Skip to main content
Back to Blog

PCI Compliance Fees: What You Actually Owe vs What You're Paying

August 21, 20268 min read
PCI CompliancePayment Processing CanadaMerchant FeesSmall Business Payments
PCI Compliance Fees: What You Actually Owe vs What You're Paying

The $99 Line Item Nobody Explains

Pull up your last three merchant statements. Somewhere on there, probably tucked between "batch fee" and "statement fee," you'll find something called a PCI Compliance Fee, PCI Assessment Fee, or Data Security Fee. It's usually $79 to $395 a year, sometimes billed monthly in $6.95 to $12.95 chunks so it's less noticeable.

Ask your processor what that fee actually pays for and you'll get a vague answer about "maintaining compliance standards." That's not a real explanation, and for most small Canadian merchants, that fee is pure margin for the processor, not a cost they're passing through.

This article breaks down what PCI DSS compliance actually requires for a restaurant, a retail shop, a clinic, or an online store in Canada, what you're legally and contractually on the hook for, and where processors pad the bill.

What PCI DSS Actually Is

PCI DSS (Payment Card Industry Data Security Standard) is a set of rules created by Visa, Mastercard, Amex, and the other card networks, not by the Canadian government. It exists so that businesses handling card data don't leak it. Every business that accepts card payments is contractually required to comply, whether you're a 400-seat restaurant or a home-based Etsy shop taking Interac e-Transfer alternatives through a card reader.

The rules scale with how much card data actually touches your systems. A shop using a modern terminal that encrypts card data the instant it's tapped has almost nothing to do. A business that stores card numbers in a spreadsheet (please don't) has a lot to do.

The Four Merchant Levels (and Why Yours Almost Certainly Doesn't Matter Yet)

Card networks split merchants into four levels based on annual transaction volume, mostly per card brand:

  • Level 1: 6 million+ transactions a year
  • Level 2: 1 million to 6 million
  • Level 3: 20,000 to 1 million (mostly relevant for e-commerce)
  • Level 4: Everyone else, under 20,000 e-commerce transactions or any volume for card-present business

Unless you're running a regional chain or a high-volume e-commerce operation, you're a Level 4 merchant. Level 4 merchants self-assess. There's no auditor showing up at your restaurant. You fill out a Self-Assessment Questionnaire (SAQ) once a year, keep it on file, and that's genuinely most of it.

Which SAQ Actually Applies to You

This is where the headache usually comes from, because processors rarely tell you which SAQ type fits your setup, and the SAQ type determines how much work you have.

SAQ A is for merchants who never touch card data directly, everything runs through a third-party hosted checkout (think Shopify Payments, a hosted payment page for an e-commerce store). This is the shortest form, about 20 questions, mostly confirming you're not storing anything and your provider handles the rest.

SAQ B covers standalone terminals connected via phone line or dedicated connection that don't touch your network at all. A lot of restaurants and retail counters with older dial-up style terminals fall here.

SAQ B-IP is for standalone, IP-connected terminals, the standard countertop terminal most small Canadian merchants use today, connected to internet but isolated from your other systems.

SAQ P2PE applies if you're using a validated point-to-point encryption terminal, meaning card data is encrypted the second it's read and never appears in plain text anywhere on your network. This is the easiest category for a merchant with staff and multiple terminals, because encryption happens at the hardware level regardless of what your POS or network looks like.

SAQ D is the long one, 300+ controls, and it applies if you store, process, or transmit card data yourself outside a validated third-party system, custom-built checkout pages, in-house card storage, that kind of setup. Almost no small business needs to be here, and if you are, it's usually because of a legacy system that should be replaced anyway.

Say a restaurant is running three countertop terminals connected over WiFi with no card data touching their POS software. That's SAQ B-IP or SAQ P2PE depending on the terminal model, both short forms, both something an owner can complete in under an hour once a year with no consultant.

