance charges for years without realising a 15-minute questionnaire would stop it immediately.

How to Check If You Are Being Charged a Non-Compliance Fee

  • Review your most recent merchant statement line by line, looking for terms like "non-compliance," "PCI penalty," or "security non-adherence fee"
  • Call your provider's merchant services helpline and ask directly whether your account is currently PCI compliant
  • Log into your provider's online portal, most acquirers host a dedicated compliance dashboard showing your SAQ status
  • Ask your provider to confirm your SAQ type (A, A-EP, B, C or D) and when it was last completed

How to Reduce or Eliminate PCI Compliance Fees

There are several practical steps UK merchants can take, some immediate, some requiring a longer-term review of their processing arrangement.

1. Complete Your SAQ Immediately

This is the single fastest way to remove a non-compliance fee. Most SAQs, particularly SAQ A for businesses using a fully hosted payment page or SAQ B for standalone terminal-only merchants, take under 20 minutes to complete online. Contact your provider if you cannot locate the portal link.

2. Ask Your Provider to Waive or Reduce the Fee

PCI compliance fees are far more negotiable than most merchants realise, particularly for businesses processing above £10,000 per month. Providers would rather retain a compliant, paying customer than lose the account entirely, so a direct request often results in a partial or full waiver, especially if you have been a customer for some time or are considering a switch.

3. Review Whether Your Provider Includes Compliance Free

A growing number of UK providers, particularly app-based and fintech-style processors, build PCI compliance support into their standard pricing with no separate fee at all. If your current provider charges £20-£30 a month purely for compliance administration, it may be worth comparing alternatives that include it as standard.

4. Understand Your SAQ Type to Avoid Overpaying for Scanning

Some providers charge for quarterly vulnerability scanning even when a merchant's SAQ type does not require it. Confirm your correct SAQ classification, most small retail and hospitality businesses using standalone terminals fall into SAQ B or P2PE, neither of which requires external scanning.

5. Consider Switching Provider if Fees Remain Unreasonable

If your provider is unwilling to reduce or remove an excessive PCI fee, and the wider pricing on your account is uncompetitive, it may be time to review the whole contract rather than just this one line item. Before doing so, check your existing agreement for exit terms, our guide on early termination fees explains what switching might actually cost.

PCI Compliance Fees by Business Type

The compliance burden, and therefore the fairness of the fee charged, varies depending on how a business takes payments. A business relying entirely on a standalone chip and PIN terminal has a far lighter compliance obligation than an e-commerce business hosting its own checkout page.

Business Type Likely SAQ Type Compliance Complexity Fair Fee Range
Retail shop with standalone terminal SAQ B / P2PE Low - no card data touches business systems £0 - £10 per month
Hospitality venue with integrated EPOS SAQ B-IP or C Moderate - EPOS integration adds some scope £5 - £15 per month
E-commerce using hosted payment page (e.g. Stripe Checkout, PayPal) SAQ A Low - card data never touches merchant server £0 - £10 per month
E-commerce with self-hosted payment form SAQ A-EP Higher - requires more security controls £10 - £25 per month
Large business processing/storing card data directly SAQ D High - full PCI DSS assessment required £20 - £40+ per month

If you are unsure which category applies to your business, our detailed breakdown of card processing fees by business type covers how payment method and setup affects your overall cost structure, not just PCI fees.

How PCI Fees Fit Into Your Wider Merchant Statement

PCI compliance charges rarely appear in isolation. They usually sit alongside authorisation fees, scheme fees, minimum monthly service charges, and your core interchange plus markup rate. Because these charges are often bundled or vaguely labelled, it is easy for a genuinely small PCI fee to be overshadowed by larger, more impactful charges elsewhere on the statement that merchants have never queried.

Before raising the PCI fee specifically with your provider, it is worth reviewing the statement as a whole. Our guide to authorisation, scheme and minimum fees explains how these separate charges interact, and our breakdown of debit versus credit card fees explains why the rate you pay can vary significantly depending on the card type your customers use.

When It Is Worth Negotiating vs When It Is Worth Switching

Not every PCI fee issue requires switching provider. If your overall processing rates are competitive and the PCI fee is your only concern, a direct negotiation is usually the quickest fix, particularly if you have been with the same provider for more than 12 months. However, if a review of your full statement reveals that PCI fees are just one symptom of a broader pattern of overcharging, alongside high minimum monthly fees, excessive authorisation charges, or an uncompetitive markup on interchange, it is worth reviewing the whole contract.

Our guide on how to negotiate lower card processing fees includes specific scripts and benchmarks you can use when speaking to your provider, including how to approach the PCI fee conversation specifically.

Common Mistakes UK Merchants Make With PCI Fees

  • Ignoring the compliance portal invitation emails, which often leads directly to a non-compliance charge appearing a few months later
  • Assuming the fee is fixed and non-negotiable, when in most cases it can be reduced or waived with a phone call
  • Not knowing their SAQ type, leading to confusion about whether scanning charges are legitimately required
  • Failing to review the statement regularly, meaning non-compliance fees can run for months or years unnoticed
  • Switching provider without checking whether PCI compliance is included, only to find a new fee introduced later once an introductory period ends

Frequently Asked Questions

Is PCI compliance a legal requirement in the UK?

PCI DSS is not UK law, but it is a contractual requirement enforced through your merchant agreement with your acquiring bank or payment provider. Failing to comply can result in fines, increased fees, or in serious cases the withdrawal of your ability to accept card payments.

Can I avoid paying a PCI compliance fee entirely?

Some UK providers, particularly newer app-based and fintech processors, include PCI compliance support within their standard pricing with no separate charge. For merchants on legacy contracts with a bank-owned acquirer, negotiating a waiver or switching to a provider that includes compliance free is usually the most effective route to eliminating the fee.

What happens if I never complete my SAQ?

If you never complete your Self-Assessment Questionnaire, most providers will apply an ongoing non-compliance fee to your account, typically £20-£60 per month, until it is completed. In more serious or prolonged cases, particularly following a data breach, non-compliant merchants can face significantly larger fines from the card schemes themselves.

How often do I need to complete PCI compliance paperwork?

PCI DSS requires annual re-validation for most merchants, meaning you need to complete your SAQ once every 12 months. Larger merchants with higher transaction volumes (SAQ D) may face more frequent requirements, including quarterly vulnerability scans.

Is the PCI fee the same as the card processing fee?

No, the PCI compliance fee is entirely separate from your core card processing costs such as interchange, scheme fees, and your provider's markup. It specifically covers compliance administration and appears as a distinct line item on your statement, though some providers do bundle it into a broader "security" or "service" fee.

Which SAQ type applies to my business?

Your SAQ type depends on how your business accepts and processes card payments: standalone terminal-only merchants typically fall into SAQ B or P2PE, e-commerce businesses using a fully hosted payment page usually fall into SAQ A, and businesses that store or process card data directly on their own systems fall into the more demanding SAQ D. Your provider's compliance portal will confirm your specific classification.

Can my provider charge me PCI fees even if I have completed my SAQ?

Yes, a standard PCI compliance management fee can still apply even once your SAQ is complete, as it covers the ongoing administration of the compliance programme rather than being a penalty. However, if you have completed your SAQ, you should not be charged an additional non-compliance penalty on top of the standard fee.

How Compare Card Fees Can Help

Compare Card Fees is a free, independent advisory service. We compare rates from leading UK payment providers to find you the best deal available - no fee, no obligation.

Whether you are looking to reduce your card processing costs, switch provider, or understand what you are currently paying, our experts can help. Tell us about your business and we will find the best rates available.