Critical ResourceVisa CEDP: Major Payments Disruption
Back to Blog
Compliance

PCI DSS 4.0: Hidden Non-Compliance Fees Guide

Joe Wise
5 min read
PCI DSS 4.0: Hidden Non-Compliance Fees Guide

As of March 31, 2025, the "future dated" requirements of PCI DSS v4.0 officially became mandatory. While the base standard took effect in 2024, many mid-market merchants delayed implementing the more technical controls, such as expanded Multi-Factor Authentication and authenticated vulnerability scanning, until this final deadline. As a result, processors are now automatically assessing PCI Non-Compliance Fees on merchants who have not updated their Self-Assessment Questionnaires or met the new standards. These fees often range from $5,000 to $100,000 per month for larger violations, or appear as recurring line item penalties on monthly statements.

Why PCI Non-Compliance Fees Are Spiking in Q4 2025

For most of 2024, PCI DSS 4.0 was treated as a future problem. The Payment Card Industry Security Standards Council designated many of the hardest technical changes as "future dated," meaning they would not become mandatory until March 31, 2025. The PCI Council outlined these changes in its official documentation.

That deadline has passed.

As we move through Q4 2025, we are seeing a spike in a specific, avoidable expense appearing on statements: the PCI Non-Compliance Fee. Many finance leaders incorrectly assume that compliance submitted in 2024 still applies in 2025. That assumption is now outdated. The definition of "compliant" changed when the future-dated requirements became enforceable.

If your IT or security teams did not implement expanded Multi-Factor Authentication, script monitoring, or authenticated scanning, your processor has likely downgraded your compliance status.

This is no longer just a cybersecurity issue. It is now a direct financial drain on your P&L.

The Future-Dated Requirements That Are Now Mandatory

Expanded Multi-Factor Authentication (Requirement 8.4.2)

PCI DSS v4.0 requires MFA for all access into the Cardholder Data Environment, not just remote access.

The common failure pattern: Merchants implemented MFA only on VPN access but not on internal administrative logins.

Payment Page Script Protection (Requirements 6.4.3 and 11.6.1)

PCI DSS 4.0 introduces script integrity requirements for e-commerce payment pages. This requirement is detailed in the PCI DSS SAQ Instructions and Guidelines.

The failure pattern: Merchants assume hosted fields or iframe-based payment pages are exempt, but any third-party script on the page (analytics, UX, tracking) must now be monitored and authorized.

Authenticated Vulnerability Scanning (Requirement 11.3.1.2)

Internal vulnerability scanning must now be authenticated, as clarified in both the official standard and the v4.0.1 update notice.

If your quarterly scans still run unauthenticated, your environment automatically fails v4.0.

The Financial Impact of PCI Non-Compliance

Processors monetize risk. When compliance lapses, acquirers apply penalties.

Monthly Penalties for SMB and Mid-Market Merchants

For SMB and mid-market merchants, non-compliance fees typically range from $29.95 to $150 per month per MID.

Enterprise-Level Fines

For larger merchants, acquirers may pass through fines of $5,000 to $100,000 per month, depending on the severity and duration of non-compliance.

Breach Multiplier Risk

If a breach occurs during a period of non-compliance, merchants lose "safe harbor" protections. Card-brand penalties may rise significantly, and liability exposure increases dramatically.

Implementation Checklist: How to Stop the Penalties

To remove these fees, merchants must demonstrate compliance with the mandatory v4.0 controls.

Step 1: Update Your SAQ to v4.0 Format

Ensure you are submitting the current SAQ format. Any v3.2.1 SAQ is now invalid.

Step 2: Audit Your MFA Coverage

Ask your IT team whether MFA is enforced for all system access, including local console access. If not, you fail Requirement 8.4.2.

Step 3: Inventory and Monitor Your Payment Page Scripts

PCI DSS Requirements 6.4.3 and 11.6.1 mandate monitoring of all scripts running on payment pages. Create an inventory and remove or authorize scripts accordingly.

Step 4: Conduct a Targeted Risk Analysis

Targeted Risk Analyses (TRAs) allow flexibility in how frequently certain tasks are performed. Without a TRA, auditors default to the strictest interpretation of the rule.

Step 5: Verify Authenticated Scanning

Confirm with your security team that internal vulnerability scans are running with authenticated credentials, not just network-level scans.

Why Many Non-Compliance Fees Are Incorrectly Applied

PCI Non-Compliance Fees are often preventable penalties. In many cases, the merchant is actually compliant, but the processor has not updated its internal records. In other cases, the merchant is one control away from closing the compliance gap.

Common issues include:

  • Processors not receiving updated SAQ submissions
  • Compliance portal errors that don't sync with billing systems
  • Merchants completing requirements but failing to notify the acquirer
  • Ambiguous fee labels that obscure the root cause

A proper merchant cost recovery approach can:

  • Audit processor logic and fee application
  • Verify your compliance status against processor records
  • Challenge non-compliance fees when inaccurately applied
  • Identify gaps in MFA, scanning, and script monitoring

Security is mandatory. Paying unnecessary penalties is not.

Key Takeaways for Finance Leaders

PCI DSS 4.0 compliance is no longer optional, and the financial consequences of non-compliance are immediate. The future-dated requirements that many merchants postponed are now fully enforceable.

Finance leaders should:

  • Verify current SAQ submission status with their processor
  • Confirm MFA coverage extends to all CDE access points
  • Ensure payment page scripts are inventoried and authorized
  • Review statements for non-compliance fees that may be incorrectly applied

The path to removing these fees is straightforward: close the remaining compliance gaps and ensure your processor records reflect your current status.

Tags:
PCI DSSPCI compliancesecuritynon-compliance feesMFAvulnerability scanningpayment securitymerchant fees
Share:

Frequently Asked Questions

Have questions?

Find answers.

Ready to Optimize Your Payment Processing?

Get a free analysis of your current processing setup and discover potential savings.