Home / Blog / PCI Compliance

PCI Compliance for Small Businesses Without the Junk Fees

For most small businesses, staying PCI compliant is simpler and cheaper than the scary emails suggest. Here's what you actually owe.

If you accept credit cards, you've almost certainly seen the letters "PCI" on a statement, an email, or a scary-sounding letter warning you to "become compliant or face fees." For a lot of small business owners, PCI compliance feels like a bill you're being charged for something you don't understand. That's not an accident. The rules themselves are reasonable, but the way they're often packaged and sold to merchants is where the confusion — and the overcharging — creeps in.

The good news: for most small businesses, staying PCI compliant is far simpler and cheaper than the fear-based marketing suggests. Let's walk through what PCI actually is, what you're genuinely responsible for, and how to avoid paying "non-compliance" fees that never needed to exist.

What PCI DSS actually is (in plain English)

PCI DSS stands for the Payment Card Industry Data Security Standard. It's a set of security requirements created and maintained by the PCI Security Standards Council — a body founded by the major card networks (Visa, Mastercard, Discover, American Express). It is not a government law and it is not something your processor invented. It's an industry standard that anyone who stores, processes, or transmits cardholder data is expected to follow.

The purpose is straightforward: protect card numbers from being stolen. When a customer hands you their card, that data has to be handled carefully so it can't be skimmed, intercepted, or breached. PCI DSS is the checklist that spells out what "handled carefully" means — things like using secure networks, not writing down full card numbers, keeping software patched, and restricting who can access sensitive data.

The core requirements boil down to common-sense security:

  • Protect stored data — don't keep full card numbers lying around; if you don't need it, don't store it.
  • Use secure connections — card data should travel encrypted, never in plain text.
  • Control access — only the people who need cardholder data should be able to reach it, each with their own login.
  • Keep systems current — use up-to-date, supported equipment and software with strong passwords (not the factory default).
  • Monitor and test — watch for problems and check your setup periodically.

For a large enterprise processing millions of transactions, meeting these requirements is a serious project. For a small shop running a modern terminal or a hosted checkout page, most of it is already handled by the equipment and software you're using.

The SAQ: how small merchants prove compliance

Here's the part that trips people up. You don't hire an auditor to inspect your business every year. Instead, most small and mid-sized merchants demonstrate compliance by completing a Self-Assessment Questionnaire — the SAQ. It's essentially a form where you attest that you're following the relevant security practices for the way you accept cards.

There isn't one universal SAQ. The type you complete depends on how you take payments — whether you swipe/dip/tap in person, key cards in over the phone, or accept them online, and whether card data ever touches your own systems. The simpler and more "hands-off" your setup, the shorter your questionnaire.

The key insight: the more you outsource card handling to secure equipment and hosted checkout pages, the fewer requirements land on you. A business whose card data never touches its own computers has a much shorter SAQ than one that stores or keys card numbers directly. When in doubt, the goal is to keep raw card data out of your own environment entirely.

Here are the most common SAQ types small businesses encounter. (This is a simplified overview — your processor or a compliance portal will help you confirm which applies to you.)

SAQ typeTypically applies toRelative effort
SAQ ACard-not-present merchants who fully outsource checkout to a hosted/redirected page — card data never touches your systemsShortest
SAQ A-EPE-commerce sites where your page partly controls the payment flowModerate
SAQ B / B-IPStandalone dial-out or IP-connected terminals, no electronic card storageShort–moderate
SAQ P2PEMerchants using a validated point-to-point encryption terminalVery short
SAQ C / C-VTPayment applications or virtual terminals on an internet-connected deviceModerate
SAQ DMerchants who store card data or don't fit the categories aboveLongest

SAQ names and criteria are illustrative and can change; always confirm the current version and the type that fits your business.

