PCI Compliance and Merchant Accounts

By Patrick FelstedCEO, Structure Payments

As a high-risk merchant, do you need to worry about PCI compliance and PCI non-compliance fees? Here is what actually applies to you, what it costs, and how to spot a scam call.

What PCI compliance is

The Payment Card Industry Data Security Standard (PCI DSS) is a collection of security standards created to safeguard sensitive payment card information during credit card transactions. It was established by the major card brands — including Visa, MasterCard, and American Express — and it requires businesses to follow specific security measures protecting cardholder data.

The standards cover requirements such as maintaining secure networks, implementing robust access controls, regularly monitoring and testing those networks, and maintaining a comprehensive information security policy.

Achieving and maintaining PCI compliance enhances data security, builds customer trust, and reduces the risk of data breaches and fraud. Non-compliance can mean financial penalties, reputational damage, and the loss of customer trust.

Is PCI compliance mandatory?

No — PCI compliance is not a legal requirement. The card providers established it as a standard to ensure the integrity of payment processing, not as legislation. While non-compliance carries no legal consequences, it remains essential for maintaining trust in the payment system, and your processor will generally charge you for it either way.

Understanding PCI fees

PCI fees are a normal part of payment processing, imposed under PCI DSS to keep merchants aligned with current regulations. They commonly appear as a line item on your merchant statement, and they fund the security measures the Payment Card Industry mandates.

Separate non-compliance fees may apply if your credit card technology does not meet the required standards.

What a non-compliance fee costs

The annual PCI fee is typically nominal — around $10 per month, or roughly $120 a year. Renewal each year depends on continuing to meet the main requirements for recertification.

If PCI calls your business

If someone contacts your business claiming to be "PCI," it is either a scam or your payment processor.

Ask questions, and request documentation by email so you can verify who you are dealing with. Legitimate processors usually handle these matters on your behalf, so an unsolicited call from an unknown source warrants caution. Do not share sensitive information unless you are certain the caller is legitimate.

Florida PCI compliance laws

In Florida, PCI compliance is guided by the PCI DSS standards and applies to companies that process, retain, or transmit cardholder information. The intent is to keep that information protected and to mitigate the risks that come with accepting credit cards.

Where Structure Payments fits

PCI compliance applies to every merchant, but it tends to cause the most confusion for high-risk businesses that have been passed between processors. If you are unsure what you are being charged for — or you have been declined elsewhere — talk to us and we will walk you through it.