What is a PCI compliance fee, and can you avoid it?
A PCI compliance fee is a charge your card machine provider adds to cover the cost of keeping you compliant with the Payment Card Industry Data Security Standard. It is a commercial fee, not a legal one, and whether you pay it depends entirely on the provider's pricing model. Pay-as-you-go readers publish no PCI fee; Dojo includes PCI management in its transaction fee and only charges separately if you fail to comply; some contract providers bill it as its own monthly line.

What PCI DSS actually is
PCI DSS is a security standard written and maintained by the card schemes. It applies to any business that stores, processes or transmits cardholder data, which in practice means anyone who accepts card payments. It is not a UK statute. You will not be fined by a regulator for breaching it. What you will have is a clause in your acquirer agreement requiring you to comply, and a provider that can charge you, or in serious cases close your account, if you do not.
For a shop, cafe or salon with a standalone terminal, compliance is mostly about not doing daft things: not writing card numbers on paper, not keying cards into a spreadsheet, not letting staff photograph receipts with the full PAN on. The terminal itself encrypts the card data, which is why most small businesses fall into the simplest assessment category.
The self-assessment questionnaire (SAQ)
Smaller merchants demonstrate compliance by completing a self-assessment questionnaire once a year. There are several versions, lettered by how you handle card data. A business using only a standalone terminal connected to the provider's network answers a short version. A business that takes cards over the phone and keys them in, or runs its own e-commerce checkout, answers a longer one. Your provider tells you which applies and usually hosts the questionnaire in an online portal.
The questionnaire is the bit most people ignore. The email arrives, it looks like admin, it gets buried. Then a non-compliance charge appears on the statement and stays there until someone logs in and ticks the boxes. We see this on a lot of statements sent to our free fee check.
How providers charge for it
| Pricing model | How it works | Example |
|---|---|---|
| Separate monthly PCI fee | A fixed line on every statement regardless of compliance status | Varies by provider; ask for the fees schedule |
| Included in transaction fee | PCI management is bundled into the per-transaction charge | Dojo: "included in the secure transaction fee" (T&Cs) |
| Non-compliance charge only | Nothing while compliant; a monthly penalty while not | Dojo: £15 + VAT per month when non-compliant, per review sites |
| No PCI fee published | Provider holds the merchant account; what it asks of you is set out in its help pages | SumUp (1.69%, no monthly fee), Square (1.75%, no monthly fees), Zettle (1.75%, no recurring fees) |
Dojo PCI wording from Dojo T&Cs v1.6; Dojo non-compliance amount from Mobile Transaction (review site). PAYG pricing from SumUp, Square and Zettle pricing pages. All checked August 2026.
Dojo specifically
Dojo's terms reference two PCI-related charges. The PCI management fee is described as “included in the secure transaction fee”, so it is not a separate monthly line. The PCI non-compliance charge is listed in the fees schedule and applies only while you are non-compliant. Review sites put that charge at £15 plus VAT a month, and free if compliant. We have not been able to verify the figure on Dojo's own pricing page, so treat it as indicative and check your fees schedule. More on Dojo's structure on our Dojo provider page.
Pay-as-you-go readers
SumUp lists 1.69% per in-person transaction and no monthly fee. Square lists 1.75% on UK cards in person with no setup or monthly fees on its free plan. Zettle lists 1.75% with no contracts or recurring fees. None of those pricing pages shows a PCI line. The provider holds the merchant account, so compliance sits at its level; what, if anything, it asks you to complete is set out in each provider's help pages. The trade-off is the flat rate, which for higher volumes is usually more than a contract rate. We set that out in card machine fees explained.
Can you avoid it?
Choose a pricing model where PCI management is included or not charged, and confirm that in writing before signing
Complete the self-assessment questionnaire when the provider sends it, and diarise the annual renewal
Keep card handling simple: standalone terminal, no manual keying, no card numbers on paper
Check your statement every month; a non-compliance charge is a sign something lapsed
What you cannot avoid is compliance itself. Any provider can require it, and a serious breach (losing customer card data) leaves you exposed to the card schemes' own penalties through your acquirer, regardless of what your monthly statement says.
When a PCI fee is not the thing to worry about
A separate PCI charge is irritating but it is rarely the biggest number on a statement. If you are paying one, look at the rest of the page before you switch providers over it. A few pounds a month for PCI next to an uncompetitive transaction rate, a minimum monthly service charge and a terminal rental is a pattern we see often, and the PCI line is the smallest part of it. Our guide to reading your merchant statement shows how to work out the effective rate, which is the number that matters.
Equally, if you already have a provider with no PCI line and a rate you are happy with, there is no reason to move.
Paying a PCI fee you did not expect?
Send us a statement and we will show you the effective rate line by line, then compare it against a Dojo quote.
Compare my feesCapExpand is an authorised Dojo partner and is paid by Dojo when a business signs up through us. That does not change the price you pay.
Frequently asked questions
What does PCI DSS stand for?
Payment Card Industry Data Security Standard. It is a set of security requirements maintained by the card schemes for any business that stores, processes or transmits cardholder data. It is an industry standard, not UK law, but your acquirer contract will require you to comply with it.
Is a PCI compliance fee a legal requirement?
No. The fee is a commercial charge set by your provider to cover the cost of managing your compliance programme. Some providers charge it as a separate monthly line, some fold it into the transaction fee, and pay-as-you-go readers publish no PCI fee at all. What is required is compliance with the standard itself, not any particular fee.
What is a PCI non-compliance charge?
A separate penalty charge that some providers apply each month you have not completed your self-assessment questionnaire or failed a scan. Review sites report Dojo charges £15 plus VAT a month when non-compliant and nothing when compliant. The simplest way to avoid it is to complete the questionnaire when asked and keep it current.
Do I need PCI compliance if I only use a contactless card reader?
You still fall within the standard, but a standalone terminal that never stores card data keeps you in the lightest category, and your provider normally handles most of the work. Pay-as-you-go providers hold the merchant account themselves. Their pricing pages show no PCI line. What, if anything, they ask you to complete is set out in each provider's help pages.
Can I negotiate a PCI fee away?
Sometimes. When you are comparing quotes, ask each provider for its full fees schedule and whether PCI management is a separate line or included. Dojo's terms say its PCI management fee is included in the secure transaction fee, with a separate non-compliance charge that only applies if you do not comply. Other providers vary; check before signing.
Fee amounts change and differ between contracts. Figures here were checked in August 2026 against the sources below; your own fees schedule is the document that counts.
Sources (checked August 2026)
CapExpand Ltd (Company No. 14433858) is an authorised Dojo partner, not a card machine manufacturer. We are not currently authorised or regulated by the Financial Conduct Authority. Card machine pricing and availability are subject to change. All information on this page is for general guidance only.