What You're Actually Required to Do

Strip away the sales pitch and a typical small Canadian merchant needs to:

  1. Complete the correct SAQ annually (your processor should tell you which one, and if they can't, that's a red flag about how well they're managing your account)
  2. Use point-of-sale equipment and payment gateways that are on the PCI Council's list of validated devices, which almost every terminal issued by a legitimate Canadian processor already is
  3. Never store full card numbers, CVV codes, or magnetic stripe data in any file, spreadsheet, email, or POS note field
  4. Run a quarterly external vulnerability scan only if you have a public-facing IP address tied to payment processing, which applies mainly to e-commerce merchants hosting their own checkout, not to a restaurant with a countertop terminal
  5. Keep your terminal and POS software updated when the vendor pushes patches

That's it. There's no PCI police showing up. There's no annual $395 audit for a Level 4 merchant. The fee on your statement is not a pass-through cost from the card networks, it's a service charge from your processor for helping you fill out a form that, in most cases, takes 20 minutes.

Where the Non-Compliance Fee Trap Comes In

Here's the part that actually costs merchants money. Most processor contracts include a separate "non-compliance fee," often $20 to $30 a month, charged automatically if you haven't submitted your SAQ that year. Some merchants get hit with both the PCI compliance fee AND the non-compliance fee in the same year because the SAQ reminder email went to a spam folder.

Say a clinic is paying a $10/month PCI fee plus a $25/month non-compliance penalty because nobody on staff realized the annual questionnaire needed resubmitting. That's $420 a year for a form that takes less time than a coffee break, and the processor has zero incentive to make the reminder process easier because the penalty is revenue for them.

What Actually Reduces the Headache

  • Use terminals with built-in point-to-point encryption. This drops you into the simplest SAQ category and removes most of your network from PCI scope entirely, because card data never sits in plain text on anything you control.
  • Use a hosted checkout for e-commerce, not a custom-built payment form. Shopify, a hosted Moneris page, or a similar setup keeps you at SAQ A instead of SAQ D.
  • Ask your processor directly which SAQ you fall under and get it in writing. If they can't answer in one email, that tells you how much attention your account actually gets.
  • Set your own calendar reminder for the SAQ renewal date instead of relying on the processor's email, since that's the actual mechanism that triggers non-compliance fees.
  • Never let staff write down card numbers, even temporarily, even for a refund. This is the single most common way small businesses accidentally fall out of SAQ A or B into scope for something worse.

None of this requires a security consultant or a compliance officer. It requires a terminal built in the last five years and a calendar reminder.

The Real Question to Ask Your Processor

When you're comparing statements, don't just look at your effective rate in basis points, look at what the PCI fee is actually funding. A processor charging 15 basis points more on your blended rate but bundling PCI compliance guidance, correct SAQ routing, and no separate non-compliance penalty is often cheaper in real dollars than one charging a lower headline rate plus $180 a year in compliance and penalty fees stacked on top.

A fair, transparent breakdown looks like this: interchange plus a fixed markup, a flat monthly fee that's clearly itemized, and a PCI line that either doesn't exist or is clearly explained as covering scan costs for merchants who actually need scans. If your current statement can't explain the PCI fee in one sentence, that's the tell.

Wrapping Up

PCI compliance for a small Canadian business is not the burden most statements make it look like. For the overwhelming majority of restaurants, retail shops, clinics, and service businesses, it's a short annual form and a terminal that's already doing the encryption work for you. The real cost isn't the compliance itself, it's the padded fees and penalty structures processors build around it because most merchants never ask what the line item is actually for.

If you're not sure which SAQ you're on, whether you're getting hit with a non-compliance fee you didn't know about, or whether your "PCI fee" is doing anything at all, that's worth a second look alongside your actual processing rate.

Get a free side-by-side comparison of what you pay now vs PaymentsPlus at paymentsplus.ca/quote

Ready to Save on Payment Processing?

Get a free, no-obligation quote and see how much you could save.

Get Your Free Quote