What a small merchant actually has to do

Strip away the jargon and, for a typical small business, annual PCI compliance usually comes down to a short list:

  • Complete the right SAQ once a year — usually through an online compliance portal your processor provides. It walks you through the questions.
  • Run a network scan if required — if you accept cards online or have internet-connected payment systems, you may need a quarterly external scan from an Approved Scanning Vendor. Many portals include this. Standalone terminals often don't need it.
  • Follow basic security hygiene — change default passwords, keep your terminal and software updated, don't share logins, and never write down full card numbers or store them in a spreadsheet.
  • Use trusted equipment — modern terminals and gateways are built to be compliant out of the box, which keeps your responsibility small.

For many small merchants, the whole thing is an hour or two of clicking through a questionnaire once a year. It should not be a source of ongoing dread — and it shouldn't quietly cost you $20 or $30 every single month.

"PCI non-compliance fees" — and how they turn into profit

Now the part that costs real money. Look closely at your merchant statement and you'll likely find one or more of these line items:

  • A "PCI compliance fee" — often billed monthly or annually (an illustrative range might be anywhere from a few dollars a month to $100+ a year). This is sometimes tied to a real compliance portal or breach-protection program.
  • A "PCI non-compliance fee" — a penalty charged because you haven't completed your SAQ. This is where things get frustrating.

Here's the problem. Some processors enroll merchants in a compliance program, send a single easy-to-miss email, and then — if you never log in and finish the questionnaire — start charging a monthly "non-compliance" penalty. Because the questionnaire is unfamiliar and the reminder blends in with dozens of other emails, plenty of merchants never complete it and simply eat the fee, month after month, for years.

The uncomfortable reality is that for some players in the industry, non-compliance fees have become a revenue line rather than a genuine security nudge. The card networks require that merchants be compliant; they do not require that anyone profit from your paperwork sitting unfinished. Completing your SAQ is what makes the penalty go away — and it's free to do.

Watch for this pattern: a monthly "non-compliance" charge that never disappears, even though nobody ever clearly walked you through finishing the questionnaire. That's not a security problem — it's an admin problem, and it's fixable. Completing your SAQ (and, if applicable, a scan) should clear the penalty, often retroactively on request.

How to stay compliant without overpaying

You can be fully compliant and stop leaking money to junk fees. A few practical steps:

1. Actually complete your SAQ

Ask your processor for the login to your PCI compliance portal and finish the questionnaire. Once it's done, any "non-compliance" penalty should stop. If you've been charged that penalty while the portal was available the whole time, it's worth asking whether recent charges can be refunded.

2. Read your statement line by line

Separate the legitimate items (a modest program fee tied to a real compliance/breach-protection service) from the avoidable ones (a recurring non-compliance penalty). If you can't tell what a fee is for, that's a red flag worth a phone call. Many of these charges hide in the same murky territory as the gap between the fees between the quote and the bill.

3. Simplify how you handle cards

The less card data touches your own systems, the shorter your SAQ and the lower your risk. Hosted checkout pages, validated encrypting terminals, and modern gateways all shrink your compliance burden. If your current setup forces you into the longest questionnaire, ask whether a simpler configuration is possible.

4. Get a second set of eyes on your fees

If you suspect you're paying PCI-related charges you shouldn't be, a free statement analysis can spot non-compliance fees, redundant program charges, and other padding. It's a quick way to see exactly what you're being billed and why — with no obligation.

PCI compliance exists for a good reason: it keeps your customers' card data safe and it protects you from the fallout of a breach. But keeping your business compliant should be a straightforward annual task, not a permanent surcharge on your bottom line. Understand what you owe, finish the paperwork, and don't pay a penalty for a form nobody helped you fill out.

Want to dig deeper into how the numbers on your statement really work? Start with our processing rates FAQ, or explore the solutions built around transparent, no-surprise pricing. And if a line item on your bill doesn't add up, call us at (888) 592-1110 — we'll help you read it straight.

Find Out What You're Really Paying

Send us one recent statement. We'll calculate your true effective rate, flag the junk fees, and show you a side-by-side — free, no obligation, usually within one business day.

Get My Free Statement Analysis Call (888) 592-1110